Okay. Here's my SpySweeper log:
8:01 AM: |··· Start of Session, Wednesday, July 27, 2005 ···|
8:01 AM: Spy Sweeper started
8:01 AM: Sweep initiated using definitions version 505
8:01 AM: Starting Memory Sweep
8:03 AM: Found Adware: abetterinternet
8:03 AM: Detected running threat: C:\WINDOWS\system32\DrPMon.dll (ID = 4127918)
8:05 AM: Memory Sweep Complete, Elapsed Time: 00:03:43
8:05 AM: Starting Registry Sweep
8:05 AM: Found Adware: begin2search
8:05 AM: HKCR\btnetw.amo.1\ (3 subtraces) (ID = 4364935)
8:05 AM: HKCR\btnetw.amo\ (5 subtraces) (ID = 4364936)
8:05 AM: HKCR\btnetw.iiittt.1\ (3 subtraces) (ID = 4364937)
8:05 AM: HKCR\btnetw.iiittt\ (5 subtraces) (ID = 4364938)
8:05 AM: HKCR\btnetw.momo.1\ (3 subtraces) (ID = 4364939)
8:05 AM: HKCR\btnetw.momo\ (5 subtraces) (ID = 4364940)
8:05 AM: HKCR\btnetw.ohb.1\ (3 subtraces) (ID = 4364941)
8:05 AM: HKCR\btnetw.ohb\ (5 subtraces) (ID = 4364942)
8:05 AM: HKCR\clsid\{9ade0443-2ab2-4b23-a3f8-ac520773de12}\ (11 subtraces) (ID = 4364949)
8:05 AM: HKCR\clsid\{bc54b24c-5a97-4c19-9181-8b8a05b2e931}\ (11 subtraces) (ID = 4364958)
8:05 AM: HKCR\clsid\{bd9584ef-c28c-4f6d-8d49-0cee3c0e442f}\ (22 subtraces) (ID = 4364959)
8:05 AM: HKCR\clsid\{c7888681-1a83-4c14-b9a5-95f91240b44f}\ (11 subtraces) (ID = 4364960)
8:05 AM: HKCR\interface\{6b882c34-a832-4f5b-bef1-7e198be3f094}\ (8 subtraces) (ID = 4364964)
8:05 AM: HKCR\interface\{9b6b4031-1d6d-4c65-acba-021916853822}\ (8 subtraces) (ID = 4364966)
8:05 AM: HKCR\interface\{9ff60a27-0c0c-4a6a-a15f-b21b644d67bb}\ (8 subtraces) (ID = 4364967)
8:05 AM: HKCR\interface\{15d53b86-e055-43b1-bbee-a91a0f37bd2a}\ (8 subtraces) (ID = 4364968)
8:05 AM: HKCR\interface\{f3c41c1d-22f1-4692-8a7a-88de70a2e9e2}\ (8 subtraces) (ID = 4364979)
8:05 AM: HKCR\interface\{fa6fa7a5-2c49-4567-ba74-6dd1c36099ee}\ (8 subtraces) (ID = 4364981)
8:05 AM: HKLM\software\classes\btnetw.amo.1\ (3 subtraces) (ID = 4364985)
8:05 AM: HKLM\software\classes\btnetw.amo\ (5 subtraces) (ID = 4364986)
8:05 AM: HKLM\software\classes\btnetw.iiittt.1\ (3 subtraces) (ID = 4364987)
8:05 AM: HKLM\software\classes\btnetw.iiittt\ (5 subtraces) (ID = 4364988)
8:05 AM: HKLM\software\classes\btnetw.momo.1\ (3 subtraces) (ID = 4364989)
8:05 AM: HKLM\software\classes\btnetw.momo\ (5 subtraces) (ID = 4364990)
8:05 AM: HKLM\software\classes\btnetw.ohb.1\ (3 subtraces) (ID = 4364991)
8:05 AM: HKLM\software\classes\btnetw.ohb\ (5 subtraces) (ID = 4364992)
8:05 AM: HKLM\software\classes\clsid\{9ade0443-2ab2-4b23-a3f8-ac520773de12}\ (11 subtraces) (ID = 4364999)
8:05 AM: HKLM\software\classes\clsid\{bc54b24c-5a97-4c19-9181-8b8a05b2e931}\ (11 subtraces) (ID = 4365008)
8:05 AM: HKLM\software\classes\clsid\{bd9584ef-c28c-4f6d-8d49-0cee3c0e442f}\ (22 subtraces) (ID = 4365009)
8:05 AM: HKLM\software\classes\clsid\{c7888681-1a83-4c14-b9a5-95f91240b44f}\ (11 subtraces) (ID = 4365010)
8:05 AM: HKLM\software\classes\interface\{6b882c34-a832-4f5b-bef1-7e198be3f094}\ (8 subtraces) (ID = 4365014)
8:05 AM: HKLM\software\classes\interface\{9b6b4031-1d6d-4c65-acba-021916853822}\ (8 subtraces) (ID = 4365016)
8:05 AM: HKLM\software\classes\interface\{9ff60a27-0c0c-4a6a-a15f-b21b644d67bb}\ (8 subtraces) (ID = 4365017)
8:05 AM: HKLM\software\classes\interface\{15d53b86-e055-43b1-bbee-a91a0f37bd2a}\ (8 subtraces) (ID = 4365018)
8:05 AM: HKLM\software\classes\interface\{f3c41c1d-22f1-4692-8a7a-88de70a2e9e2}\ (8 subtraces) (ID = 4365029)
8:05 AM: HKLM\software\classes\interface\{fa6fa7a5-2c49-4567-ba74-6dd1c36099ee}\ (8 subtraces) (ID = 4365031)
8:05 AM: HKLM\software\classes\typelib\{bf56be6a-0aea-45f3-8b10-7312876584a8}\ (9 subtraces) (ID = 4365035)
8:05 AM: HKLM\software\microsoft\windows\currentversion\explorer\browser helper objects\{9ade0443-2ab2-4b23-a3f8-ac520773de12}\ (1 subtraces) (ID = 4365051)
8:05 AM: HKCR\typelib\{bf56be6a-0aea-45f3-8b10-7312876584a8}\ (9 subtraces) (ID = 4365078)
8:05 AM: Found Adware: hotsearchbar toolbar
8:05 AM: HKCR\btnetw.amo\ (5 subtraces) (ID = 4388745)
8:05 AM: HKCR\btnetw.iiittt\ (5 subtraces) (ID = 4388746)
8:05 AM: HKCR\btnetw.momo\ (5 subtraces) (ID = 4388747)
8:05 AM: HKCR\btnetw.ohb\ (5 subtraces) (ID = 4388748)
8:05 AM: HKCR\clsid\{9ade0443-2ab2-4b23-a3f8-ac520773de12}\ (11 subtraces) (ID = 4388751)
8:05 AM: HKCR\clsid\{bc54b24c-5a97-4c19-9181-8b8a05b2e931}\ (11 subtraces) (ID = 4388756)
8:05 AM: HKCR\clsid\{bd9584ef-c28c-4f6d-8d49-0cee3c0e442f}\ (22 subtraces) (ID = 4388757)
8:05 AM: HKCR\clsid\{c7888681-1a83-4c14-b9a5-95f91240b44f}\ (11 subtraces) (ID = 4388758)
8:05 AM: HKLM\software\classes\btnetw.amo\ (5 subtraces) (ID = 4388762)
8:05 AM: HKLM\software\classes\btnetw.iiittt\ (5 subtraces) (ID = 4388763)
8:05 AM: HKLM\software\classes\btnetw.momo\ (5 subtraces) (ID = 4388764)
8:05 AM: HKLM\software\classes\btnetw.ohb\ (5 subtraces) (ID = 4388765)
8:05 AM: HKLM\software\classes\clsid\{9ade0443-2ab2-4b23-a3f8-ac520773de12}\ (11 subtraces) (ID = 4388768)
8:05 AM: HKLM\software\classes\clsid\{bc54b24c-5a97-4c19-9181-8b8a05b2e931}\ (11 subtraces) (ID = 4388773)
8:05 AM: HKLM\software\classes\clsid\{bd9584ef-c28c-4f6d-8d49-0cee3c0e442f}\ (22 subtraces) (ID = 4388774)
8:05 AM: HKLM\software\classes\clsid\{c7888681-1a83-4c14-b9a5-95f91240b44f}\ (11 subtraces) (ID = 4388775)
8:05 AM: HKLM\software\classes\typelib\{bf56be6a-0aea-45f3-8b10-7312876584a8}\ (9 subtraces) (ID = 4388779)
8:05 AM: HKLM\software\microsoft\windows\currentversion\explorer\browser helper objects\{9ade0443-2ab2-4b23-a3f8-ac520773de12}\ (1 subtraces) (ID = 4388790)
8:05 AM: HKCR\typelib\{bf56be6a-0aea-45f3-8b10-7312876584a8}\ (9 subtraces) (ID = 4388793)
8:05 AM: Found Adware: drsnsrch.com hijacker
8:05 AM: HKU\S-1-5-21-343818398-484763869-854245398-1003\software\microsoft\search assistant\ || defaultsearchurl (ID = 4389253)
8:05 AM: HKU\S-1-5-21-343818398-484763869-854245398-1003\software\microsoft\internet explorer\main\ || search bar (ID = 4389254)
8:05 AM: HKU\S-1-5-21-343818398-484763869-854245398-1003\software\microsoft\internet explorer\main\ || search page (ID = 4389255)
8:05 AM: HKLM\software\microsoft\internet explorer\main\ || search bar (ID = 4389256)
8:05 AM: HKLM\software\microsoft\internet explorer\main\ || search page (ID = 4389257)
8:05 AM: HKLM\software\microsoft\internet explorer\search\ || customizesearch (ID = 4389258)
8:05 AM: HKLM\software\microsoft\internet explorer\search\ || searchassistant (ID = 4389259)
8:05 AM: HKU\S-1-5-21-343818398-484763869-854245398-1003\software\microsoft\internet explorer\searchurl\ (2 subtraces) (ID = 4389260)
8:05 AM: Found Adware: privacyscan
8:05 AM: HKU\S-1-5-21-343818398-484763869-854245398-1003\software\in3rd\ (1 subtraces) (ID = 4398210)
8:05 AM: HKU\S-1-5-21-343818398-484763869-854245398-1003\software\aurora\ || au3n5a7tionscode (ID = 4407471)
8:05 AM: HKU\S-1-5-21-343818398-484763869-854245398-1003\software\aurora\ || aub3d5om (ID = 4407472)
8:05 AM: HKU\S-1-5-21-343818398-484763869-854245398-1003\software\aurora\ || auc1o3d5eofsfinalad (ID = 4407473)
8:05 AM: HKU\S-1-5-21-343818398-484763869-854245398-1003\software\aurora\ || auc3n5tfyl (ID = 4407474)
8:05 AM: HKU\S-1-5-21-343818398-484763869-854245398-1003\software\aurora\ || auc3n5trmsgsdisp (ID = 4407475)
8:05 AM: HKU\S-1-5-21-343818398-484763869-854245398-1003\software\aurora\ || auc3u5rrentsmode (ID = 4407476)
8:05 AM: HKU\S-1-5-21-343818398-484763869-854245398-1003\software\aurora\ || aud3s5tssend (ID = 4407477)
8:05 AM: HKU\S-1-5-21-343818398-484763869-854245398-1003\software\aurora\ || aue3v5nt (ID = 4407478)
8:05 AM: HKU\S-1-5-21-343818398-484763869-854245398-1003\software\aurora\ || aui3d5ofsinst (ID = 4407479)
8:05 AM: HKU\S-1-5-21-343818398-484763869-854245398-1003\software\aurora\ || aui3g5nores (ID = 4407480)
8:05 AM: HKU\S-1-5-21-343818398-484763869-854245398-1003\software\aurora\ || aui3n5progscab (ID = 4407481)
8:05 AM: HKU\S-1-5-21-343818398-484763869-854245398-1003\software\aurora\ || aui3n5progsex (ID = 4407482)
8:05 AM: HKU\S-1-5-21-343818398-484763869-854245398-1003\software\aurora\ || aui3n5progslstest (ID = 4407483)
8:05 AM: HKU\S-1-5-21-343818398-484763869-854245398-1003\software\aurora\ || aul3n5title (ID = 4407484)
8:05 AM: HKU\S-1-5-21-343818398-484763869-854245398-1003\software\aurora\ || aum3o5dessync (ID = 4407485)
8:05 AM: HKU\S-1-5-21-343818398-484763869-854245398-1003\software\aurora\ || aup3d5om (ID = 4407486)
8:05 AM: HKU\S-1-5-21-343818398-484763869-854245398-1003\software\aurora\ || aus3t5icky1s (ID = 4407488)
8:05 AM: HKU\S-1-5-21-343818398-484763869-854245398-1003\software\aurora\ || aus3t5icky2s (ID = 4407489)
8:05 AM: HKU\S-1-5-21-343818398-484763869-854245398-1003\software\aurora\ || aus3t5icky3s (ID = 4407490)
8:05 AM: HKU\S-1-5-21-343818398-484763869-854245398-1003\software\aurora\ || aus3t5icky4s (ID = 4407491)
8:05 AM: HKU\S-1-5-21-343818398-484763869-854245398-1003\software\aurora\ || aut3h5rshsbath (ID = 4407492)
8:05 AM: HKU\S-1-5-21-343818398-484763869-854245398-1003\software\aurora\ || aut3h5rshschecksin (ID = 4407493)
8:05 AM: HKU\S-1-5-21-343818398-484763869-854245398-1003\software\aurora\ || aut3h5rshsmots (ID = 4407494)
8:05 AM: HKU\S-1-5-21-343818398-484763869-854245398-1003\software\aurora\ || aut3h5rshsyssinf (ID = 4407495)
8:05 AM: HKU\S-1-5-21-343818398-484763869-854245398-1003\software\aurora\ || aut3i5m7eofsfinalad (ID = 4407496)
8:05 AM: HKLM\software\microsoft\windows\currentversion\uninstall\abi-1\ (6 subtraces) (ID = 4407772)
8:05 AM: HKLM\system\currentcontrolset\services\svcproc\ (8 subtraces) (ID = 4407797)
8:05 AM: Registry Sweep Complete, Elapsed Time:00:00:21
8:05 AM: Starting Cookie Sweep
8:05 AM: Cookie Sweep Complete, Elapsed Time: 00:00:00
8:05 AM: Starting File Sweep
8:05 AM: drpmon.dll (ID = 4127918)
8:06 AM: svcproc.exe (ID = 4128208)
8:06 AM: abiuninst.htm (ID = 4127732)
8:07 AM: pinkkas21.ico (ID = 4091716)
8:07 AM: __delete_on_reboot__drpmon.dll (ID = 4127918)
8:07 AM: File Sweep Complete, Elapsed Time: 00:01:48
8:07 AM: Full Sweep has completed. Elapsed time 00:05:56
8:07 AM: Traces Found: 575
8:12 AM: Removal process initiated
8:13 AM: Quarantining All Traces: abetterinternet
8:13 AM: Quarantining All Traces: begin2search
8:13 AM: Quarantining All Traces: hotsearchbar toolbar
8:13 AM: Quarantining All Traces: drsnsrch.com hijacker
8:13 AM: Quarantining All Traces: privacyscan
8:13 AM: Preparing to restart your computer. Please wait...
8:13 AM: Removal process completed. Elapsed time 00:01:23
8:16 AM: Warning: Hosts File Shield unable to read from hosts file. Access violation at address 7C910370 in module 'ntdll.dll'. Read of address 00000058
8:16 AM: Warning: Hosts File Shield unable to read from hosts file. Access violation at address 7C910370 in module 'ntdll.dll'. Read of address 00000024
8:16 AM: Warning: Hosts File Shield unable to read from hosts file. Invalid pointer operation
********
7:58 AM: |··· Start of Session, Wednesday, July 27, 2005 ···|
7:58 AM: Spy Sweeper started
7:58 AM: Warning: Hosts File Shield unable to read from hosts file. Access violation at address 7C910370 in module 'ntdll.dll'. Read of address 00000058
7:58 AM: Warning: Hosts File Shield unable to read from hosts file. Access violation at address 7C910370 in module 'ntdll.dll'. Read of address 00000050
7:58 AM: Warning: Hosts File Shield unable to read from hosts file. Access violation at address 7C910370 in module 'ntdll.dll'. Read of address 00000458
8:01 AM: |··· End of Session, Wednesday, July 27, 2005 ···|
Here's the Hijack This log:Logfile of HijackThis v1.99.1
Scan saved at 8:22:33 AM, on 7/27/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft Money\System\mnyexpr.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
c:\windows\system32\zhtmhuo.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Documents and Settings\Dana Melancon\My Documents\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://websearch.drs...esearch.cgi?id=R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://websearch.drs...esearch.cgi?id=R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://aimhome.netsc...com/aimhome.adpR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://websearch.drs...esearch.cgi?id=R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://websearch.drs...esearch.cgi?id=R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://websearch.drs...esearch.cgi?id=R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://websearch.drs...esearch.cgi?id=R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: Band Class - {00F1D395-4744-40f0-A611-980F61AE2C59} - C:\WINDOWS\dsr.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: RichEditor Class - {F79A2C4B-8776-4ED7-8B2F-4786A4A3500A} - C:\WINDOWS\system32\richedtr.dll (file missing)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [richup] C:\WINDOWS\system32\richup.exe
O4 - HKLM\..\Run: [Dinst] C:\WINDOWS\dinst.exe
O4 - HKLM\..\Run: [bofhdoi] c:\windows\system32\zhtmhuo.exe r
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [DW4] "C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe"
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) -
http://housecall60.t...all/xscan60.cabO16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) -
http://www.popcap.co...aploader_v6.cabO20 - Winlogon Notify: PCANotify - C:\WINDOWS\SYSTEM32\PCANotify.dll
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe