

C:\Program Files\iPod\bin\iPodService.exe O23 - Service: iPodService - Apple Computer, Inc. O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
#ULEAD PHOTO EXPLORER 7.0 DOWNLOAD PASSWORD#
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe

O4 - Global Startup: Ulead Photo Express 4.0 SE Calendar Checker. O4 - Global Startup: E-Color.lnk = C:\Program Files\E-Color\Common\IconMgr.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - HKCU\.\Run: C:\WINDOWS\system32\ctfmon.exe O4 - HKLM\.\Run: "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe" O4 - HKLM\.\Run: %systemroot%\system32\dumprep 0 -k O4 - HKLM\.\Run: C:\PROGRA~1\SYMANT~1\VPTray.exe O4 - HKLM\.\Run: "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\.\Run: "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\.\Run: "C:\Program Files\Microsoft IntelliPoint\point32.exe" O4 - HKLM\.\Run: C:\Program Files\Ulead Systems\Ulead Photo Explorer 7.0\Monitor.exe O4 - HKLM\.\Run: C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe

O4 - HKLM\.\Run: C:\Program Files\Hercules\Video\Hercules 3DTweaker 3.0 LE (Build 26)\H3dTweaker.exe -hide O4 - HKLM\.\Run: C:\WINDOWS\system32\NeroCheck.exe R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :8080į2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = MSIE: Internet Explorer v6.00 SP2 (.2180)Ĭ:\Program Files\Common Files\Symantec Shared\ccSetMgr.exeĬ:\Program Files\Symantec AntiVirus\DefWatch.exeĬ:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exeĬ:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exeĬ:\Program Files\Spyware Doctor\sdhelp.exeĬ:\Program Files\Symantec AntiVirus\Rtvscan.exeĬ:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exeĬ:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exeĬ:\Program Files\Ulead Systems\Ulead Photo Explorer 7.0\Monitor.exeĬ:\Program Files\Microsoft IntelliPoint\point32.exeĬ:\Program Files\Spyware Doctor\swdoctor.exeĬ:\Program Files\Common Files\Symantec Shared\ccApp.exeĬ:\Program Files\E-Color\Common\IconMgr.exeĬ:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exeĬ:\Program Files\E-Color\E-Color Indicator\TICIcon.exeĬ:\DOCUME~1\Yves\LOCALS~1\Temp\Temporary Directory 8 for hijackthis.zip\HijackThis.exe Perhaps the files 020 and 021 in the HJT log are responsible?Īnyone can tell me if i can fix them with HJT When i uninstalled spybot and spysweeper and wanted to delete the left over files, i couldn't because it never could remove. When running Ewido spyware i always get the same infection wich it can't remove, even after restart.
