8:33 PM: IE Security Shield: found: C:\WINDOWS\SYSTEM32\COMPONENTS\FLX1.DLL – IE Security modification denied
Keylogger Shield: On
BHO Shield: On
IE Security Shield: On
Alternate Data Stream (ADS) Execution Shield: On
Startup Shield: On
Common Ad Sites Shield: Off
Hosts File Shield: On
Spy Communication Shield: On
ActiveX Shield: On
Windows Messenger Service Shield: On
IE Favorites Shield: On
Spy Installation Shield: On
Memory Shield: On
IE Hijack Shield: On
IE Tracking Cookies Shield: Off
8:33 PM: Shield States
8:33 PM: Spyware Definitions: 718
8:32 PM: Spy Sweeper 5.0.5.1286 started
8:10 PM: | End of Session, Thursday, July 13, 2006 |
8:09 PM: Your spyware definitions have been updated.
8:08 PM: IE Security Shield: found: C:\WINDOWS\SYSTEM32\COMPONENTS\FLX1.DLL – IE Security modification denied
8:07 PM: The Spy Communication shield has blocked access to: OWNUSA.INFO
8:07 PM: The Spy Communication shield has blocked access to: OWNUSA.INFO
Keylogger Shield: On
BHO Shield: On
IE Security Shield: On
Alternate Data Stream (ADS) Execution Shield: On
Startup Shield: On
Common Ad Sites Shield: Off
Hosts File Shield: On
Spy Communication Shield: On
ActiveX Shield: On
Windows Messenger Service Shield: On
IE Favorites Shield: On
Spy Installation Shield: On
Memory Shield: On
IE Hijack Shield: On
IE Tracking Cookies Shield: Off
8:07 PM: Shield States
8:07 PM: Spyware Definitions: 691
8:07 PM: Spy Sweeper 5.0.5.1286 started
8:07 PM: Spy Sweeper 5.0.5.1286 started
8:07 PM: | Start of Session, Thursday, July 13, 2006 |
********
8:29 PM: IE Security Shield: found: C:\WINDOWS\SYSTEM32\COMPONENTS\FLX1.DLL – IE Security modification denied
8:24 PM: Removal process completed. Elapsed time 00:02:01
8:24 PM: A reboot was required but declined.
8:23 PM: The Spy Communication shield has blocked access to: OWNUSA.INFO
8:23 PM: The Spy Communication shield has blocked access to: OWNUSA.INFO
8:23 PM: The Spy Communication shield has blocked access to: CONTENTS.EXETRAFFLC.COM
8:23 PM: The Spy Communication shield has blocked access to: CONTENTS.EXETRAFFLC.COM
8:23 PM: The Spy Communication shield has blocked access to: HERE4SEARCH.BIZ
8:23 PM: The Spy Communication shield has blocked access to: HERE4SEARCH.BIZ
8:23 PM: The Spy Communication shield has blocked access to: SMART-SECURITY.BIZ
8:23 PM: The Spy Communication shield has blocked access to: SMART-SECURITY.BIZ
8:22 PM: Quarantining All Traces: ic-live cookie
8:22 PM: Quarantining All Traces: dialerplatform
8:22 PM: Quarantining All Traces: prosearch.com hijack
8:22 PM: Quarantining All Traces: sysprotect
8:22 PM: Quarantining All Traces: moneytree
8:22 PM: Quarantining All Traces: internetoptimizer
8:22 PM: Quarantining All Traces: cws-aboutblank
8:22 PM: Quarantining All Traces: trojan agent winlogonhook
8:22 PM: Quarantining All Traces: 180search assistant/zango
8:22 PM: Quarantining All Traces: clearsearch
8:22 PM: C:\WINDOWS\g464089156.dll is in use. It will be removed on reboot.
8:22 PM: trojan-downloader-2pursuit is in use. It will be removed on reboot.
8:22 PM: Quarantining All Traces: trojan-downloader-2pursuit
8:22 PM: C:\WINDOWS\system32\issearch.exe is in use. It will be removed on reboot.
8:22 PM: security2k hijacker is in use. It will be removed on reboot.
8:22 PM: Quarantining All Traces: security2k hijacker
8:22 PM: C:\WINDOWS\system32\isnotify.exe is in use. It will be removed on reboot.
8:22 PM: trojan-downloader-zlob is in use. It will be removed on reboot.
8:22 PM: Quarantining All Traces: trojan-downloader-zlob
8:22 PM: Removal process initiated
8:21 PM: Traces Found: 35
8:21 PM: Full Sweep has completed. Elapsed time 00:11:49
8:21 PM: File Sweep Complete, Elapsed Time: 00:07:47
8:20 PM: Warning: Failed to open file "c:\documents and settings\owner\application data\mozilla\firefox\profiles\721ub1n9.default\parent.lock". The operation completed successfully
8:20 PM: Warning: Failed to open file "c:\documents and settings\owner\local settings\temp\~dfa1b7.tmp". The operation completed successfully
8:20 PM: Warning: Failed to open file "c:\documents and settings\owner\local settings\temp\~df7464.tmp". The operation completed successfully
8:20 PM: Warning: Failed to open file "c:\documents and settings\owner\local settings\application data\microsoft\messenger\[removed]\sharingmetadata\pending.dat". The operation completed successfully
8:20 PM: Warning: Failed to open file "c:\documents and settings\owner\local settings\application data\microsoft\messenger\[removed]\sharingmetadata\infected.dat". The operation completed successfully
8:18 PM: c:\windows\downloaded program files\gdnus2339.exe (ID = 322697)
8:15 PM: c:\windows\downloaded program files\conflict.3\gdnus2339.exe (ID = 322697)
8:15 PM: c:\windows\downloaded program files\conflict.1\gdnus2339.exe (ID = 322697)
8:14 PM: c:\windows\downloaded program files\conflict.2\gdnus2339.exe (ID = 322697)
8:14 PM: Found Adware: dialerplatform
8:14 PM: C:\Program Files\SysProtect Free (1 subtraces) (ID = 2147520129)
8:14 PM: Starting File Sweep
8:14 PM: Cookie Sweep Complete, Elapsed Time: 00:00:00
8:14 PM: c:\documents and settings\david\cookies\david@ic-live[1].txt (ID = 2821)
8:14 PM: Found Spy Cookie: ic-live cookie
8:14 PM: Starting Cookie Sweep
8:14 PM: Registry Sweep Complete, Elapsed Time:00:00:13
8:13 PM: HKU\S-1-5-21-3753251763-2348510289-2647141112-1003\software\microsoft\internet explorer\main\ || search page_bak (ID = 774883)
8:13 PM: HKU\S-1-5-21-3753251763-2348510289-2647141112-1003\software\microsoft\internet explorer\main\ || search page_bak (ID = 115925)
8:13 PM: Found Adware: cws-aboutblank
8:13 PM: HKLM\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler\ || {259ba022-2005-45e9-a965-10edb9c00605} (ID = 1538921)
8:13 PM: HKLM\software\microsoft\windows\currentversion\policies\explorer\run\ || ishost.exe (ID = 1524342)
8:13 PM: HKLM\software\microsoft\windows\currentversion\policies\explorer\run\ || ishost.exe (ID = 1513976)
8:13 PM: HKLM\software\microsoft\windows\currentversion\policies\explorer\run\ || issearch.exe (ID = 1506013)
8:13 PM: HKLM\software\microsoft\windows nt\currentversion\winlogon\notify\cfgmngr32\ (ID = 1252409)
8:13 PM: HKLM\software\microsoft\internet explorer\main\ || search page_bak (ID = 1250789)
8:13 PM: Found Adware: prosearch.com hijack
8:13 PM: HKLM\software\classes\appid\checkproduct2_1.dll\ (ID = 1249922)
8:13 PM: HKLM\software\classes\checkprod.checkproduct.1\ (ID = 1249811)
8:13 PM: HKLM\software\classes\checkprod.checkproduct\ (ID = 1249805)
8:13 PM: HKCR\appid\checkproduct2_1.dll\ (ID = 1249240)
8:13 PM: HKCR\checkprod.checkproduct.1\ (ID = 1249122)
8:13 PM: HKCR\checkprod.checkproduct\ (ID = 1249116)
8:13 PM: Found Adware: sysprotect
8:13 PM: HKLM\software\microsoft\mssmgr\ (ID = 937101)
8:13 PM: Found Trojan Horse: trojan agent winlogonhook
8:13 PM: HKLM\software\microsoft\windows\currentversion\policies\explorer\run\ || kernel32.dll (ID = 796421)
8:13 PM: HKLM\software\prositefinder1\ (ID = 773865)
8:13 PM: Found Adware: 180search assistant/zango
8:13 PM: HKLM\software\prositefinder\ (ID = 773839)
8:13 PM: Found Adware: clearsearch
8:13 PM: HKLM\software\microsoft\windows\currentversion\explorer\browser helper objecta\ (ID = 735573)
8:13 PM: HKCR\interface\{eee4a2e5-9f56-432f-a6ed-f6f625b551e0}\ (ID = 135185)
8:13 PM: Found Adware: moneytree
8:13 PM: HKLM\software\classes\interface\{aa4939c3-deca-4a48-a454-97cd587c0ef5}\ (ID = 128896)
8:13 PM: HKCR\interface\{aa4939c3-deca-4a48-a454-97cd587c0ef5}\ (ID = 128885)
8:13 PM: Found Adware: internetoptimizer
8:13 PM: Starting Registry Sweep
8:13 PM: Memory Sweep Complete, Elapsed Time: 00:03:37
8:10 PM: The Spy Communication shield has blocked access to: MUSAH.INFO
8:10 PM: The Spy Communication shield has blocked access to: MUSAH.INFO
8:10 PM: The Spy Communication shield has blocked access to: MUSAH.INFO
8:10 PM: The Spy Communication shield has blocked access to: MUSAH.INFO
8:10 PM: The Spy Communication shield has blocked access to: MUSAH.INFO
8:10 PM: The Spy Communication shield has blocked access to: MUSAH.INFO
8:10 PM: Warning: Failed to load image: C:\WINDOWS\system32\compstuic.dll
8:10 PM: Starting Memory Sweep
8:10 PM: C:\WINDOWS\g464089156.dll (ID = 1538933)
8:10 PM: HKLM\software\microsoft\windows nt\currentversion\winlogon\notify\cfgmngr32\ || dllname (ID = 1538933)
8:10 PM: Found Trojan Horse: trojan-downloader-2pursuit
8:10 PM: Warning: TVolume.Read: read past end of volume size: 0 reading cluster: 0
8:10 PM: C:\WINDOWS\system32\issearch.exe (ID = 1512087)
8:10 PM: HKLM\software\microsoft\windows\currentversion\policies\explorer\run\ || issearch.exe (ID = 1512087)
8:10 PM: Found Adware: security2k hijacker
8:10 PM: C:\WINDOWS\system32\isnotify.exe (ID = 1052560)
8:10 PM: HKLM\software\microsoft\windows\currentversion\policies\explorer\run\ || kernel32.dll (ID = 1052560)
8:10 PM: Found Trojan Horse: trojan-downloader-zlob
8:10 PM: Sweep initiated using definitions version 718
8:10 PM: Spy Sweeper 5.0.5.1286 started
8:10 PM: | Start of Session, Thursday, July 13, 2006 |
********
Logfile of HijackThis v1.99.1
Scan saved at 8:37:49 PM, on 7/13/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\system32\ishost.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\igfxtray.exe
C:\PROGRA~1\Dantz\RETROS~1\retrorun.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\ismon.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
C:\WINDOWS\system32\WDBtnMgr.exe
C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\40a21d35.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Digital Asphyxia\Y!TunnelPro 2.0\YTPro.exe
C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\BigFix\BigFix.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Yahoo!\Messenger\YPager.exe
C:\Program Files\Jinx Inc\EviL Online Checker\EviL Online Checker v2.0.exe
C:\Documents and Settings\Owner\Desktop\HijackThis_v1.99.1.exe
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.yahoo.com/
O2 - BHO: (no name) - {062492AF-392E-479D-BF52-A7A4BCA00307} - C:\WINDOWS\system32\compstuic.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {873eb32d-ae1a-4183-89bd-45a77f761be4} - C:\WINDOWS\system32\ixt2.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: NTIECatcher Class - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - C:\Program Files\Xi\NetTransport 2\NTIEHelper.dll
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SynTPLpr] "C:\Program Files\Synaptics\SynTP\SynTPLpr.exe"
O4 - HKLM\..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] "C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe"
O4 - HKLM\..\Run: [WD Button Manager] WDBtnMgr.exe
O4 - HKLM\..\Run: [LVCOMS] "C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE"
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [40a21d35.exe] C:\WINDOWS\system32\40a21d35.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [AIM] "C:\Program Files\AIM\aim.exe" -cnetwait.odl
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Y!TunnelPro] "C:\Program Files\Digital Asphyxia\Y!TunnelPro 2.0\YTPro.exe"
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_7 -reboot 1
O4 - HKCU\..\Run: [40a21d35.exe] "C:\Documents and Settings\Owner\Local Settings\Application Data\40a21d35.exe"
O4 - Startup: ePrompter.lnk = C:\Program Files\ePrompter\ePrompter.exe
O4 - Startup: Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\WidgetEngine\YahooWidgetEngine.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O8 - Extra context menu item: Download all by Net Transport - C:\Program Files\Xi\NetTransport 2\NTAddList.html
O8 - Extra context menu item: Download by Net Transport - C:\Program Files\Xi\NetTransport 2\NTAddLink.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) -
https://rtc4.webresponse.one.microsoft.com/…p/TLIEFlash.CAB
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {DC75FEF6-165D-4D25-A518-C8C4BDA7BAA6} (CPlayFirstDinerDashControl Object) -
http://games.pogo.com/online2/pogop/diner_…sh.1.0.0.80.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} -
http://games.pogo.com/online2/pogo/chuzzle…aploader_v6.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: windav32 - windav32.dll (file missing)
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O21 - SSODL: cinnamomum - {93ac7c30-3878-4eaa-9420-7977285df5b1} - C:\WINDOWS\system32\pmnqguh.dll (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Retrospect Launcher (RetroLauncher) - Dantz Development Corporation - C:\PROGRA~1\Dantz\RETROS~1\retrorun.exe
O23 - Service: Retrospect Helper - Dantz Development Corporation - C:\PROGRA~1\Dantz\RETROS~1\rthlpsvc.exe
O23 - Service: Retrospect WD Service (RetroWDSvc) - Dantz Development Corporation - C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
at the moment nothing is happening out of place on my comp. although thoughse security icons are on my desktop, the online security and security troubleshooting thing.