Yes that is my ISP. I did aready change my DNS back to automatic but i do think there is a problem with my IP.
Earlier today i disconnected my pc from the internet and connected my laptop thats what im on now) so i could safely change my online banking passwords ... However, i seem to have the same redirecting problem on my laptop now aswell!
Could this be beacuse i connected through the same modem and internet source?
Should i post AVG and HJT logs for my laptop aswell ... and have i managed to mess my laptop up now aswell?!!
The messages from Norton vary but they are always some sort of Trojan. I'm not on that pc now though so im not getting the pop ups to copy and paste.
There should only be 2 users, Sarah and Admin however at some point in the past an ex of mine decided he would mess around with my pc so i'm not entirely sure.
That folder appears to lead to a LOCAL folder and then into various Realtek files which i think is to do with my audio?
Here are the logs for my pc:
"Sarah" - 07-02-08 21:44:13 Service Pack 2
ComboFix 07-02-07 - Running from: "C:\Documents and Settings\Sarah.SARAHS-PC\Desktop"
((((((((((((((((((((((((((((((( Files Created from 2007-01-08 to 2007-02-08 ))))))))))))))))))))))))))))))))))
2007-02-08 14:28 524,288 --ah----- C:\DOCUME~1\ADMINI~1.SAR\NTUSER.DAT
2007-02-08 13:58 <DIR> d-------- C:\fixwareout
2007-02-08 13:48 767,308 ---hs---- C:\WINDOWS\system32\mnnmp.bak2
2007-02-08 13:48 178,408 --a------ C:\WINDOWS\system32\muweb.dll
2007-02-08 02:03 497,496 --a------ C:\WINDOWS\system32\XceedZip.dll
2007-02-07 22:58 753,157 ---hs---- C:\WINDOWS\system32\mnnmp.ini2
2007-02-07 22:43 65,536 --a------ C:\WINDOWS\system32\Schedule.dll
2007-02-07 22:42 512,688 --a------ C:\WINDOWS\system32\XceedCry.dll
2007-02-07 22:42 423,784 --a------ C:\WINDOWS\system32\XceedBkp.dll
2007-02-07 22:42 118,784 --a------ C:\WINDOWS\system32\msstdfmt.dll
2007-02-07 22:42 101,888 --a------ C:\WINDOWS\system32\VB6STKIT.DLL
2007-02-07 20:53 <DIR> d-------- C:\Program Files\RegCure
2007-02-07 15:24 <DIR> d-------- C:\HijackThis
2007-02-07 14:31 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-02-07 14:31 <DIR> d-------- C:\Program Files\Grisoft
2007-02-07 14:13 <DIR> d-------- C:\Program Files\CCleaner
2007-02-07 13:59 <DIR> d-------- C:\DOCUME~1\SARAH~1.SAR\Application Data\Google
2007-02-07 13:59 <DIR> d-------- C:\DOCUME~1\ALLUSE~1.WIN\Application Data\Google
2007-02-07 13:58 <DIR> d-------- C:\Program Files\Google
2007-02-07 13:58 <DIR> d-------- C:\DOCUME~1\ALLUSE~1.WIN\Application Data\Google Updater
2007-02-07 02:22 734,404 ---hs---- C:\WINDOWS\system32\mnnmp.bak1
2007-02-07 02:22 277,184 ---hs---- C:\WINDOWS\system32\pmnnm.dll
2007-02-07 02:16 22,757 ---hs---- C:\WINDOWS\system32\gebayyy.dll
2007-02-07 01:03 <DIR> d-------- C:\WINDOWS\network diagnostic
2007-02-06 17:42 <DIR> d-------- C:\DOCUME~1\SARAH~1.SAR\Application Data\TrojanHunter
2007-02-06 00:19 4,096 --a------ C:\WINDOWS\d3dx.dat
2007-02-06 00:06 0 -rahs---- C:\MSDOS.SYS
2007-02-06 00:06 0 -rahs---- C:\IO.SYS
2007-02-05 19:13 <DIR> d-------- C:\Program Files\ParetoLogic
2007-02-05 19:13 <DIR> d-------- C:\DOCUME~1\SARAH~1.SAR\Application Data\ParetoLogic
2007-02-05 01:56 <DIR> d-------- C:\Program Files\Encore
2007-02-05 01:40 <DIR> d-------- C:\Program Files\Common Files\Hoyle Poker Online
2007-02-04 16:23 <DIR> d-------- C:\Program Files\ProxyLicense
2007-02-04 01:55 <DIR> d-------- C:\DOCUME~1\ALLUSE~1.WIN\Application Data\Trymedia
2007-01-29 14:19 0 --a------ C:\WINDOWS\system32\Ultra.dll
2007-01-14 07:17 <DIR> d-------- C:\Program Files\XoftSpy
2007-01-14 07:16 <DIR> d-------- C:\Program Files\7-Zip
2007-01-12 01:16 <DIR> d-------- C:\WINDOWS\ie7updates
2007-01-12 01:16 <DIR> d-------- C:\Program Files\MSXML 4.0
2007-01-10 02:15 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2007-01-10 02:03 <DIR> d-------- C:\DOCUME~1\ALLUSE~1.WIN\Application Data\Hewlett-Packard
2007-01-10 02:02 82,432 -ra------ C:\WINDOWS\system32\MSXML4r.dll
2007-01-10 02:02 626,960 -ra------ C:\WINDOWS\system32\hpvaut32.dll
2007-01-10 02:02 487,424 -ra------ C:\WINDOWS\system32\hpvcp70.dll
2007-01-10 02:02 44,544 -ra------ C:\WINDOWS\system32\MSXML4a.dll
2007-01-10 02:02 344,064 -ra------ C:\WINDOWS\system32\hpvcr70.dll
2007-01-10 01:44 94,208 --a------ C:\WINDOWS\system32\HPZipt12.dll
2007-01-10 01:44 65,536 --a------ C:\WINDOWS\system32\HPZipm12.exe
2007-01-10 01:44 61,440 --a------ C:\WINDOWS\system32\HPZinw12.exe
2007-01-10 01:44 57,344 --a------ C:\WINDOWS\system32\HPZisn12.dll
2007-01-10 01:44 306,688 --a------ C:\WINDOWS\IsUninst.exe
2007-01-10 01:44 278,584 --a------ C:\WINDOWS\system32\HPZidr12.dll
2007-01-10 01:44 204,800 --a------ C:\WINDOWS\system32\HPZipr12.dll
2007-01-10 01:42 17,176 --------- C:\WINDOWS\hpomdl04.dat
2007-01-10 01:42 104,217 --a------ C:\WINDOWS\hpoins04.dat
2007-01-09 23:38 <DIR> d-------- C:\temp
2007-01-09 23:23 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-02-08 15:18 -------- d-------- C:\Program Files\mozilla firefox
2007-02-08 14:11 -------- d-------- C:\Program Files\Common Files\symantec shared
2007-02-07 23:46 -------- d-------- C:\Program Files\searchrelevant
2007-02-06 02:18 -------- d-------- C:\DOCUME~1\SARAH~1.SAR\Application Data\limewire
2007-02-05 21:59 -------- d--h----- C:\Program Files\installshield installation information
2007-02-05 17:14 -------- d-------- C:\Program Files\winaso
2007-01-29 14:29 -------- d-------- C:\Program Files\quicktime
2007-01-16 10:52 -------- d-------- C:\Program Files\java
2007-01-09 23:39 -------- d---s---- C:\DOCUME~1\SARAH~1.SAR\Application Data\microsoft
2007-01-09 23:39 -------- d-------- C:\Program Files\hp
2007-01-05 19:14 -------- d-------- C:\Program Files\messenger
2007-01-05 19:14 -------- d-------- C:\Program Files\limewire
2007-01-05 19:13 -------- d-------- C:\Program Files\quickpar
2006-12-25 18:42 -------- d-------- C:\DOCUME~1\SARAH~1.SAR\Application Data\apple computer
2006-12-21 23:36 -------- d-------- C:\DOCUME~1\SARAH~1.SAR\Application Data\sony
2006-12-21 23:33 -------- d-------- C:\Program Files\sony
2006-12-20 11:22 48768 --a------ C:\WINDOWS\system32\s32evnt1.dll
2006-12-20 11:22 110952 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2006-12-20 11:22 -------- d-------- C:\Program Files\symantec
2006-12-20 10:34 0 --a------ C:\DOCUME~1\SARAH~1.SAR\Application Data\download.tmp
2006-12-17 19:33 -------- d-------- C:\DOCUME~1\SARAH~1.SAR\Application Data\ign_dlm
2006-12-14 12:54 23600 --a------ C:\WINDOWS\system32\drivers\TVICHW32.SYS
2006-11-13 21:17 7409 --a------ C:\WINDOWS\extend.dat
2006-11-08 05:06 679424 --a------ C:\WINDOWS\system32\inetcomm.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"igndlm.exe"="C:\\Program Files\\IGN\\Download Manager\\DLM.exe /windowsstart /startifwork"
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.1128.5462\\GoogleToolbarNotifier.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"SoundMan"="SOUNDMAN.EXE"
"ATIPTA"="C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe"
"ATICCC"="\"C:\\Program Files\\ATI Technologies\\ATI.ACE\\CLIStart.exe\""
"NeroCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"InCD"="C:\\Program Files\\Ahead\\InCD\\InCD.exe"
"SpeedTouch USB Diagnostics"="\"C:\\Program Files\\Thomson\\SpeedTouch USB\\Dragdiag.exe\" /icon"
"osCheck"="\"C:\\Program Files\\Norton Internet Security\\osCheck.exe\""
"RemoteControl"="\"C:\\Program Files\\CyberLink\\PowerDVD\\PDVDServ.exe\""
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_10\\bin\\jusched.exe\""
"!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="hpcmpmgr"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\HP\\hpcoretech\\hpcmpmgr.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="HPWuSchd2"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\HP\\HP Software Update\\HPWuSchd2.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igndlm.exe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="DLM"
"hkey"="HKCU"
"command"="C:\\Program Files\\IGN\\Download Manager\\DLM.exe /windowsstart /startifwork"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="qttask"
"hkey"="HKLM"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{40CBCC7F-63C3-4D94-B4D6-A0ED77B9EEB7}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\gebayyy
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmnnm
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0
*newlycreated* - HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\LEGACY_COMHOST
*newlycreated* - HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\LEGACY_ERASERUTILDRV10710
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Norton Internet Security - Run Full System Scan - Sarah.job
C:\WINDOWS\tasks\RegCure.job
C:\WINDOWS\tasks\XoftSpy.job
********************************************************************
catchme 0.1 W2K/XP - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
********************************************************************
Completion time: 07-02-08 21:52:18
Logfile of HijackThis v1.99.1
Scan saved at 21:59:31, on 08/02/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\IGN\Download Manager\DLM.exe /windowsstart /startifwork
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: &Yahoo! Search -
file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary -
file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps -
file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS -
file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD File System Service (InCDsrv) - AHEAD Software - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
Thanks again
Sarah