Done... found over 60 files (and deleted them)... WOW.
In the HJT log I'm pretty suspicious of these guys:
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai...all/xscan53.cabO20 - Winlogon Notify: ruins - C:\WINDOWS\system32\jtj0071me.dll (file missing)
For the ones that say "(file missing)", can they safely be deleted ? I could be wrong (and often I am)
but since the file is missing, that "entry" isn't doing anything. Am I assuming correctly... or am I
way off. (In other words, "Hey Paperweight, go back to your web surfing and leave the malware to
the professionals")
By the way, I don't have paypal. Is there any other method to contribute ?
*** L2M txt ***
Look2Me-Destroyer V1.0.6
Scanning for infected files.....
Scan started at 2/26/2006 5:19:22 AM
Infected! C:\WINDOWS\SYSTEM32\azaul9191.dll
Infected! C:\WINDOWS\SYSTEM32\azivtmxx.dll
Infected! C:\WINDOWS\SYSTEM32\dn8801lue.dll
Infected! C:\WINDOWS\SYSTEM32\dnl4013qe.dll
Infected! C:\WINDOWS\SYSTEM32\e002lado1d0c.dll
Infected! C:\WINDOWS\SYSTEM32\e8jm0i11e8.dll
Infected! C:\WINDOWS\SYSTEM32\enpql1751.dll
Infected! C:\WINDOWS\SYSTEM32\f00o0ad3ed0.dll
Infected! C:\WINDOWS\SYSTEM32\f6j20g1oe6.dll
Infected! C:\WINDOWS\SYSTEM32\fp2q03f5e.dll
Infected! C:\WINDOWS\SYSTEM32\fzdrclnr.dll
Infected! C:\WINDOWS\SYSTEM32\gpjml3111.dll
Infected! C:\WINDOWS\SYSTEM32\h6n00g5me6.dll
Infected! C:\WINDOWS\SYSTEM32\hhpertrm.dll
Infected! C:\WINDOWS\SYSTEM32\hrps0577e.dll
Infected! C:\WINDOWS\SYSTEM32\ia41_qcx.dll
Infected! C:\WINDOWS\SYSTEM32\ir00l5dm1.dll
Infected! C:\WINDOWS\SYSTEM32\ir28l5fu1.dll
Infected! C:\WINDOWS\SYSTEM32\ir8ml5l11.dll
Infected! C:\WINDOWS\SYSTEM32\j46m0ej1eho.dll
Infected! C:\WINDOWS\SYSTEM32\jt6m07j1e.dll
Infected! C:\WINDOWS\SYSTEM32\jtj0071me.dll
Infected! C:\WINDOWS\SYSTEM32\jtr8079ue.dll
Infected! C:\WINDOWS\SYSTEM32\kt20l7fm1.dll
Infected! C:\WINDOWS\SYSTEM32\kt2ql7f51.dll
Infected! C:\WINDOWS\SYSTEM32\kzdmaori.dll
Infected! C:\WINDOWS\SYSTEM32\l08m0al1edq.dll
Infected! C:\WINDOWS\SYSTEM32\l08mlal11dq.dll
Infected! C:\WINDOWS\SYSTEM32\l42slef71h2.dll
Infected! C:\WINDOWS\SYSTEM32\l8l60i3se8.dll
Infected! C:\WINDOWS\SYSTEM32\lueps12n.dll
Infected! C:\WINDOWS\SYSTEM32\lv0809due.dll
Infected! C:\WINDOWS\SYSTEM32\lv4409hqe.dll
Infected! C:\WINDOWS\SYSTEM32\lvj0091me.dll
Infected! C:\WINDOWS\SYSTEM32\lytif11n.dll
Infected! C:\WINDOWS\SYSTEM32\m6460ghse6460.dll
Infected! C:\WINDOWS\SYSTEM32\m8rm0i91e8.dll
Infected! C:\WINDOWS\SYSTEM32\mmimg32.dll
Infected! C:\WINDOWS\SYSTEM32\mpricons.dll
Infected! C:\WINDOWS\SYSTEM32\mvjul9191.dll
Infected! C:\WINDOWS\SYSTEM32\mvl8l93u1.dll
Infected! C:\WINDOWS\SYSTEM32\mvn0l95m1.dll
Infected! C:\WINDOWS\SYSTEM32\n24s0ch7ef4.dll
Infected! C:\WINDOWS\SYSTEM32\n44sleh71h4.dll
Infected! C:\WINDOWS\SYSTEM32\n48olel31hq.dll
Infected! C:\WINDOWS\SYSTEM32\nttrap.dll
Infected! C:\WINDOWS\SYSTEM32\o2lu0c39ef.dll
Infected! C:\WINDOWS\SYSTEM32\otbc32gt.dll
Infected! C:\WINDOWS\SYSTEM32\oxhlp30e.dll
Infected! C:\WINDOWS\SYSTEM32\pbdx5032.dll
Infected! C:\WINDOWS\SYSTEM32\q4860elsehq60.dll
Infected! C:\WINDOWS\SYSTEM32\q8psli7718.dll
Infected! C:\WINDOWS\SYSTEM32\qYsf.dll
Infected! C:\WINDOWS\SYSTEM32\r6r60g9se6.dll
Infected! C:\WINDOWS\SYSTEM32\roched20.dll
Infected! C:\WINDOWS\SYSTEM32\suc.dll
Infected! C:\WINDOWS\SYSTEM32\tJpi32.dll
Infected! C:\WINDOWS\SYSTEM32\u8ruli9918.dll
Infected! C:\WINDOWS\SYSTEM32\wbsapi32.dll
Infected! C:\WINDOWS\SYSTEM32\wgaservc.dll
Infected! C:\WINDOWS\SYSTEM32\wm2_32.dll
Infected! C:\WINDOWS\SYSTEM32\wtw32.dll
Attempting to delete infected files...
Attempting to delete: C:\WINDOWS\SYSTEM32\azaul9191.dll
C:\WINDOWS\SYSTEM32\azaul9191.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\azivtmxx.dll
C:\WINDOWS\SYSTEM32\azivtmxx.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\dn8801lue.dll
C:\WINDOWS\SYSTEM32\dn8801lue.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\dnl4013qe.dll
C:\WINDOWS\SYSTEM32\dnl4013qe.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\e002lado1d0c.dll
C:\WINDOWS\SYSTEM32\e002lado1d0c.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\e8jm0i11e8.dll
C:\WINDOWS\SYSTEM32\e8jm0i11e8.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\enpql1751.dll
C:\WINDOWS\SYSTEM32\enpql1751.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\f00o0ad3ed0.dll
C:\WINDOWS\SYSTEM32\f00o0ad3ed0.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\f6j20g1oe6.dll
C:\WINDOWS\SYSTEM32\f6j20g1oe6.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\fp2q03f5e.dll
C:\WINDOWS\SYSTEM32\fp2q03f5e.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\fzdrclnr.dll
C:\WINDOWS\SYSTEM32\fzdrclnr.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\gpjml3111.dll
C:\WINDOWS\SYSTEM32\gpjml3111.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\h6n00g5me6.dll
C:\WINDOWS\SYSTEM32\h6n00g5me6.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\hhpertrm.dll
C:\WINDOWS\SYSTEM32\hhpertrm.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\hrps0577e.dll
C:\WINDOWS\SYSTEM32\hrps0577e.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\ia41_qcx.dll
C:\WINDOWS\SYSTEM32\ia41_qcx.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\ir00l5dm1.dll
C:\WINDOWS\SYSTEM32\ir00l5dm1.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\ir28l5fu1.dll
C:\WINDOWS\SYSTEM32\ir28l5fu1.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\ir8ml5l11.dll
C:\WINDOWS\SYSTEM32\ir8ml5l11.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\j46m0ej1eho.dll
C:\WINDOWS\SYSTEM32\j46m0ej1eho.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\jt6m07j1e.dll
C:\WINDOWS\SYSTEM32\jt6m07j1e.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\jtj0071me.dll
C:\WINDOWS\SYSTEM32\jtj0071me.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\jtr8079ue.dll
C:\WINDOWS\SYSTEM32\jtr8079ue.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\kt20l7fm1.dll
C:\WINDOWS\SYSTEM32\kt20l7fm1.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\kt2ql7f51.dll
C:\WINDOWS\SYSTEM32\kt2ql7f51.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\kzdmaori.dll
C:\WINDOWS\SYSTEM32\kzdmaori.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\l08m0al1edq.dll
C:\WINDOWS\SYSTEM32\l08m0al1edq.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\l08mlal11dq.dll
C:\WINDOWS\SYSTEM32\l08mlal11dq.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\l42slef71h2.dll
C:\WINDOWS\SYSTEM32\l42slef71h2.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\l8l60i3se8.dll
C:\WINDOWS\SYSTEM32\l8l60i3se8.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\lueps12n.dll
C:\WINDOWS\SYSTEM32\lueps12n.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\lv0809due.dll
C:\WINDOWS\SYSTEM32\lv0809due.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\lv4409hqe.dll
C:\WINDOWS\SYSTEM32\lv4409hqe.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\lvj0091me.dll
C:\WINDOWS\SYSTEM32\lvj0091me.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\lytif11n.dll
C:\WINDOWS\SYSTEM32\lytif11n.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\m6460ghse6460.dll
C:\WINDOWS\SYSTEM32\m6460ghse6460.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\m8rm0i91e8.dll
C:\WINDOWS\SYSTEM32\m8rm0i91e8.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\mmimg32.dll
C:\WINDOWS\SYSTEM32\mmimg32.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\mpricons.dll
C:\WINDOWS\SYSTEM32\mpricons.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\mvjul9191.dll
C:\WINDOWS\SYSTEM32\mvjul9191.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\mvl8l93u1.dll
C:\WINDOWS\SYSTEM32\mvl8l93u1.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\mvn0l95m1.dll
C:\WINDOWS\SYSTEM32\mvn0l95m1.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\n24s0ch7ef4.dll
C:\WINDOWS\SYSTEM32\n24s0ch7ef4.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\n44sleh71h4.dll
C:\WINDOWS\SYSTEM32\n44sleh71h4.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\n48olel31hq.dll
C:\WINDOWS\SYSTEM32\n48olel31hq.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\nttrap.dll
C:\WINDOWS\SYSTEM32\nttrap.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\o2lu0c39ef.dll
C:\WINDOWS\SYSTEM32\o2lu0c39ef.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\otbc32gt.dll
C:\WINDOWS\SYSTEM32\otbc32gt.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\oxhlp30e.dll
C:\WINDOWS\SYSTEM32\oxhlp30e.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\pbdx5032.dll
C:\WINDOWS\SYSTEM32\pbdx5032.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\q4860elsehq60.dll
C:\WINDOWS\SYSTEM32\q4860elsehq60.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\q8psli7718.dll
C:\WINDOWS\SYSTEM32\q8psli7718.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\qYsf.dll
C:\WINDOWS\SYSTEM32\qYsf.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\r6r60g9se6.dll
C:\WINDOWS\SYSTEM32\r6r60g9se6.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\roched20.dll
C:\WINDOWS\SYSTEM32\roched20.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\suc.dll
C:\WINDOWS\SYSTEM32\suc.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\tJpi32.dll
C:\WINDOWS\SYSTEM32\tJpi32.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\u8ruli9918.dll
C:\WINDOWS\SYSTEM32\u8ruli9918.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\wbsapi32.dll
C:\WINDOWS\SYSTEM32\wbsapi32.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\wgaservc.dll
C:\WINDOWS\SYSTEM32\wgaservc.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\wm2_32.dll
C:\WINDOWS\SYSTEM32\wm2_32.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\SYSTEM32\wtw32.dll
C:\WINDOWS\SYSTEM32\wtw32.dll Deleted successfully!
Making registry repairs.
Restoring Windows certificates.
Replaced hosts file with default windows hosts file
Restoring SeDebugPrivilege for Administrators - Succeeded
*** HJT log ***
Logfile of HijackThis v1.99.1
Scan saved at 5:35:08 AM, on 2/26/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Nhksrv.exe
C:\WINDOWS\System32\PackethSvc.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Network Monitor\netmon.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\MMKeybd.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
C:\WINDOWS\System32\hphmon04.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\PROGRA~1\LEXMAR~1\ACMonitor_X73.exe
C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X73.exe
C:\Program Files\Common Files\MySoftware\intercom.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Netropa\Traymon.exe
C:\Program Files\Netropa\OSD.exe
C:\WINDOWS\System32\HPHipm11.exe
C:\WINDOWS\system32\wuauclt.exe
C:\paperweight\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file:///C:/html/start/start.html
O4 - HKLM\..\Run: [DellTouch] C:\WINDOWS\MMKeybd.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [AHQInit] C:\Program Files\Creative\SBLive\Program\AHQInit.exe
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MusicMatch\MusicMatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\System32\hphmon04.exe
O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe"
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [Lexmark X73 Button Monitor] C:\PROGRA~1\LEXMAR~1\ACMonitor_X73.exe
O4 - HKLM\..\Run: [Lexmark X73 Button Manager] C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X73.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: MySoftware InterCom.lnk = C:\Program Files\Common Files\MySoftware\intercom.exe
O9 - Extra button: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra 'Tools' menuitem: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra button: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O9 - Extra 'Tools' menuitem: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 - Plugin for .mp3: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai...all/xscan53.cabO16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) -
http://web1.shutterf...ds/Uploader.cabO20 - Winlogon Notify: Fonts - C:\WINDOWS\system32\KZDPO.DLL
O20 - Winlogon Notify: ruins - C:\WINDOWS\system32\jtj0071me.dll (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe
O23 - Service: Netropa NHK Server (Nhksrv) - Unknown owner - C:\WINDOWS\Nhksrv.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Virtual NIC Service (PackethSvc) - America Online, Inc. - C:\WINDOWS\System32\PackethSvc.exe
O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\System32\HPHipm11.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
Edited by Paperweight, 26 February 2006 - 06:01 AM.