Options

win32 trojan problems

Hi and thank you for taking the time to look at this thread.

A couple of days ago, avast had found a win32 trojan not once but quite a few times and each time I ran adaware it removed it but it keeps coming back after a reboot. It also kept changing my homepage as well as pop ups. I have followed the instructions in this thread http://www.short-media.com/forum/showthread.php?t=43902

Please help in getting rid of the nasties.

Panda Log:
Incident Status Location

Spyware:Cookie/Tickle Not disinfected C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\default.w9m\cookies.txt[]
Adware:adware/tvmedia Not disinfected C:\Documents and Settings\Owner\Application Data\tvmcwrd.dll
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Owner\Cookies\owner@ad.yieldmanager[1].txt
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Owner\Cookies\owner@com[1].txt
Spyware:Cookie/Advnt Not disinfected C:\Documents and Settings\Owner\Cookies\owner@www.advnt01[1].txt
Spyware:Cookie/myaffiliateprogram Not disinfected C:\Documents and Settings\Owner\Cookies\owner@www.myaffiliateprogram[2].txt
Adware:Adware/WebHancer Not disinfected C:\Documents and Settings\Owner\Local Settings\Temp\temp.fr61AD\Programs\webhdll.dll
Adware:Adware/WebHancer Not disinfected C:\Documents and Settings\Owner\Local Settings\Temp\temp.frF129\Programs\webhdll.dll
Adware:Adware/WebHancer Not disinfected C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\Y7YZ2PEN\WHCC2[1].exe
Adware:Adware/WebHancer Not disinfected C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\Y7YZ2PEN\WHCC2[1].exe[whAgent.exe]
Adware:Adware/WebHancer Not disinfected C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\Y7YZ2PEN\WHCC2[1].exe[whInstaller.exe]
Adware:Adware/WebHancer Not disinfected C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\Y7YZ2PEN\WHCC2[1].exe[whSurvey.exe]
Adware:Adware/WebHancer Not disinfected C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\Y7YZ2PEN\WHCC2[1].exe[webhdll.dll]
Adware:Adware/WebHancer Not disinfected C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\Y7YZ2PEN\WHCC2[1].exe[whiehlpr.dll]
Potentially unwanted tool:Application/HideWindow.A Not disinfected C:\hp\bin\FondleWindow.exe
Potentially unwanted tool:Application/KillApp.B Not disinfected C:\hp\bin\KillIt.exe
Potentially unwanted tool:Application/KillApp.A Not disinfected C:\hp\bin\Terminator.exe
Adware:Adware/Yazzle Not disinfected C:\SnowballWarsInstaller.exe
Adware:adware/adroar Not disinfected C:\WINDOWS\artmmp.ini
Adware:Adware/IPInsight Not disinfected C:\WINDOWS\inf\conscorr.inf
Adware:Adware/LocalNRD Not disinfected C:\WINDOWS\inf\localNrd.inf
Adware:Adware/DollarRevenue Not disinfected C:\WINDOWS\keyboard12.exe
Dialer:dialer.bny Not disinfected C:\WINDOWS\pcconfig.dat
Adware:Adware/Deskwizz Not disinfected C:\WINDOWS\sk02.exe
Dialer:dialer.b Not disinfected C:\WINDOWS\tmlpcert2005

Kapersky Log:

KASPERSKY ON-LINE SCANNER REPORT
Saturday, April 22, 2006 9:30:58 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky On-line Scanner version: 5.0.78.0
Kaspersky Anti-Virus database last update: 22/04/2006
Kaspersky Anti-Virus database records: 177985

Scan Settings:
Scan using the following antivirus database: standard
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\
M:\

Scan Statistics:
Total number of scanned objects: 86914
Number of viruses found: 9
Number of infected objects: 30
Number of suspicious objects: 0
Duration of the scan process: 01:21:39

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\Owner\.housecall\Quarantine\drsmartload1.exe.bac_a02544 Infected: Trojan-Downloader.Win32.Adload.au skipped
C:\Documents and Settings\Owner\.housecall\Quarantine\drsmartload45a.exe.bac_a02544 Infected: Trojan-Downloader.Win32.Adload.as skipped
C:\Documents and Settings\Owner\.housecall\Quarantine\drsmartload45a[1].exe.bac_a02544 Infected: Trojan-Downloader.Win32.Adload.as skipped
C:\Documents and Settings\Owner\.housecall\Quarantine\drsmartload[1].exe.bac_a02544 Infected: Trojan-Downloader.Win32.Adload.au skipped
C:\Documents and Settings\Owner\.housecall\Quarantine\mousepad12.exe.bac_a02544 Infected: Trojan-Clicker.Win32.VB.mo skipped
C:\Documents and Settings\Owner\.housecall\Quarantine\mousepad12[1].exe.bac_a02544 Infected: Trojan-Clicker.Win32.VB.mo skipped
C:\Documents and Settings\Owner\.housecall\Quarantine\newname12.exe.bac_a02544 Infected: Trojan-Downloader.Win32.VB.aaf skipped
C:\Documents and Settings\Owner\.housecall\Quarantine\newname12[1].exe.bac_a02544 Infected: Trojan-Downloader.Win32.VB.aaf skipped
C:\Documents and Settings\Owner\.housecall\Quarantine\sk02.exe.bac_a02544/data0002 Infected: Trojan-Clicker.Win32.Small.jf skipped
C:\Documents and Settings\Owner\.housecall\Quarantine\sk02.exe.bac_a02544 NSIS: infected - 1 skipped
C:\Documents and Settings\Owner\.housecall\Quarantine\sk02.exe.bac_a02544 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\Owner\.housecall\Quarantine\sk02[1].exe.bac_a02544/data0002 Infected: Trojan-Clicker.Win32.Small.jf skipped
C:\Documents and Settings\Owner\.housecall\Quarantine\sk02[1].exe.bac_a02544 NSIS: infected - 1 skipped
C:\Documents and Settings\Owner\.housecall\Quarantine\sk02[1].exe.bac_a02544 CryptFF.b: infected - 1 skipped
C:\SnowballWarsInstaller.exe/data0006 Infected: Trojan-Downloader.Win32.PurityScan.cf skipped
C:\SnowballWarsInstaller.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{344D6A0F-CE3C-4FE8-85DE-CCCF54169E06}\RP806\A0058192.exe Infected: Trojan-Downloader.Win32.Adload.au skipped
C:\System Volume Information\_restore{344D6A0F-CE3C-4FE8-85DE-CCCF54169E06}\RP806\A0058193.exe Infected: Trojan-Downloader.Win32.Adload.as skipped
C:\System Volume Information\_restore{344D6A0F-CE3C-4FE8-85DE-CCCF54169E06}\RP806\A0058194.exe/data0002 Infected: Trojan-Clicker.Win32.Small.jf skipped
C:\System Volume Information\_restore{344D6A0F-CE3C-4FE8-85DE-CCCF54169E06}\RP806\A0058194.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{344D6A0F-CE3C-4FE8-85DE-CCCF54169E06}\RP806\A0058195.exe Infected: Trojan-Downloader.Win32.VB.aaf skipped
C:\System Volume Information\_restore{344D6A0F-CE3C-4FE8-85DE-CCCF54169E06}\RP809\A0058684.exe Infected: Trojan-Downloader.Win32.VB.aaf skipped
C:\System Volume Information\_restore{344D6A0F-CE3C-4FE8-85DE-CCCF54169E06}\RP809\A0058685.exe Infected: Trojan-Clicker.Win32.VB.mo skipped
C:\System Volume Information\_restore{344D6A0F-CE3C-4FE8-85DE-CCCF54169E06}\RP809\A0058686.exe Infected: Trojan-Downloader.Win32.VB.abj skipped
C:\System Volume Information\_restore{344D6A0F-CE3C-4FE8-85DE-CCCF54169E06}\RP809\A0058688.exe Infected: Trojan-Downloader.Win32.Adload.as skipped
C:\System Volume Information\_restore{344D6A0F-CE3C-4FE8-85DE-CCCF54169E06}\RP809\A0058689.exe Infected: Trojan-Downloader.Win32.VB.abm skipped
C:\WINDOWS\keyboard12.exe Infected: Trojan-Downloader.Win32.VB.abd skipped
C:\WINDOWS\mousepad12.exe Infected: Trojan-Clicker.Win32.VB.mo skipped
C:\WINDOWS\sk02.exe/data0002 Infected: Trojan-Clicker.Win32.Small.jf skipped
C:\WINDOWS\sk02.exe NSIS: infected - 1 skipped

Scan process completed.

HijackThis Log:
Logfile of HijackThis v1.99.1
Scan saved at 9:37:38 PM, on 22/04/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\windows\system\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\WINDOWS\System32\hphmon05.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Messenger Plus! 3\MsgPlus.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\MYPRES~1\Presario\XPHAPRF3EN\plugin\bin\pchbutton.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qau9.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bigpond.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://qau9.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.ninemsn.com.au/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = BigPond Dial-Up Residential Internet Explorer
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - c:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: - {A0DE02AB-8DED-45E4-83D4-2B50CDCB7E2E} - C:\WINDOWS\lbbho.dll (file missing)
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [CamMonitor] c:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [STOPzilla] "C:\Program Files\STOPzilla!\Stopzilla.exe" /autorun
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [winupdates] C:\Program Files\winupdates\winupdates.exe /auto
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [MoneyAgent] "c:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [Riced web link] "C:\Program Files\Riced\screen saver\FWLink.exe"
O4 - HKCU\..\Run: [Acme.PCHButton] C:\PROGRA~1\MYPRES~1\Presario\XPHAPRF3EN\plugin\bin\pchbutton.exe
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra button: ICQ 4.1 - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.bigpond.com/
O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl Class) - https://components.viewpoint.com/MTSInstallers/MetaStream3.cab?url=http://www.viewpoint.com/cgi-bin/installer.v3/vet_install_popup.pl?1&4&04.00.07.02&unknown&unknown&http://www.holden3d.com.au/commodore/VY_Series2/content.asp?model=15
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by10fd.bay10.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - http://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{39B58940-DF3D-4C99-8AC3-EE1A3294413C}: NameServer = 192.168.1.254
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

Comments

Sign In or Register to comment.