Arcade File Downloads Support Forum
Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

Bad - Remove almost always
OK Most of the time - don't need to touch
Probably not needed - Safe to remove
Generally harmless - third party applications
Bad if you don't know what it is
Unknown Item - Investigate further

Logfile of HijackThis v1.99.1
Old Version of HijackThis
We suggest you upgrade to the latest version of HijackThis (version 2.0.4") at www.merijn.org

Scan saved at 9:49:26 PM, on 12/25/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
Smss.exe
What is it?
Session Manager SubSystem - smss.exe

What does it do?
smss.exe - This is the session manager subsystem, which is responsible for starting the user session. This process is initiated by the system thread and is responsible for various activities, including launching the Winlogon and Win32 (Csrss.exe) processes and setting system variables. After it has launched these processes, it waits for either Winlogon or Csrss to end. If this happens "normally," the system shuts down; if it happens unexpectedly, Smss.exe causes the system to stop responding (hang).

Additional Reading:
Smss.exe does not resolve forward references in environment

You will not be able to end this through task manager!

More info



Virus Precaution:

The smss.exe which is from Microsoft is located at c:windowsSystem32smss.exe . We've been able to find several viruses that run as smss to trick you.

Adware.Advision - Symantec Corporation
Adware.DreamAd - Symantec Corporation
Backdoor.IRC.Aladinz.O - Symantec Corporation
Backdoor.IRC.Flood.F - Symantec Corporation
W32.Dalbug.Worm - Symantec Corporation
W32.Resdoc - Symantec Corporation

C:\WINDOWS\SYSTEM32\winlogon.exe
Winlogon.exe
What is it?
Windows Logon Process - Winlogon.exe

What does it do?
Direct Quote from here:
This is the process responsible for managing user logon and logoff. Moreover, Winlogon is active only when the user presses CTRL+ALT+DEL, at which point it shows the security dialog box.

Search MS for more info: Link

Virus Precaution:
The original Winlogon.exe from Microsoft gets placed in the C:WINDOWSSystem32 directory. if you find it anywhere else then you should be suspicious for sure.

You'll want to keep an eye on this google search for any known viruses. We've been able to find only 1 report of a virus so far.

Troj/Madr-B @ Sophos
Netsky.D @ Trend Micro

C:\WINDOWS\system32\services.exe
services.exe
services.exe is a part of Windows that manages the processes. Anytime a service starts or stops it is through services.exe. During system startup and shutdown is when this process sees most of its action. You should never end this process unless it is running outside of your windows system folder.

C:\WINDOWS\system32\lsass.exe
lsass.exe
What is it?
Local Security Authentication Server - lsass.exe

What does it do?
lsass.exe - It generates the process responsible for authenticating users for the Winlogon service. This process is performed by using authentication packages such as the default Msgina.dll. If authentication is successful, Lsass generates the user's access token, which is used to launch the initial shell. Other processes that the user initiates inherit this token.

You will not be able to end this through task manager!

From MS



The lsass.exe which is from Microsoft is located at c:windowsSystem32lsass.exe . there's a few viruses that have been found to run as lsass.exe to hide from you.

C:\WINDOWS\system32\svchost.exe
Svchost.exe

What is it?
Service Host Process - svchost.exe

What does it do?

Here's a direct quote from MS about this: (source)
Svchost.exe is a generic host process name for services that are run from dynamic-link libraries (DLLs). The Svchost.exe file is located in the %SystemRoot%System32 folder. At startup, Svchost.exe checks the services portion of the registry to construct a list of services that it needs to load. There can be multiple instances of Svchost.exe running at the same time. Each Svchost.exe session can contain a grouping of services, so that separate services can be run depending on how and where Svchost.exe is started. This allows for better control and debugging.

Svchost.exe groups are identified in the following registry key:

HKEY_LOCAL_MACHINESoftwareMicrosoftWindows NTCurrentVersionSvchost

Each value under this key represents a separate Svchost group and is displayed as a separate instance when you are viewing active processes. Each value is a REG_MULTI_SZ value and contains the services that run under that Svchost group. Each Svchost group can contain one or more service_names extracted from the following registry key, whose Parameters key contains a ServiceDLL value:

HKEY_LOCAL_MACHINESystemCurrentControlSetServicesService

If you're running Windows XP Home edition then you'll have to download this file HERE and put it in your windows/system32 directory. If you're running XP Pro then you won't need that file since you already have it.

1.) Start --> Run --> cmd
2.) Tasklist /svc >C:ianaginfo.txt

Here's an example of what I got when I issued this command if you'd like to take a look at an example.

A Description of Svchost.exe in Windows XP:
http://support.microsoft.com/?kbid=314056

More Info
More Info

Virus Precaution:
The original file from Microsoft gets placed in the Located in C:WINDOWSSystem32 directory. If you find it anywhere else then you should be suspicious for sure.

You'll want to keep an eye on this google search for any known viruses.


C:\Program Files\Windows Defender\MsMpEng.exe
MsMpEng.exe
MsMpEng.exe is one of the core files to windows defender which is the microsoft anti spyware software.

C:\WINDOWS\System32\svchost.exe
Svchost.exe

What is it?
Service Host Process - svchost.exe

What does it do?

Here's a direct quote from MS about this: (source)
Svchost.exe is a generic host process name for services that are run from dynamic-link libraries (DLLs). The Svchost.exe file is located in the %SystemRoot%System32 folder. At startup, Svchost.exe checks the services portion of the registry to construct a list of services that it needs to load. There can be multiple instances of Svchost.exe running at the same time. Each Svchost.exe session can contain a grouping of services, so that separate services can be run depending on how and where Svchost.exe is started. This allows for better control and debugging.

Svchost.exe groups are identified in the following registry key:

HKEY_LOCAL_MACHINESoftwareMicrosoftWindows NTCurrentVersionSvchost

Each value under this key represents a separate Svchost group and is displayed as a separate instance when you are viewing active processes. Each value is a REG_MULTI_SZ value and contains the services that run under that Svchost group. Each Svchost group can contain one or more service_names extracted from the following registry key, whose Parameters key contains a ServiceDLL value:

HKEY_LOCAL_MACHINESystemCurrentControlSetServicesService

If you're running Windows XP Home edition then you'll have to download this file HERE and put it in your windows/system32 directory. If you're running XP Pro then you won't need that file since you already have it.

1.) Start --> Run --> cmd
2.) Tasklist /svc >C:ianaginfo.txt

Here's an example of what I got when I issued this command if you'd like to take a look at an example.

A Description of Svchost.exe in Windows XP:
http://support.microsoft.com/?kbid=314056

More Info
More Info

Virus Precaution:
The original file from Microsoft gets placed in the Located in C:WINDOWSSystem32 directory. If you find it anywhere else then you should be suspicious for sure.

You'll want to keep an eye on this google search for any known viruses.


C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
EvtEng.exe
EvtEng.exe belongs to EvtEng Module to provide additional support to your Intel Wireless hardware. If you're not using your wireless hardware feel free to remove this.

C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
S24EvMon.exe
S24EvMon.exe is used in the situations where you have a wireless and wired LAN connection at the same time. It acts like a software "bridge" to use the bandwidth of both connections at the same time.

C:\WINDOWS\system32\ZoneLabs\vsmon.exe
vsmon.exe

What is it?
True Vector Internet Monitor - vsmon.exe

What does vsmon.exe do?
This process is associated with Zone Alarm's personal firewall. This is the process that runs in the background and sends you the alert messages anytime an application either breaks one of the already created rules or it doesn't have a rule in place already so you have to "train it".

It is highly suggested that you use a firewall application like this one.

Virus Precautions:
You'll want to keep an eye on this google search for any known viruses. The normal location of vsmon.exe is:
%windows%systemvsmon.exe

At this time There's quite a few viruses running around using this filename!
for vsmon.exe

Also .


C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
ccsetmgr.exe
What Is It?
Norton Security - ccsetmgr.exe

What Does ccsetmgr.exe Do?
This is one of MANY processes that are used by Norton Security (AV + Net Security) If its under the appropriate directory you'll have nothing to worry about. If you're experiencing slowdowns you'll want to upgrade your hard drive and/or your RAM. Norton is a resource hog.

Virus Precautions:
The normal location of ccsetmgr.exe is: C:PROGRAM FILESCOMMON FILESSYMANTEC SHAREDccsetmgr.exe

C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
ZCfgSvc.exe

What is it?

ZCfgSvc.exe is part of intell wireless network adapters proset utility. It is included with the installation of the drivers?and included with the?OEM install of PC?notebooks with Intel Cintrino technology

What does it do?

Allows monitoring and configuration of the wireless connection.

More info:

You can read more about Intel wireless technology's proset utility?and Cintrino device drivers[url=http://support.intel.com/support/wireless/wlan/sb/CS-010623.htm]@ intel.com[/url]


C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
ccevtmgr.exe
What Is It?
Norton Security - ccEvtMgr.exe

What Does ccevtmgr.exe Do?
This is one of MANY processes that are used by Norton Security (AV + Net Security) If its under the appropriate directory you'll have nothing to worry about. If you're experiencing slowdowns you'll want to upgrade your hard drive and/or your RAM. Norton is a resource hog.
This particular process is the event log manager which monitors the virus scanning process and will trigger the alert process as needed.

Virus Precautions:
The normal location of ccevtmgr.exe is: C:PROGRAM FILESCOMMON FILESSYMANTEC SHAREDccevtmgr.exe

C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
1XConfig.exe

What is it?

1XConfig.exe is?associated with?shuttle multimedia device?drivers, software?or?USB utillities.

What does it do?

Provides a tray icon to access and config shuttle multimedia?utillities,?Monitor usb devices, connections?or?configuration.

More info:

Might have been included with software utilities for a Shuttle X?PC, an?OEM slim PC or other add on device,?more specifically USB card readers.

?Not certain about this file,?ask?[url=www.google.com]google[/url]


C:\WINDOWS\Explorer.EXE
explorer.exe

What is it?
Windows Explorer - explorer.exe

What does it do?
explorer.exe - Below is a direct quote from Microsoft found on THIS page:

This is the user shell, which we see as the familiar taskbar, desktop, and so on. This process isn't as vital to the running of Windows as you might expect, and can be stopped (and restarted) from Task Manager, usually with no negative side effects on the system.

I have found that stopping this process is needed sometimes to stop some other processes.

More Info
More Info

Virus Precaution:
The original file from Microsoft gets placed at C:WINDOWSSystem32explorer.exe . if you find it anywhere else then you should be suspicious for sure.

You'll want to keep an eye on this google search for any known viruses. There's only one unique virus found through this search. All of the results are the various names of this single virus.

Deloder-A @ Sophos
MyDoom.B @ Symantec


C:\WINDOWS\system32\spoolsv.exe
Spoolsv.exe
What is it?
SPOOLer SerVice - spoolsv.exe

What does it do?
spoolsv.exe - The spooler service is responsible for managing spooled print/fax jobs

You will be able to end this through task manager!

More info



Virus Precaution:
The spoolsv.exe which is from Microsoft is located at c:windowsSystem32spoolsv.exe . We've been able to find several viruses that run as spoolsv to trick you.

Backdoor.Ciadoor.B - Symantec Corporation
Hacktool.Privshell - Symantec Corporation
VBS.Masscal.Worm (vbs) - Symantec Corporation
Graybird-A @ Sophos

C:\WINDOWS\system32\acs.exe
acs.exe

What is it?

acs.exe is associated with the Atheros configuration service.

What does it do?

used for configuring wireless network connections.

More info:


C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
ALUSchedulerSvc.exe

What is it?

ALUSchedulerSvc.exe or "Live Update" is associated with Symantec's security software.

What does it do?

Symantec Live Update Scheduler handles regularly scheduled automatic software and virus definition updates.

More info:

Read more about Symantec's applications @ symantec.com


C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
btwdins.exe

What is it?

btwdins.exe is an?application for bluetooth wireless communication devices.

What does it do?

Senses the presence of bluetooth enabled devices in the area of?the PC that is equiped with the?bluetooth transceiver.

There are over 1200 unique Bluetooth enabled products on the market ranging from automobiles to personal computers, mobile phones to pulse oximeters. There are over 2000 companies, worldwide, that build Bluetooth wireless technology into their products.

More info:

http://www.bluetooth.com/help/tech.asp

[url=http://www.microsoft.com/hardware/mouseandkeyboard/features/bluetooth.mspx]www.microsoft.com[/url]?bluetooth info


C:\Program Files\Symantec AntiVirus\DefWatch.exe
DefWatch.exe
DefWatch.exe is a part of Norton Antivirus. By Symantec Corporation and is the virus definition monitor that will make sure your virus definitions do not get too horribly outdated. You should leave this process running so your definitions don't get out of date.

C:\Program Files\Intel\Wireless\Bin\OProtSvc.exe
OProtSvc.exe

What is it?

OProtSvc.exe is associated with Intel Proset wireless software.

What does it do?

More info:


C:\WINDOWS\system32\IoctlSvc.exe
IoctlSvc.exe
IoctlSvc.exe - This third party application seems to be harmless, currentely not sure what it does.

C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
RegSrvc.exe
RegSrvc.exe is a part of the Intel PROSet drivers and is used by your wireless connection. Ending this process may cause your network connection to quit working properly.

C:\WINDOWS\system32\svchost.exe
Svchost.exe

What is it?
Service Host Process - svchost.exe

What does it do?

Here's a direct quote from MS about this: (source)
Svchost.exe is a generic host process name for services that are run from dynamic-link libraries (DLLs). The Svchost.exe file is located in the %SystemRoot%System32 folder. At startup, Svchost.exe checks the services portion of the registry to construct a list of services that it needs to load. There can be multiple instances of Svchost.exe running at the same time. Each Svchost.exe session can contain a grouping of services, so that separate services can be run depending on how and where Svchost.exe is started. This allows for better control and debugging.

Svchost.exe groups are identified in the following registry key:

HKEY_LOCAL_MACHINESoftwareMicrosoftWindows NTCurrentVersionSvchost

Each value under this key represents a separate Svchost group and is displayed as a separate instance when you are viewing active processes. Each value is a REG_MULTI_SZ value and contains the services that run under that Svchost group. Each Svchost group can contain one or more service_names extracted from the following registry key, whose Parameters key contains a ServiceDLL value:

HKEY_LOCAL_MACHINESystemCurrentControlSetServicesService

If you're running Windows XP Home edition then you'll have to download this file HERE and put it in your windows/system32 directory. If you're running XP Pro then you won't need that file since you already have it.

1.) Start --> Run --> cmd
2.) Tasklist /svc >C:ianaginfo.txt

Here's an example of what I got when I issued this command if you'd like to take a look at an example.

A Description of Svchost.exe in Windows XP:
http://support.microsoft.com/?kbid=314056

More Info
More Info

Virus Precaution:
The original file from Microsoft gets placed in the Located in C:WINDOWSSystem32 directory. If you find it anywhere else then you should be suspicious for sure.

You'll want to keep an eye on this google search for any known viruses.


C:\Program Files\Symantec AntiVirus\Rtvscan.exe
rtvscan.exe

What is it?
Real Time Virus scan (Symantec Security) - rtvscan.exe


What does it do?
Symantec Internet Security Suite is taking Norton AV to another level and scan the files as they enter your system instead of the usual scan right after they hit your system. You should not end this process if you have it running.

Virus Precautions:
You'll want to keep an eye on this google search for any known viruses. The normal location of this file is C:Program FilesSymantec_Client_SecuritySymantec AntiVirusRtvscan.exe


Also .


C:\WINDOWS\system32\igfxtray.exe
igfxtray.exe

What is it?
Intel Graphics Tray- igfxtray.exe

What does it do?
igfxtray.exe? - This application gives you easy access to your Intel graphics configuration by giving options to you in the system tray.

Virus Precautions:
You'll want to keep an eye on this google search for any known viruses. The normal location of this file is C:WINNTSystem32igfxtray.exe


C:\WINDOWS\system32\hkcmd.exe
hkcmd.exe

What is it?
Intel's HotKey Command - hkcmd.exe

What does hkcmd.exe do?
Not much data has been found on this. It seems like every manufacturer has their own hotkey programming application and this is the one brought to you by Intel.

Virus Precautions:
You'll want to keep an eye on this google search for any known viruses. The normal location of hkcmd.exe is
C:WINDOWSSystem32hkcmd.exe

At this time no viruses were found running as this process. You will want to check since new bugs come through daily.

Also .


C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
SynTPLpr.exe
SynTPLpr.exe is Synaptics touchpad driver helper. Required for touchpad features to work. More information can be found here.

Quote:

Synaptics TouchPad? devices are touch-sensitive pads that sense the position of a person's finger on its surface to provide screen navigation, cursor movement, and a platform for interactive input. Synaptics TouchPad devices are the industry leading solution, known for their durability, reliability, and accuracy. Synaptics TouchPad solutions can be custom designed to meet your requirements for sizes, thickness, feature functionality and electrical interfaces.

Synaptics TouchPad devices also offer advanced device driver features that allow end users to customize their TouchPad device settings to meet their individual preferences.



C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
SynTPEnh.exe
SynTPEnh.exe is Synaptics touchpad driver helper. Required for touchpad features to work. More information can be found here.

Quote:

Synaptics TouchPad? devices are touch-sensitive pads that sense the position of a person's finger on its surface to provide screen navigation, cursor movement, and a platform for interactive input. Synaptics TouchPad devices are the industry leading solution, known for their durability, reliability, and accuracy. Synaptics TouchPad solutions can be custom designed to meet your requirements for sizes, thickness, feature functionality and electrical interfaces.

Synaptics TouchPad devices also offer advanced device driver features that allow end users to customize their TouchPad device settings to meet their individual preferences.


C:\Program Files\acer\Wireless\Utility\WlanUtil.exe
wlanutil.exe
wlanutil.exe - This is a wireless LAN configuration utility.

C:\Program Files\Atheros\ACU.exe
ACU.exe
We Don't know! Please post a comment with information about this file

C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
ifrmewrk.exe
ifrmewrk.exe - This is a process with Intel/Pro wireless software.

C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe
EOUWiz.exe
EOUWiz.exe - This process is not visible it can be uninstalled in the control panel, this starts when Windows starts but is is not A Windows core program, this is able to record inputs, the danger with this process is 6%.

C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
jusched.exe

What is it?
Java Update Scheduler - jusched.exe

What does it do?
jusched.exe - This is Sun's Java automatic update utility. If you would like to disable this scheduler then go to your control panel and click on the java module. The go to the updates tab and uncheck "check for updates automatically".

Virus Precautions:
You'll want to keep an eye on this google search for any known viruses. The normal location of jusched.exe is
C:Program FilesJavaj2re1.4.2_04injusched.exe. Obviously j2re1.4.2_04 is the version number. At this time my search shows nothing that you need to worry about..


C:\Program Files\Prolific\USB Flash Disk Utility\PLBkMon.exe
PLBkMon.exe
We Don't know! Please post a comment with information about this file

C:\WINDOWS\system32\HotfixQ0306270.exe
HotfixQ0306270.exe
We Don't know! Please post a comment with information about this file

C:\Program Files\Picasa2\PicasaMediaDetector.exe
PicasaMediaDetector.exe
PicasaMediaDetector.exe is Picasa an automated photo organizer. More information can be found here.

Quote:
A free software download from Google.

Picasa is software that helps you instantly find, edit and share all the pictures on your PC. Every time you open Picasa, it automatically locates all your pictures (even ones you forgot you had) and sorts them into visual albums organized by date with folder names you will recognize. You can drag and drop to arrange your albums and make labels to create new groups. Picasa makes sure your pictures are always organized.



C:\Program Files\Common Files\Symantec Shared\ccApp.exe
ccApp.exe
What Is It?
Norton Security - ccApp.exe
?
What Does it Do?
ccapp.exe - This is one of MANY processes that are used by Norton Security (AV + Net Security) If its under the appropriate directory you'll have nothing to worry about. If you're experiencing slowdowns you'll want to upgrade your hard drive and/or your RAM. Norton is a resource hog.
This process is referred to as Common Client App which is also used by auto protect and email checking.

Virus Precautions:
The normal location of ccapp.exe is: C:Program FilesCommon FilesSymantec Sharedccapp.exe

C:\PROGRA~1\SYMANT~1\VPTray.exe
vptray.exe

What is it?
Norton AV Tray icon- vptray.exe


What does it do?
This executable belongs to Norton Antivirus and is nothing more than a try icon which gives you quicker access to various settings. I hate cluttered task bars so I personally would end this task from my startup list.

Virus Precautions:
You'll want to keep an eye on this google search for any known viruses. The normal location of this file is C:Program FilesSymantec_Client_SecuritySymantec AntiVirusvptray.exe


C:\WINDOWS\VM_STI.EXE
VM_STI.EXE

This is a valid program that is bundled with many digital cameras that use a USB connection. It is unknown at this time whether or not it is needed to run.

C:\Program Files\Windows Defender\MSASCui.exe
MSASCui.exe
MSASCui.exe is a part of the windows defender program which runs in the background to protect you from spyware.

C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
zlclient.exe

What is it?
Zone Alarm - zlclient.exe

What does it do?
zlclient.exe is a part of Zone Labs Internet Security. You should not end this process for any reason. This is the firewall I use behind my router as a second level of protection. The most important part of this is having to give permission to applications before they access the internet in any way. routers and the windows firewall have a tendency to allow anything out and only blocking inbound connections.

Virus Precautions:
You'll want to keep an eye on this google search for any known viruses. The normal location of this file is C:Program Filesone LabsoneAlarmzlclient.exe


C:\Program Files\iTunes\iTunesHelper.exe
iTunesHelper.exe
iTunesHelper.exe belongs to Apples Itunes which is an online MP3 store. Ituneshelper.exe will play the music and it also monitors for when you plug your ipod in so it can transfer files over to it.

Ipod's rock... Even with the horrible U2... U2 sucks and Bono needs to keep his mouth shut and out of politics. Nobody cares what a musician thinks.

Oh wait, Bono isn't a musician....

C:\Program Files\iPod\bin\iPodService.exe
iPodService.exe
iPodService.exe monitors for when you connect your ipod. see also ituneshelper.exe. Ipods are great and if you own one you are slightly cooler than me.

C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe
DesktopWeather.exe
DesktopWeather.exe - This is the weather channels desktop program.

C:\WINDOWS\system32\ctfmon.exe
ctfmon.exe
What is it?
Language bar AKA Alternative User Input Services - ctfmon.exe

What does it do?
ctfmon.exe - it's an ever annoying helper tool that comes rather unexpectedly at times and liked by nearly nobody.

Ctfmon.exe monitors the active windows and provides text input service support for speech recognition, handwriting recognition, keyboard, translation, and other alternative user input technologies.

Loads of information can be found on microsoft's site here.

Unless you're using anything in that list above you'll want to stop this file from loading!

How do I get rid of it?
There's been a number of threads in our forum as well as others about this. A typical thread can be found here.

control panel --> regional and language options --> languages tab --> details button --> language bar button

Virus Precaution:
Just like so many of the other files I've written about so far, ctfmon.exe is located in the c:windowsSystem32ctfmon.exe. At the time of this writing there isn't any spyware, viruses or anything like that masking itself as this file. If you find any info on one then please let me know!

C:\Program Files\Adobe\Acrobat 4.0\Distillr\AcroTray.exe
acrotray.exe

What is it?
Adobe Acrobat Distiller - acrotray.exe

What does it do?
While printing large files to the PDF format this process may consume large chunks of your CPU. Do not end this process if you're printing something to PDF.

Virus Precautions:
You'll want to keep an eye on this google search for any known viruses. The normal location of this file is C:Program FilesAdobeAcrobat 6.0Distillracrotray.exe


Also .


C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
BTTray.exe
BTTray.exe is a System tray icon which shows the status of a BlueTooth wireless module. Most systems with such a module installed can enable/disable the module. The system tray icon changes from blue/white to blue/red when the module is turned off. Allows access to explore bluetooth places, setup wizard, advanced configuration, quick connect and shutdown device

C:\Program Files\WordWeb\wweb32.exe
wweb32.exe
wweb32.exe - This process is from WordWeb thesaurus/dictionary, this is non esential only terminate if causing problems.

C:\WINDOWS\system32\wuauclt.exe
wuauclt.exe

What is it?
Windows Update Automatic Client - wuauclt.exe

What does it do?
wuauclt.exe - This is used by the automatic update tool in Windows ME to check the Windows Update site every so often to see if any updates need to be installed.

More Info
More Info

Virus Precaution:
The original wuauclt.exe from Microsoft gets placed in the Located at C:WINDOWSSystem32wuauclt.exe . If you find it anywhere else then you should be suspicious for sure.

You'll want to keep an eye on this google search for any known viruses.

.

Backdoor.Clt @ Symantec Corporation
Troj/Cult-B @ Sophos


C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
What is it?
Internet Explorer - iexplore.exe


What does iexplore.exe do?
This is the main executable to the browser brought to you by Microsoft. If you're using this then please look into Firefox. This browser is a security hazard

Microsoft's information page.

Virus Precautions:
You'll want to keep an eye on this google search for any known viruses. The normal location of iexplore.exe is C:Program FilesInternet Exploreriexplore.exe There's a LOT of bugs you need to worry about if the exe is running in any location other than that one.


search Trend Micro.

C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
What is it?
Internet Explorer - iexplore.exe


What does iexplore.exe do?
This is the main executable to the browser brought to you by Microsoft. If you're using this then please look into Firefox. This browser is a security hazard

Microsoft's information page.

Virus Precautions:
You'll want to keep an eye on this google search for any known viruses. The normal location of iexplore.exe is C:Program FilesInternet Exploreriexplore.exe There's a LOT of bugs you need to worry about if the exe is running in any location other than that one.


search Trend Micro.

C:\Program Files\Hijackthis\HijackThis.exe
HijackThis.exe
This is our favorite application for fighting against malware and other trashy application that bog systems down. Our guide to using this software can be found here. We have also taken the time to write a system to process the log files created from this application here.


R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
Internet Start Page
This is where you go when you first open IE. Should be something like google.com or iamnotageek.com if theres a site you don't know here clean this line!

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
Internet Start Page
This is where you go when you first open IE. Should be something like google.com or iamnotageek.com if theres a site you don't know here clean this line!

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
Internet Start Page
This is where you go when you first open IE. Should be something like google.com or iamnotageek.com if theres a site you don't know here clean this line!

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
Internet Start Page
This is where you go when you first open IE. Should be something like google.com or iamnotageek.com if theres a site you don't know here clean this line!

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
Internet Start Page
This is where you go when you first open IE. Should be something like google.com or iamnotageek.com if theres a site you don't know here clean this line!

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
Internet Start Page
This is where you go when you first open IE. Should be something like google.com or iamnotageek.com if theres a site you don't know here clean this line!

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
AcroIEhelper.ocx AcroIEhelper.dll - Adobe Acrobat reader http://www.adobe.com/products/acrobat/reads
AcroIEhelper.ocx AcroIEhelper.dll - Adobe Acrobat reader http://www.adobe.com/products/acrobat/readstep2.html

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
SDhelper.dll - SpyBot Search&Destroy http://www.safer-networking.org/index.php
SDhelper.dll - SpyBot Search&Destroy http://www.safer-networking.org/index.php

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
Unnamed BHO
ssv.dll - Related to Sun_Java_software http://java.com/en/download/index.jsp

O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
IgfxTray
"System Tray access to display settings for Intel desktop and mobile motherboard chipsets with integrated graphics. With this enabled

O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
HotKeysCmds
"Hot Key handler for Intel desktop and mobile motherboard chipsets with integrated graphics. With this enabled

O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
SynTPLpr
"Synaptics TouchPad driver helper - included with drivers for Synaptics based TouchPads

O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
SynTPEnh
"Synaptics TouchPad Enhancements - included with drivers for Synaptics based TouchPads

O4 - HKLM\..\Run: [acerWireless] C:\Program Files\acer\Wireless\Utility\WlanUtil.exe
Unknown Item
Sorry. We are not sure what this item is. If you would like, you can click on it to request additional information about it.

O4 - HKLM\..\Run: [ACU] "C:\Program Files\Atheros\ACU.exe" -nogui
ACU
"Atheros wireless Client Utility"

O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
IntelWireless
Associated with the Intel PRO/Set Wireless software

O4 - HKLM\..\Run: [EOUApp] C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe
EOUApp
Intel ProSET Wireless related - provides additional configuration options for these devices

O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
SunJavaUpdateSched
"Checks with Sun's Java updates site to see if newer Java versions are available. Either visit the Java download page or click on Start → Control Panel → Java → Update → Update Now"

O4 - HKLM\..\Run: [Prolific_PLUtil] C:\Program Files\Prolific\USB Flash Disk Utility\PLBkMon.exe
Unknown Item
Sorry. We are not sure what this item is. If you would like, you can click on it to request additional information about it.

O4 - HKLM\..\Run: [PLFFAP] C:\WINDOWS\system32\HotfixQ0306270.exe
PLFFAP
"Prolific Technology Inc. USB Flash Disk driver - is it required in startup?"

O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
Picasa Media Detector
"Media detector for Picasa's automatic photo organizer"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
QuickTime Task
System Tray access to Apple's "Quick Time" viewer from version 5 onwards

O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
ccApp
"Part of earlier versions of Norton AntiVirus - Auto-protect and E-mail check will not function without this"

O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
vptray
"System Tray icon for Norton Anti-Virus Corporate Edition. Gives access to the options available and may not be required. Some users may have problems - refer here"

O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE Vimicro USB PC Camera (VC0305)
BigDogPath
"Bundled with some software for digital cameras that use a USB connection - what does it do and is it required?"

O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
Windows Defender
"Main user interface for Microsoft's Windows Defender on XP/Vista - which ""helps protect your computer against pop-ups

O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
Zone Labs Client
"Firewall program from Zonelabs. Pro version inlcudes other online security options"

O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
iTunesHelper
Installed with Apple's iTunes for Windows. Uses ~3-4MB of memory and if disabled in MSCONFIG or deleted from the registry it will re-instate itself after running iTunes a few times - hence the reluctant Y recommendation

O4 - HKCU\..\Run: [DW4] "C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe"
DW4
"Desktop Weather 4 by The Weather Channel - provides current temperature

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
Ctfmon.exe
"CoolWebSearch Ctfmon32 parasite variant"

O4 - Startup: WordWeb.lnk = C:\Program Files\WordWeb\wweb32.exe


O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 4.0\Distillr\AcroTray.exe


O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe


O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe


O4 - Global Startup: BTTray.lnk = ?


O8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
Internet Right Click Menu
Most of the time this is garbage leave it only if you actually use this function. Otherwise for the sake of cleanliness get rid of this sucker. A wise man once said Cleanliness is next to godliness

O8 - Extra context menu item: &WordWeb... - res://C:\WINDOWS\wweb32.dll/lookup.html
Internet Right Click Menu
Most of the time this is garbage leave it only if you actually use this function. Otherwise for the sake of cleanliness get rid of this sucker. A wise man once said Cleanliness is next to godliness

O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
Internet Right Click Menu
Most of the time this is garbage leave it only if you actually use this function. Otherwise for the sake of cleanliness get rid of this sucker. A wise man once said Cleanliness is next to godliness

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Internet Right Click Menu
Most of the time this is garbage leave it only if you actually use this function. Otherwise for the sake of cleanliness get rid of this sucker. A wise man once said Cleanliness is next to godliness

O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
Internet Right Click Menu
Most of the time this is garbage leave it only if you actually use this function. Otherwise for the sake of cleanliness get rid of this sucker. A wise man once said Cleanliness is next to godliness

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
Sun Java Console
Related to Sun Java

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
Sun Java Console
Related to Sun Java

O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
ieSpell
ieSpell - A Spell Checker for Internet Explorer

O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
ieSpell
ieSpell - A Spell Checker for Internet Explorer

O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
ieSpell Options
Related to ieSpell - A Spell Checker for Internet Explorer. Note: The entry's name may also be (no file)

O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
ieSpell Options
Related to ieSpell - A Spell Checker for Internet Explorer. Note: The entry's name may also be (no file)

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
Research
Microsoft Office related

O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
@btrez.dll-401x
BlueTooth

O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
@btrez.dll-401x
BlueTooth

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
File Missing
When a file is missing, you should always have HijackThis fix the item.

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
File Missing
When a file is missing, you should always have HijackThis fix the item.

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
Windows Messenger
Related to Microsoft's Windows Messenger.

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
Windows Messenger
Related to Microsoft's Windows Messenger.

O11 - Options group: [INTERNATIONAL] International*
IE Advanced Options
This is rarely modified by programs.

O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - http://www.andhrajyothy.com/wfplayer/tdserver.cab
Unnamed BHO
http://www.truedoc.com

O16 - DPF: {2B1AA38D-2D12-11D5-AAD0-00C04FA03D78} (LocalExec Control) - https://insite.warwick.ac.uk/nps/portal/gadgets/com.novell.nps.gadgets.shortcut.ShortcutGadget/LocalExec.CAB
Unknown Item
Sorry. We are not sure what this item is. If you would like, you can click on it to request additional information about it.

O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
Unnamed BHO
yinst0401.cab - Yahoo Messenger Installer

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1128587475843
muweb_site.cab
Microsoft Windows Update more here

O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab
Unnamed BHO
http://messenger.yahoo.com

O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
Unnamed BHO
http://messenger.msn.com

O16 - DPF: {CE3409C4-9E26-4F8E-83E4-778498F9E7B4} (PB_Uploader Class) - http://static.photobox.co.uk/sg/common/uploader.cab
Unknown Item
Sorry. We are not sure what this item is. If you would like, you can click on it to request additional information about it.

O17 - HKLM\System\CCS\Services\Tcpip\..\{49CAF0DE-207D-44EF-88E8-F5BDC4FFD8EA}: NameServer = 192.168.10.51,202.9.145.6
Internet Settings
These may not be bad if your internet connection is set manually

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
File Missing
When a file is missing, you should always have HijackThis fix the item.

O18 - Protocol: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - C:\WINDOWS\system32\btxppanel.dll
Extra Protocols
There's a few known hijackers that use this but I haven't found anything good come out of these

O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
AppInit_DLLs Registry value autorun
Very few known *good* purposes of this. Norton Cleansweep being the headliner of good items
Loads a .dll into memory when a user logs in. Frequently used by VERY bad hijackers.

O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
AppInit_DLLs Registry value autorun
Very few known *good* purposes of this. Norton Cleansweep being the headliner of good items
Loads a .dll into memory when a user logs in. Frequently used by VERY bad hijackers.

O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
AppInit_DLLs Registry value autorun
Very few known *good* purposes of this. Norton Cleansweep being the headliner of good items
Loads a .dll into memory when a user logs in. Frequently used by VERY bad hijackers.

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
ShellServiceObjectDelayLoad Registry key autorun
HJT automatically weeds out the good ones here so we'll flag this as bad. Consult a HJT expert before cleaning anything.

O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
Atheros Configuration Service
related to Atheros Wireless LAN

O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
Automatic LiveUpdate Scheduler
Related to to the Symantec LiveUpdate service which updates your Symantec products periodically.

O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
Bluetooth Service
Bluetooth Service

O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
Symantec Event Manager

Symantec Life Update service used for auto updating symantec products in the background. Commonly in \%Program Files%\Common Files\Symantec Shared\


O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
Unknown Item
Sorry. We are not sure what this item is. If you would like, you can click on it to request additional information about it.

O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
Symantec Settings Manager

Norton/symantec settings manager. There has been a couple known problem files using this startup name. Check the folder this file is running from.


O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
Symantec AntiVirus Definition Watcher
Related to Symantec AntiVirus Software.

O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
EvtEng
Related to Intel Corporation http://www.what-process.com/process-info.aspx?p=EvtEng.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
Google Updater Service
(gusvc) - Google - commonly found in a location like this: C:Program Files (x86)GoogleCommonGoog

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
InstallDriver Table Manager
Related to Macrovision Corporation.

O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
Unknown Item
Sorry. We are not sure what this item is. If you would like, you can click on it to request additional information about it.

O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
LiveUpdate
Related to Norton Internet securty suite and provides up to date antivirus data for your Norton Anti

O23 - Service: OwnershipProtocol - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\OProtSvc.exe
OwnershipProtocol
Related to PROSet Wireless Software from Intel

O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
PLFlash DeviceIoControl Service
Related to PLFlash_DeviceIoControl Service from Prolific Technology Inc. Note: located in C:WindowsS

O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
RegSrvc
Intel PROset

O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
File Missing
When a file is missing, you should always have HijackThis fix the item.

O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
Spectrum24 Event Monitor
Intel Corporation

O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
SAVRoam
Related to Norton/Symantec AntiVirus

O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
Symantec Network Drivers Service

Norton Personal Firewall and Norton Internet Security. believed to be the email scanner.


O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
Unknown Item
Sorry. We are not sure what this item is. If you would like, you can click on it to request additional information about it.

O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
Symantec AntiVirus
Related to Symantec AntiVirus

O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
TrueVector Internet Monitor
Zone Alarm Firewall