This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved]Lusbfilt.sys

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of HijackThis v1.99.1
Scan saved at 21:41:15, on 2007-08-10
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program\Windows Defender\MsMpEng.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program\Mozilla Firefox\firefox.exe
C:\Program\Hijackthis\HijackThis.exe
C:\Program\Windows Defender\MpCmdRun.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.handelsbanken.se/jarna
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.pandasoftware.com/redirector/?p…rt&lang=swe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
O2 - BHO: Länkhjälp till Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program\Delade filer\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program\Java\jre1.6.0_01\bin\ssv.dll
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program\Panda Software\Panda Internet Security 2007\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [SCANINICIO] "C:\Program\Panda Software\Panda Internet Security 2007\Inicio.exe"
O4 - HKLM\..\Run: [NaturalPoint] C:\Program\NaturalPoint\TrackIR4\TrackIR.exe
O4 - HKLM\..\Run: [Profiler] C:\Program\Saitek\Software\ProfilerU.exe
O4 - HKLM\..\Run: [SaiMfd] C:\Program\Saitek\Software\SaiMfd.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [CTDVDDET] C:\Program\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE
O4 - HKLM\..\Run: [SBDrvDet] C:\Program\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program\Delade filer\Logitech\LCD Manager\lcdmon.exe"
O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program\Delade filer\Logitech\G-series Software\LGDCore.exe" /SHOWHIDE
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [AudioHQU] C:\Program\Creative\SBAudigy2ZS\AudioHQ\AHQTbU.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTXFIREG] CTxfiReg.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Fraps] C:\FRAPS\FRAPS.EXE
O4 - HKCU\..\Run: [nHancer] "C:\Program\KSE\nHancer 32bit\nHancer.exe" /tray
O4 - Global Startup: IL-2 Manager PF.lnk = ?
O4 - Global Startup: Logitech SetPoint.lnk = ?
O4 - Global Startup: NETGEAR WG311T Wireless Assistant.lnk = C:\Program\NETGEAR\WG311T\wlancfg5.exe
O4 - Global Startup: Personal.lnk = C:\Program\Personal\bin\Personal.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java-konsol - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1F2AA8E4-9D1E-4A3C-9010-852C68EE46AC}: NameServer = 195.58.103.124,195.58.103.18
O17 - HKLM\System\CS1\Services\Tcpip\..\{1F2AA8E4-9D1E-4A3C-9010-852C68EE46AC}: NameServer = 195.58.103.124,195.58.103.18
O17 - HKLM\System\CS2\Services\Tcpip\..\{1F2AA8E4-9D1E-4A3C-9010-852C68EE46AC}: NameServer = 195.58.103.124,195.58.103.18
O20 - AppInit_DLLs: C:\Program\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: avldr - C:\WINDOWS\SYSTEM32\avldr.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program\Delade filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: nHancer Support (nHancer) - KSE - Korndörfer Software Engineering - C:\Program\KSE\nHancer 32bit\nHancerService.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Panda Software Controller - Panda Software International - C:\Program\Panda Software\Panda Internet Security 2007\PsCtrls.exe
O23 - Service: Panda Function Service (PAVFNSVR) - Panda Software International - C:\Program\Panda Software\Panda Internet Security 2007\PavFnSvr.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software International - C:\Program\Delade filer\Panda Software\PavShld\pavprsrv.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software International - C:\Program\Panda Software\Panda Internet Security 2007\pavsrv51.exe
O23 - Service: Panda Antispam Engine (pmshellsrv) - Panda Software International - C:\Program\Panda Software\Panda Internet Security 2007\AntiSpam\pskmssvc.exe
O23 - Service: Panda Host Service (PSHost) - Panda Software International - c:\program\panda software\panda internet security 2007\firewall\PSHOST.EXE
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software International - C:\Program\Panda Software\Panda Internet Security 2007\psimsvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\Program\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: Stuffit Archive Name Service - Smith Micro Software, Inc. - C:\Program\Smith Micro\StuffIt11\ArcNameService.exe
O23 - Service: Panda TPSrv (TPSrv) - Panda Software International - C:\Program\Panda Software\Panda Internet Security 2007\TPSrv.exe
Hello and welcome to the forums

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.


(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time.

Next:

Download ComboFix from Here to your Desktop.
  • Double click combofix.exe and follow the prompts.
  • When finished, it shall produce a log for you, combofix.txt. Post that log and a HiJackthis log in your next reply
Note: Do not mouseclick while its running. That may cause it to stall
I´l follow your instructions as soon as I get up tomorrow, it´s getting late here in sweden (00.00hrs) + I´ve managed to get into "safe mode" on the PC that malfunctiones, where I´m running Spybot, Adaware and Panda in sequence thruogh the night. I start up working on your advice when I get up, Then I have all day to curse M$ and others, and maybe get it fixed!
Hi, it´me, I´m back,….. Now ATF cleaner was swift, the combofix is running, stupid me put it in a folder so I can´t se the progress, does it inform when finished? Does it take long, I have one 250 Gb HDD © + two 160 Gb (d & e) are they all scanned by CF? I can see HDD led flicking, so I just have to wait, huh? Sorry a bad case of RTFM, it´s done I´ll post the logs in some minutes. be back.
So Hijack log first:
Logfile of HijackThis v1.99.1
Scan saved at 23:34:41, on 2007-08-11
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program\Windows Defender\MsMpEng.exe
C:\WINDOWS\system32\svchost.exe
C:\Program\Panda Software\Panda Internet Security 2007\apvxdwin.exe
C:\Program\Panda Software\Panda Internet Security 2007\SRVLOAD.EXE
C:\Program\Panda Software\Panda Internet Security 2007\WebProxy.exe
C:\Program\Qualcomm\Eudora\Eudora.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.handelsbanken.se/jarna
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.pandasoftware.com/redirector/?p…rt&lang=swe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
O2 - BHO: Länkhjälp till Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program\Delade filer\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program\Java\jre1.6.0_01\bin\ssv.dll
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program\Panda Software\Panda Internet Security 2007\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [SCANINICIO] "C:\Program\Panda Software\Panda Internet Security 2007\Inicio.exe"
O4 - HKLM\..\Run: [NaturalPoint] C:\Program\NaturalPoint\TrackIR4\TrackIR.exe
O4 - HKLM\..\Run: [Profiler] C:\Program\Saitek\Software\ProfilerU.exe
O4 - HKLM\..\Run: [SaiMfd] C:\Program\Saitek\Software\SaiMfd.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [CTDVDDET] C:\Program\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE
O4 - HKLM\..\Run: [SBDrvDet] C:\Program\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program\Delade filer\Logitech\LCD Manager\lcdmon.exe"
O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program\Delade filer\Logitech\G-series Software\LGDCore.exe" /SHOWHIDE
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [AudioHQU] C:\Program\Creative\SBAudigy2ZS\AudioHQ\AHQTbU.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTXFIREG] CTxfiReg.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Fraps] C:\FRAPS\FRAPS.EXE
O4 - HKCU\..\Run: [nHancer] "C:\Program\KSE\nHancer 32bit\nHancer.exe" /tray
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: IL-2 Manager PF.lnk = ?
O4 - Global Startup: Logitech SetPoint.lnk = ?
O4 - Global Startup: NETGEAR WG311T Wireless Assistant.lnk = C:\Program\NETGEAR\WG311T\wlancfg5.exe
O4 - Global Startup: Personal.lnk = C:\Program\Personal\bin\Personal.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java-konsol - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1F2AA8E4-9D1E-4A3C-9010-852C68EE46AC}: NameServer = 195.58.103.124,195.58.103.18
O17 - HKLM\System\CS1\Services\Tcpip\..\{1F2AA8E4-9D1E-4A3C-9010-852C68EE46AC}: NameServer = 195.58.103.124,195.58.103.18
O17 - HKLM\System\CS2\Services\Tcpip\..\{1F2AA8E4-9D1E-4A3C-9010-852C68EE46AC}: NameServer = 195.58.103.124,195.58.103.18
O20 - AppInit_DLLs: C:\Program\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: avldr - C:\WINDOWS\SYSTEM32\avldr.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program\Delade filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: nHancer Support (nHancer) - KSE - Korndörfer Software Engineering - C:\Program\KSE\nHancer 32bit\nHancerService.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Panda Software Controller - Panda Software International - C:\Program\Panda Software\Panda Internet Security 2007\PsCtrls.exe
O23 - Service: Panda Function Service (PAVFNSVR) - Panda Software International - C:\Program\Panda Software\Panda Internet Security 2007\PavFnSvr.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software International - C:\Program\Delade filer\Panda Software\PavShld\pavprsrv.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software International - C:\Program\Panda Software\Panda Internet Security 2007\pavsrv51.exe
O23 - Service: Panda Antispam Engine (pmshellsrv) - Panda Software International - C:\Program\Panda Software\Panda Internet Security 2007\AntiSpam\pskmssvc.exe
O23 - Service: Panda Host Service (PSHost) - Panda Software International - c:\program\panda software\panda internet security 2007\firewall\PSHOST.EXE
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software International - C:\Program\Panda Software\Panda Internet Security 2007\psimsvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\Program\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: Stuffit Archive Name Service - Smith Micro Software, Inc. - C:\Program\Smith Micro\StuffIt11\ArcNameService.exe
O23 - Service: Panda TPSrv (TPSrv) - Panda Software International - C:\Program\Panda Software\Panda Internet Security 2007\TPSrv.exe

Then Combofix:

ComboFix 07-08-09.3 - "Pelle" 2007-08-11 23:31:04.1 - NTFSx86 NETWORK
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1053.18.1744 [GMT 2:00]


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


f:\RECYCLER\temp.txt


((((((((((((((((((((((((( Files Created from 2007-07-11 to 2007-08-11 )))))))))))))))))))))))))))))))


2007-08-11 23:02 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-08-11 20:58 82,944 -ra—— C:\WINDOWS\system32\MAPI.DLL
2007-08-11 02:31 d–h—– C:\WINDOWS\system32\GroupPolicy
2007-08-10 23:42 d——– C:\Program\Delade filer\Wise Installation Wizard
2007-08-10 23:35 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-08-10 21:55 d——– C:\WINDOWS\LastGood
2007-08-10 21:21 d–hs—- C:\WINDOWS\CSC
2007-08-09 16:57 524,288 –ah—– C:\DOCUME~1\ADMINI~1\NTUSER.DAT
2007-08-09 16:57 dr——- C:\DOCUME~1\ADMINI~1\Start-meny
2007-08-09 16:57 d–h—– C:\DOCUME~1\ADMINI~1\Skrivare
2007-08-09 16:57 d–h—– C:\DOCUME~1\ADMINI~1\N„tverket
2007-08-09 16:57 d–h—– C:\DOCUME~1\ADMINI~1\Mallar
2007-08-09 16:57 d–h—– C:\DOCUME~1\ADMINI~1\Lokala inst„llningar
2007-08-09 16:57 d——– C:\DOCUME~1\ADMINI~1\Skrivbord
2007-08-09 16:57 d——– C:\DOCUME~1\ADMINI~1\Mina dokument
2007-08-09 16:57 d——– C:\DOCUME~1\ADMINI~1\Favoriter
2007-07-28 00:14 10,240 –a—— C:\WINDOWS\CTDCRES.DLL
2007-07-27 23:00 d——– C:\DOCUME~1\Pelle\APPLIC~1\Help
2007-07-25 00:52 d——– C:\Program\Prime95
2007-07-21 23:45 364,544 ——— C:\WINDOWS\system32\TwnLib4.dll
2007-07-21 23:34 5,888 ——— C:\WINDOWS\system32\drivers\imagedrv.sys
2007-07-21 23:34 476,320 ——— C:\WINDOWS\system32\ImagXpr7.dll
2007-07-21 23:34 471,040 ——— C:\WINDOWS\system32\ImagXRA7.dll
2007-07-21 23:34 262,144 ——— C:\WINDOWS\system32\ImagXR7.dll
2007-07-21 23:34 155,648 –a—— C:\WINDOWS\system32\NeroCheck.exe
2007-07-21 23:34 127,488 ——— C:\WINDOWS\system32\drivers\imagesrv.sys
2007-07-21 23:34 106,496 –a—— C:\WINDOWS\system32\TwnLib20.dll
2007-07-21 23:34 1,568,768 ——— C:\WINDOWS\system32\ImagX7.dll
2007-07-21 23:34 d——– C:\Program\Delade filer\Ahead
2007-07-21 23:34 d——– C:\Program\Ahead
2007-07-21 22:04 356,352 –a—— C:\WINDOWS\system32\NVUNINST.EXE
2007-07-21 22:04 356,352 –a—— C:\WINDOWS\system32\nvudisp.exe
2007-07-21 22:04 d——– C:\WINDOWS\nview
2007-07-21 22:03 81,920 –a—— C:\WINDOWS\system32\nvwddi.dll
2007-07-21 22:03 81,920 –a—— C:\WINDOWS\system32\nvmctray.dll
2007-07-21 22:03 8,466,432 –a—— C:\WINDOWS\system32\nvcpl.dll
2007-07-21 22:03 753,664 –a—— C:\WINDOWS\system32\nvcplui.exe
2007-07-21 22:03 6,729,728 –a—— C:\WINDOWS\system32\nvoglnt.dll
2007-07-21 22:03 6,234,112 –a—— C:\WINDOWS\system32\nvdisps.dll
2007-07-21 22:03 5,455,872 –a—— C:\WINDOWS\system32\nvdispsr.dll
2007-07-21 22:03 466,944 –a—— C:\WINDOWS\system32\nvshell.dll
2007-07-21 22:03 458,752 –a—— C:\WINDOWS\system32\nvmccssr.dll
2007-07-21 22:03 45,056 –a—— C:\WINDOWS\system32\nvmccsrs.dll
2007-07-21 22:03 442,368 –a—— C:\WINDOWS\system32\nvappbar.exe
2007-07-21 22:03 425,984 –a—— C:\WINDOWS\system32\keystone.exe
2007-07-21 22:03 37,376 –a—— C:\WINDOWS\system32\nvcodins.dll
2007-07-21 22:03 37,376 –a—— C:\WINDOWS\system32\nvcod.dll
2007-07-21 22:03 360,448 –a—— C:\WINDOWS\system32\nvapi.dll
2007-07-21 22:03 335,872 –a—— C:\WINDOWS\system32\nvwrses.dll
2007-07-21 22:03 335,872 –a—— C:\WINDOWS\system32\nvwrsel.dll
2007-07-21 22:03 327,680 –a—— C:\WINDOWS\system32\nvwrsfr.dll
2007-07-21 22:03 327,680 –a—— C:\WINDOWS\system32\nvwrsesm.dll
2007-07-21 22:03 327,680 –a—— C:\WINDOWS\system32\nvrshe.dll
2007-07-21 22:03 327,680 –a—— C:\WINDOWS\system32\nvrsar.dll
2007-07-21 22:03 323,584 –a—— C:\WINDOWS\system32\nvwrspt.dll
2007-07-21 22:03 323,584 –a—— C:\WINDOWS\system32\nvwrsit.dll
2007-07-21 22:03 319,488 –a—— C:\WINDOWS\system32\nvwrsptb.dll
2007-07-21 22:03 319,488 –a—— C:\WINDOWS\system32\nvwrsnl.dll
2007-07-21 22:03 315,392 –a—— C:\WINDOWS\system32\nvwrsru.dll
2007-07-21 22:03 315,392 –a—— C:\WINDOWS\system32\nvwrshu.dll
2007-07-21 22:03 311,296 –a—— C:\WINDOWS\system32\nvwrsde.dll
2007-07-21 22:03 307,200 –a—— C:\WINDOWS\system32\nvexpbar.dll
2007-07-21 22:03 303,104 –a—— C:\WINDOWS\system32\nvwrstr.dll
2007-07-21 22:03 303,104 –a—— C:\WINDOWS\system32\nvwrssl.dll
2007-07-21 22:03 303,104 –a—— C:\WINDOWS\system32\nvwrsfi.dll
2007-07-21 22:03 3,600,384 –a—— C:\WINDOWS\system32\nvvitvsr.dll
2007-07-21 22:03 3,518,464 –a—— C:\WINDOWS\system32\nvvitvs.dll
2007-07-21 22:03 3,321,856 –a—— C:\WINDOWS\system32\nvgames.dll
2007-07-21 22:03 3,072,000 –a—— C:\WINDOWS\system32\nvgamesr.dll
2007-07-21 22:03 299,008 –a—— C:\WINDOWS\system32\nvwrssk.dll
2007-07-21 22:03 299,008 –a—— C:\WINDOWS\system32\nvwrsno.dll
2007-07-21 22:03 294,912 –a—— C:\WINDOWS\system32\nvwrssv.dll
2007-07-21 22:03 294,912 –a—— C:\WINDOWS\system32\nvwrspl.dll
2007-07-21 22:03 294,912 –a—— C:\WINDOWS\system32\nvwrsda.dll
2007-07-21 22:03 286,720 –a—— C:\WINDOWS\system32\nvwrseng.dll
2007-07-21 22:03 286,720 –a—— C:\WINDOWS\system32\nvwrscs.dll
2007-07-21 22:03 286,720 –a—— C:\WINDOWS\system32\nvnt4cpl.dll
2007-07-21 22:03 282,624 –a—— C:\WINDOWS\system32\nvwrsar.dll
2007-07-21 22:03 282,624 –a—— C:\WINDOWS\system32\nvrsfr.dll
2007-07-21 22:03 282,624 –a—— C:\WINDOWS\system32\nvrses.dll
2007-07-21 22:03 282,624 –a—— C:\WINDOWS\system32\nvrsel.dll
2007-07-21 22:03 278,528 –a—— C:\WINDOWS\system32\nvwrshe.dll
2007-07-21 22:03 278,528 –a—— C:\WINDOWS\system32\nvrsit.dll
2007-07-21 22:03 278,528 –a—— C:\WINDOWS\system32\nvrsde.dll
2007-07-21 22:03 274,432 –a—— C:\WINDOWS\system32\nvrspt.dll
2007-07-21 22:03 274,432 –a—— C:\WINDOWS\system32\nvrsnl.dll
2007-07-21 22:03 274,432 –a—— C:\WINDOWS\system32\nvrsesm.dll
2007-07-21 22:03 270,336 –a—— C:\WINDOWS\system32\nvrsru.dll
2007-07-21 22:03 266,240 –a—— C:\WINDOWS\system32\nvrsptb.dll
2007-07-21 22:03 266,240 –a—— C:\WINDOWS\system32\nvrsja.dll
2007-07-21 22:03 262,144 –a—— C:\WINDOWS\system32\nvrsko.dll
2007-07-21 22:03 258,048 –a—— C:\WINDOWS\system32\nvrstr.dll
2007-07-21 22:03 258,048 –a—— C:\WINDOWS\system32\nvrssl.dll
2007-07-21 22:03 258,048 –a—— C:\WINDOWS\system32\nvrssk.dll
2007-07-21 22:03 258,048 –a—— C:\WINDOWS\system32\nvrshu.dll
2007-07-21 22:03 253,952 –a—— C:\WINDOWS\system32\nvrssv.dll
2007-07-21 22:03 253,952 –a—— C:\WINDOWS\system32\nvrspl.dll
2007-07-21 22:03 253,952 –a—— C:\WINDOWS\system32\nvrsno.dll
2007-07-21 22:03 253,952 –a—— C:\WINDOWS\system32\nvrsda.dll
2007-07-21 22:03 249,856 –a—— C:\WINDOWS\system32\nvrsfi.dll


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-10 22:14 ——— d——– C:\Program\Windows Defender
2007-08-10 20:40 1184 –a—— C:\WINDOWS\system32\drivers\APPFLTR.CFG.bck
2007-08-10 20:40 1184 –a—— C:\WINDOWS\system32\drivers\APPFLTR.CFG
2007-08-10 20:23 344456 –a—— C:\WINDOWS\system32\drivers\APPFCONT.DAT.bck
2007-08-10 20:23 344456 –a—— C:\WINDOWS\system32\drivers\APPFCONT.DAT
2007-08-10 20:23 0 –ah—– C:\WINDOWS\system32\drivers\Msft_Kernel_LUsbFilt_01005.Wdf
2007-08-10 20:23 0 –ah—– C:\WINDOWS\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2007-07-29 22:16 ——— d——– C:\DOCUME~1\Pelle\APPLIC~1\OpenOffice.org2
2007-07-28 01:02 ——— d——– C:\Program\Norton SystemWorks
2007-07-28 00:27 ——— d–h—– C:\Program\InstallShield Installation Information
2007-07-28 00:18 ——— d——– C:\Program\Creative
2007-07-28 00:15 ——— d——– C:\DOCUME~1\Pelle\APPLIC~1\Creative
2007-07-21 22:20 ——— d——– C:\DOCUME~1\Pelle\APPLIC~1\nHancer
2007-07-19 00:18 1100 –a—— C:\WINDOWS\system32\d3d8caps.dat
2007-07-11 09:01 69816 –a—— C:\WINDOWS\system32\perfc01D.dat
2007-07-11 09:01 395852 –a—— C:\WINDOWS\system32\perfh01D.dat
2007-07-08 14:59 61 —hs—- C:\WINDOWS\cnerolf.bin
2007-07-03 20:52 ——— d——– C:\Program\MSI
2007-07-02 07:29 ——— d——– C:\DOCUME~1\Pelle\APPLIC~1\uTorrent
2007-06-30 22:06 120 –a—— C:\WINDOWS\system32\drivers\wnmsav.dat
2007-06-29 00:43 81920 –a—— C:\WINDOWS\system32\nvwddi.dll
2007-06-29 00:43 6807328 –a–c— C:\WINDOWS\system32\dllcache\nv4_mini.sys
2007-06-29 00:43 6807328 –a—— C:\WINDOWS\system32\drivers\nv4_mini.sys
2007-06-29 00:43 5690624 –a–c— C:\WINDOWS\system32\dllcache\nv4_disp.dll
2007-06-29 00:43 5690624 –a—— C:\WINDOWS\system32\nv4_disp.dll
2007-06-29 00:43 3600384 –a—— C:\WINDOWS\system32\nvvitvsr.dll
2007-06-29 00:43 3518464 –a—— C:\WINDOWS\system32\nvvitvs.dll
2007-06-29 00:43 335872 –a—— C:\WINDOWS\system32\nvwrses.dll
2007-06-29 00:43 335872 –a—— C:\WINDOWS\system32\nvwrsel.dll
2007-06-29 00:43 327680 –a—— C:\WINDOWS\system32\nvwrsfr.dll
2007-06-29 00:43 327680 –a—— C:\WINDOWS\system32\nvwrsesm.dll
2007-06-29 00:43 323584 –a—— C:\WINDOWS\system32\nvwrspt.dll
2007-06-29 00:43 323584 –a—— C:\WINDOWS\system32\nvwrsit.dll
2007-06-29 00:43 319488 –a—— C:\WINDOWS\system32\nvwrsptb.dll
2007-06-29 00:43 319488 –a—— C:\WINDOWS\system32\nvwrsnl.dll
2007-06-29 00:43 315392 –a—— C:\WINDOWS\system32\nvwrsru.dll
2007-06-29 00:43 315392 –a—— C:\WINDOWS\system32\nvwrshu.dll
2007-06-29 00:43 311296 –a—— C:\WINDOWS\system32\nvwrsde.dll
2007-06-29 00:43 303104 –a—— C:\WINDOWS\system32\nvwrstr.dll
2007-06-29 00:43 303104 –a—— C:\WINDOWS\system32\nvwrssl.dll
2007-06-29 00:43 303104 –a—— C:\WINDOWS\system32\nvwrsfi.dll
2007-06-29 00:43 299008 –a—— C:\WINDOWS\system32\nvwrssk.dll
2007-06-29 00:43 299008 –a—— C:\WINDOWS\system32\nvwrsno.dll
2007-06-29 00:43 294912 –a—— C:\WINDOWS\system32\nvwrssv.dll
2007-06-29 00:43 294912 –a—— C:\WINDOWS\system32\nvwrspl.dll
2007-06-29 00:43 294912 –a—— C:\WINDOWS\system32\nvwrsda.dll
2007-06-29 00:43 286720 –a—— C:\WINDOWS\system32\nvwrseng.dll
2007-06-29 00:43 286720 –a—— C:\WINDOWS\system32\nvwrscs.dll
2007-06-29 00:43 282624 –a—— C:\WINDOWS\system32\nvwrsar.dll
2007-06-29 00:43 278528 –a—— C:\WINDOWS\system32\nvwrshe.dll
2007-06-29 00:43 2416640 –a—— C:\WINDOWS\system32\nvwssr.dll
2007-06-29 00:43 2330624 –a—— C:\WINDOWS\system32\nvwss.dll
2007-06-29 00:43 212992 –a—— C:\WINDOWS\system32\nvwrsja.dll
2007-06-29 00:43 196608 –a—— C:\WINDOWS\system32\nvwrsko.dll
2007-06-29 00:43 167936 –a—— C:\WINDOWS\system32\nvwrszht.dll
2007-06-29 00:43 163840 –a—— C:\WINDOWS\system32\nvwrszhc.dll
2007-06-29 00:43 1018772 –a—— C:\WINDOWS\system32\nvucode.bin
2007-05-25 10:00 249 –a—— C:\WINDOWS\system32\PavCPL.dat
2007-05-17 18:40 2184 –a—— C:\WINDOWS\mozver.dat
2007-05-16 21:50 737280 –a—— C:\WINDOWS\iun6002.exe
2007-05-16 17:20 86528 –a–c— C:\WINDOWS\system32\dllcache\directdb.dll
2007-05-16 17:20 85504 –a–c— C:\WINDOWS\system32\dllcache\wabimp.dll
2007-05-16 17:20 683520 –a–c— C:\WINDOWS\system32\dllcache\inetcomm.dll
2007-05-16 17:20 683520 –a—— C:\WINDOWS\system32\inetcomm.dll
2007-05-16 17:20 510976 –a–c— C:\WINDOWS\system32\dllcache\wab32.dll
2007-05-16 17:20 1314816 –a–c— C:\WINDOWS\system32\dllcache\msoe.dll
2007-05-14 23:20 32 –ahs—- C:\WINDOWS\system32\{8B5B3F24-9B5B-47E3-8532-D9A4AB58B407}.dat
2007-05-14 23:20 32 –ahs—- C:\WINDOWS\{297B94AF-D43F-452B-8713-ACCE7A089EA2}.dat
2007-05-14 23:19 32 –ahs—- C:\WINDOWS\system32\{1678C9C0-90D6-42AC-8CBD-63AC631F3EAA}.dat
2007-05-14 23:19 32 –ahs—- C:\WINDOWS\{59BF51C0-A9B7-476F-9B2C-C14F0C796D7A}.dat
2007-05-14 23:15 32 –ahs—- C:\WINDOWS\system32\{DECB10D9-FBAA-4D3F-A0EF-C0178860D675}.dat
2007-05-14 23:15 32 –ahs—- C:\WINDOWS\{81325C69-4AE6-4EEC-B066-FD73412F685B}.dat
2007-05-14 23:10 32 –ahs—- C:\WINDOWS\system32\{B0DCF7E3-93B4-433D-90FE-788D95F30192}.dat
2007-05-14 23:10 32 –ahs—- C:\WINDOWS\system32\{9E88E583-8E47-4894-8653-E823E62608CC}.dat
2007-05-14 23:10 32 –ahs—- C:\WINDOWS\system32\{27330E22-A365-4A5B-8A4B-6E89D928F8EB}.dat
2007-05-14 23:10 32 –ahs—- C:\WINDOWS\{D9908588-E7EE-4214-88BB-7A3DA9509535}.dat
2007-05-14 23:10 32 –ahs—- C:\WINDOWS\{B2CBB9E1-CE2B-4255-ADCC-71CAA0977109}.dat
2007-05-14 23:10 32 –ahs—- C:\WINDOWS\{631C8FC0-9412-4B0C-A747-40C964BD17C6}.dat
2007-05-14 18:18 184 –a—— C:\WINDOWS\system32\e000001.dat
2007-05-13 22:25 0 –a—— C:\WINDOWS\nsreg.dat
2007-05-12 23:10 0 -rahs—- C:\MSDOS.SYS
2007-05-12 23:10 0 -rahs—- C:\IO.SYS
2007-05-12 23:10 0 –a—— C:\CONFIG.SYS
2007-05-12 23:10 0 –a—— C:\AUTOEXEC.BAT
2007-05-12 23:07 21700 –a—— C:\WINDOWS\system32\emptyregdb.dat
2005-04-06 11:55 456384 –a—— C:\WINDOWS\inf\WG311T\WG311T13.sys
2004-10-19 19:58 35232 –a—— C:\WINDOWS\inf\WG311T\ME_INST.EXE
2004-10-19 19:58 26112 –a—— C:\WINDOWS\inf\WG311T\install.exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"APVXDWIN"="C:\Program\Panda Software\Panda Internet Security 2007\APVXDWIN.exe" [2007-04-27 20:44]
"SCANINICIO"="C:\Program\Panda Software\Panda Internet Security 2007\Inicio.exe" [2007-04-17 18:29]
"NaturalPoint"="C:\Program\NaturalPoint\TrackIR4\TrackIR.exe" [2007-01-15 16:31]
"Profiler"="C:\Program\Saitek\Software\ProfilerU.exe" [2006-09-05 09:12]
"SaiMfd"="C:\Program\Saitek\Software\SaiMfd.exe" [2006-09-28 11:19]
"CTSysVol"="C:\Program\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe" [2003-09-17 10:43]
"CTDVDDET"="C:\Program\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE" [2003-06-18 01:00]
"SBDrvDet"="C:\Program\Creative\SB Drive Det\SBDrvDet.exe" [2002-12-03 18:06]
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [2000-05-11 01:00]
"QD FastAndSafe"="" []
"Google Desktop Search"="C:\Program\Google\Google Desktop Search\GoogleDesktop.exe" [2007-05-15 17:29]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-01-23 15:44 C:\WINDOWS\KHALMNPR.Exe]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-01-23 15:44 C:\WINDOWS\KHALMNPR.Exe]
"Launch LCDMon"="C:\Program\Delade filer\Logitech\LCD Manager\lcdmon.exe" [2007-04-26 16:54]
"Launch LGDCore"="C:\Program\Delade filer\Logitech\G-series Software\LGDCore.exe" [2007-04-26 17:22]
"PCSuiteTrayApplication"="C:\Program\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-03-23 13:20]
"SunJavaUpdateSched"="C:\Program\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]
"Windows Defender"="C:\Program\Windows Defender\MSASCui.exe" [2006-11-03 19:20]
"AudioHQU"="C:\Program\Creative\SBAudigy2ZS\AudioHQ\AHQTbU.exe" [2002-01-18 01:13]
"Adobe Reader Speed Launcher"="C:\Program\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-06-29 00:43]
"nwiz"="nwiz.exe" [2007-06-29 00:43 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-06-29 00:43]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2006-01-12 15:40]
"CTHelper"="CTHELPER.EXE" [2005-12-08 12:06 C:\WINDOWS\CTHELPER.EXE]
"CTXFIREG"="CTxfiReg.exe" []

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 14:00]
"Fraps"="C:\FRAPS\FRAPS.EXE" [2006-10-26 15:09]
"nHancer"="C:\Program\KSE\nHancer 32bit\nHancer.exe" [2007-04-22 15:43]
"SpybotSD TeaTimer"="C:\Program\Spybot - Search & Destroy\TeaTimer.exe" [2005-05-31 01:04]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Nokia.PCSync"=C:\Program\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog

C:\Documents and Settings\All Users\Start-meny\Program\Autostart\
IL-2 Manager PF.lnk - F:\Tillbeh”r FB AEP PF\IL-2 Manager\il2m.exe [2004-10-30 16:42:06]
Logitech SetPoint.lnk - C:\Program\Logitech\SetPoint\SetPoint.exe [2007-05-19 19:57:49]
NETGEAR WG311T Wireless Assistant.lnk - C:\Program\NETGEAR\WG311T\wlancfg5.exe [2005-05-09 11:47:22]
Personal.lnk - C:\Program\Personal\bin\Personal.exe [2007-05-24 09:17:37]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}"= C:\Program\Qualcomm\Eudora\EuShlExt.dll [2006-08-17 14:57 86016]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avldr]
avldr.dll 2007-02-15 20:02 50736 C:\WINDOWS\system32\avldr.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=C:\Program\Google\GOOGLE~1\GOEC62~1.DLL

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup"

R1 NETFLTDI;Panda Net Driver [TDI Layer];\??\C:\WINDOWS\system32\Drivers\NETFLTDI.SYS
R3 L8042Kbd;Logitech SetPoint Keyboard Driver;C:\WINDOWS\system32\DRIVERS\L8042Kbd.sys
R3 L8042mou;SetPoint PS/2 Mouse Filter Driver;C:\WINDOWS\system32\DRIVERS\L8042mou.Sys
R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver;C:\WINDOWS\system32\DRIVERS\LHidFilt.Sys
R3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver;C:\WINDOWS\system32\DRIVERS\LMouFilt.Sys
R3 LMouKE;SetPoint Mouse Filter Driver;C:\WINDOWS\system32\DRIVERS\LMouKE.Sys
R3 LUsbFilt;Logitech SetPoint KMDF USB Filter;C:\WINDOWS\system32\Drivers\LUsbFilt.Sys
R3 NETIMFLT;PANDA NDIS IM Filter Miniport;C:\WINDOWS\system32\DRIVERS\netimflt.sys
R3 SaiH0763;SaiH0763;C:\WINDOWS\system32\DRIVERS\SaiH0763.sys
R3 Wdf01000;Wdf01000;C:\WINDOWS\system32\DRIVERS\Wdf01000.sys
S1 APPFLT;App Filter Plugin;\??\C:\WINDOWS\system32\Drivers\APPFLT.SYS
S1 DSAFLT;DSA Filter Plugin;\??\C:\WINDOWS\system32\Drivers\DSAFLT.SYS
S1 FNETMON;NetMon Filter Plugin;\??\C:\WINDOWS\system32\Drivers\fnetmon.SYS
S1 IDSFLT;Ids Filter Plugin;\??\C:\WINDOWS\system32\Drivers\IDSFLT.SYS
S1 ShldDrv;Panda File Shield Driver;C:\WINDOWS\system32\Drivers\ShlDrv51.sys
S1 SMSFLT;SMS Filter Plugin;\??\C:\WINDOWS\system32\Drivers\SMSFLT.SYS
S1 WNMFLT;Wifi Monitor Filter Plugin;\??\C:\WINDOWS\system32\Drivers\WNMFLT.SYS
S2 cpoint;Panda CPoint Driver;C:\WINDOWS\system32\drivers\cpoint.sys
S2 nHancer;nHancer Support;"C:\Program\KSE\nHancer 32bit\nHancerService.exe"
S2 PAVDRV;pavdrv;C:\WINDOWS\system32\DRIVERS\pavdrv51.sys
S2 PavProc;Panda Process Protection Driver;\??\C:\WINDOWS\system32\DRIVERS\PavProc.sys
S2 PfDetNT;PfDetNT;\??\C:\WINDOWS\system32\drivers\PfModNT.sys
S2 Stuffit Archive Name Service;Stuffit Archive Name Service;"C:\Program\Smith Micro\StuffIt11\ArcNameService.exe"
S3 AvFlt;Antivirus Filter Driver;C:\WINDOWS\system32\drivers\av5flt.sys
S3 ComFiltr;Panda Anti-Dialer;\??\C:\WINDOWS\system32\DRIVERS\COMFiltr.sys
S3 GMSIPCI;GMSIPCI;\??\D:\INSTALL\GMSIPCI.SYS
S3 hap17v2k;Creative P17V HAL Driver;C:\WINDOWS\system32\drivers\hap17v2k.sys
S3 nmwcd;Nokia USB Phone Parent;C:\WINDOWS\system32\drivers\nmwcd.sys
S3 nmwcdc;Nokia USB Generic;C:\WINDOWS\system32\drivers\nmwcdc.sys
S3 nmwcdcj;Nokia USB Port;C:\WINDOWS\system32\drivers\nmwcdcj.sys
S3 nmwcdcm;Nokia USB Modem;C:\WINDOWS\system32\drivers\nmwcdcm.sys
S3 NPDriver;Norton Unerase Protection Driver;\??\C:\WINDOWS\system32\Drivers\NPDRIVER.SYS
S3 NPUSB;NPUSB;C:\WINDOWS\system32\DRIVERS\npusb.sys
S3 PavSRK.sys;PavSRK.sys;\??\C:\WINDOWS\system32\PavSRK.sys
S3 PavTPK.sys;PavTPK.sys;\??\C:\WINDOWS\system32\PavTPK.sys
S3 SaiH0255;SaiH0255;C:\WINDOWS\system32\DRIVERS\SaiH0255.sys
S3 SaiMini;SaiMini;C:\WINDOWS\system32\DRIVERS\SaiMini.sys
S3 SaiNtBus;SaiNtBus;C:\WINDOWS\system32\drivers\SaiBus.sys
S3 sdthook;sdthook;\??\C:\WINDOWS\system32\drivers\sdthook.sys


Contents of the 'Scheduled Tasks' folder
2007-08-11 19:14:58 C:\WINDOWS\Tasks\MP Scheduled Scan.job - C:\Program\Windows Defender\MpCmdRun.exe
2007-07-13 15:30:00 C:\WINDOWS\Tasks\Norton SystemWorks One Button Checkup.job

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-11 23:32:17
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden registry entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-08-11 23:32:38
C:\ComboFix-quarantined-files.txt … 2007-08-11 23:32

— E O F —
Do you need to know what the BSOD report told me, I´ve also stored the last minidumps + a fulldump if you´d like to debug them too?
The error you're getting is from Logitech. Like a mouse or trackball.

Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\WINDOWS\system32\{8B5B3F24-9B5B-47E3-8532-D9A4AB58B407}.dat
C:\WINDOWS\{297B94AF-D43F-452B-8713-ACCE7A089EA2}.dat
C:\WINDOWS\system32\{1678C9C0-90D6-42AC-8CBD-63AC631F3EAA}.dat
C:\WINDOWS\{59BF51C0-A9B7-476F-9B2C-C14F0C796D7A}.dat
C:\WINDOWS\system32\{DECB10D9-FBAA-4D3F-A0EF-C0178860D675}.dat
C:\WINDOWS\{81325C69-4AE6-4EEC-B066-FD73412F685B}.dat
C:\WINDOWS\system32\{B0DCF7E3-93B4-433D-90FE-788D95F30192}.dat
C:\WINDOWS\system32\{9E88E583-8E47-4894-8653-E823E62608CC}.dat
C:\WINDOWS\system32\{27330E22-A365-4A5B-8A4B-6E89D928F8EB}.dat
C:\WINDOWS\{D9908588-E7EE-4214-88BB-7A3DA9509535}.dat
C:\WINDOWS\{B2CBB9E1-CE2B-4255-ADCC-71CAA0977109}.dat
C:\WINDOWS\{631C8FC0-9412-4B0C-A747-40C964BD17C6}.dat
C:\WINDOWS\system32\e000001.dat


Save this as Save this as "CFScript"


[external image: Posted Image]

Refering to the picture above, drag CFScript.txt into ComboFix.exe

Then post the results log
Result

ComboFix 07-08-09.3 - "Pelle" 2007-08-12 0:53:09.2 - NTFSx86 NETWORK
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1053.18.1590 [GMT 2:00]
Command switches used :: C:\Documents and Settings\Pelle\Skrivbord\CFScript.txt

FILE::
C:\WINDOWS\system32\{8B5B3F24-9B5B-47E3-8532-D9A4AB58B407}.dat
C:\WINDOWS\{297B94AF-D43F-452B-8713-ACCE7A089EA2}.dat
C:\WINDOWS\system32\{1678C9C0-90D6-42AC-8CBD-63AC631F3EAA}.dat
C:\WINDOWS\{59BF51C0-A9B7-476F-9B2C-C14F0C796D7A}.dat
C:\WINDOWS\system32\{DECB10D9-FBAA-4D3F-A0EF-C0178860D675}.dat
C:\WINDOWS\{81325C69-4AE6-4EEC-B066-FD73412F685B}.dat
C:\WINDOWS\system32\{B0DCF7E3-93B4-433D-90FE-788D95F30192}.dat
C:\WINDOWS\system32\{9E88E583-8E47-4894-8653-E823E62608CC}.dat
C:\WINDOWS\system32\{27330E22-A365-4A5B-8A4B-6E89D928F8EB}.dat
C:\WINDOWS\{D9908588-E7EE-4214-88BB-7A3DA9509535}.dat
C:\WINDOWS\{B2CBB9E1-CE2B-4255-ADCC-71CAA0977109}.dat
C:\WINDOWS\{631C8FC0-9412-4B0C-A747-40C964BD17C6}.dat
C:\WINDOWS\system32\e000001.dat


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\{297B94AF-D43F-452B-8713-ACCE7A089EA2}.dat
C:\WINDOWS\{59BF51C0-A9B7-476F-9B2C-C14F0C796D7A}.dat
C:\WINDOWS\{631C8FC0-9412-4B0C-A747-40C964BD17C6}.dat
C:\WINDOWS\{81325C69-4AE6-4EEC-B066-FD73412F685B}.dat
C:\WINDOWS\{B2CBB9E1-CE2B-4255-ADCC-71CAA0977109}.dat
C:\WINDOWS\{D9908588-E7EE-4214-88BB-7A3DA9509535}.dat
C:\WINDOWS\system32\{1678C9C0-90D6-42AC-8CBD-63AC631F3EAA}.dat
C:\WINDOWS\system32\{27330E22-A365-4A5B-8A4B-6E89D928F8EB}.dat
C:\WINDOWS\system32\{8B5B3F24-9B5B-47E3-8532-D9A4AB58B407}.dat
C:\WINDOWS\system32\{9E88E583-8E47-4894-8653-E823E62608CC}.dat
C:\WINDOWS\system32\{B0DCF7E3-93B4-433D-90FE-788D95F30192}.dat
C:\WINDOWS\system32\{DECB10D9-FBAA-4D3F-A0EF-C0178860D675}.dat
C:\WINDOWS\system32\e000001.dat


((((((((((((((((((((((((( Files Created from 2007-07-11 to 2007-08-11 )))))))))))))))))))))))))))))))


2007-08-11 23:02 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-08-11 20:58 82,944 -ra—— C:\WINDOWS\system32\MAPI.DLL
2007-08-11 02:31 d–h—– C:\WINDOWS\system32\GroupPolicy
2007-08-10 23:42 d——– C:\Program\Delade filer\Wise Installation Wizard
2007-08-10 23:35 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-08-10 21:55 d——– C:\WINDOWS\LastGood
2007-08-10 21:21 d–hs—- C:\WINDOWS\CSC
2007-08-09 16:57 524,288 –ah—– C:\DOCUME~1\ADMINI~1\NTUSER.DAT
2007-08-09 16:57 dr——- C:\DOCUME~1\ADMINI~1\Start-meny
2007-08-09 16:57 d–h—– C:\DOCUME~1\ADMINI~1\Skrivare
2007-08-09 16:57 d–h—– C:\DOCUME~1\ADMINI~1\N„tverket
2007-08-09 16:57 d–h—– C:\DOCUME~1\ADMINI~1\Mallar
2007-08-09 16:57 d–h—– C:\DOCUME~1\ADMINI~1\Lokala inst„llningar
2007-08-09 16:57 d——– C:\DOCUME~1\ADMINI~1\Skrivbord
2007-08-09 16:57 d——– C:\DOCUME~1\ADMINI~1\Mina dokument
2007-08-09 16:57 d——– C:\DOCUME~1\ADMINI~1\Favoriter
2007-07-28 00:14 10,240 –a—— C:\WINDOWS\CTDCRES.DLL
2007-07-27 23:00 d——– C:\DOCUME~1\Pelle\APPLIC~1\Help
2007-07-25 00:52 d——– C:\Program\Prime95
2007-07-21 23:45 364,544 ——— C:\WINDOWS\system32\TwnLib4.dll
2007-07-21 23:34 5,888 ——— C:\WINDOWS\system32\drivers\imagedrv.sys
2007-07-21 23:34 476,320 ——— C:\WINDOWS\system32\ImagXpr7.dll
2007-07-21 23:34 471,040 ——— C:\WINDOWS\system32\ImagXRA7.dll
2007-07-21 23:34 262,144 ——— C:\WINDOWS\system32\ImagXR7.dll
2007-07-21 23:34 155,648 –a—— C:\WINDOWS\system32\NeroCheck.exe
2007-07-21 23:34 127,488 ——— C:\WINDOWS\system32\drivers\imagesrv.sys
2007-07-21 23:34 106,496 –a—— C:\WINDOWS\system32\TwnLib20.dll
2007-07-21 23:34 1,568,768 ——— C:\WINDOWS\system32\ImagX7.dll
2007-07-21 23:34 d——– C:\Program\Delade filer\Ahead
2007-07-21 23:34 d——– C:\Program\Ahead
2007-07-21 22:04 356,352 –a—— C:\WINDOWS\system32\NVUNINST.EXE
2007-07-21 22:04 356,352 –a—— C:\WINDOWS\system32\nvudisp.exe
2007-07-21 22:04 d——– C:\WINDOWS\nview
2007-07-21 22:03 81,920 –a—— C:\WINDOWS\system32\nvwddi.dll
2007-07-21 22:03 81,920 –a—— C:\WINDOWS\system32\nvmctray.dll
2007-07-21 22:03 8,466,432 –a—— C:\WINDOWS\system32\nvcpl.dll
2007-07-21 22:03 753,664 –a—— C:\WINDOWS\system32\nvcplui.exe
2007-07-21 22:03 6,729,728 –a—— C:\WINDOWS\system32\nvoglnt.dll
2007-07-21 22:03 6,234,112 –a—— C:\WINDOWS\system32\nvdisps.dll
2007-07-21 22:03 5,455,872 –a—— C:\WINDOWS\system32\nvdispsr.dll
2007-07-21 22:03 466,944 –a—— C:\WINDOWS\system32\nvshell.dll
2007-07-21 22:03 458,752 –a—— C:\WINDOWS\system32\nvmccssr.dll
2007-07-21 22:03 45,056 –a—— C:\WINDOWS\system32\nvmccsrs.dll
2007-07-21 22:03 442,368 –a—— C:\WINDOWS\system32\nvappbar.exe
2007-07-21 22:03 425,984 –a—— C:\WINDOWS\system32\keystone.exe
2007-07-21 22:03 37,376 –a—— C:\WINDOWS\system32\nvcodins.dll
2007-07-21 22:03 37,376 –a—— C:\WINDOWS\system32\nvcod.dll
2007-07-21 22:03 360,448 –a—— C:\WINDOWS\system32\nvapi.dll
2007-07-21 22:03 335,872 –a—— C:\WINDOWS\system32\nvwrses.dll
2007-07-21 22:03 335,872 –a—— C:\WINDOWS\system32\nvwrsel.dll
2007-07-21 22:03 327,680 –a—— C:\WINDOWS\system32\nvwrsfr.dll
2007-07-21 22:03 327,680 –a—— C:\WINDOWS\system32\nvwrsesm.dll
2007-07-21 22:03 327,680 –a—— C:\WINDOWS\system32\nvrshe.dll
2007-07-21 22:03 327,680 –a—— C:\WINDOWS\system32\nvrsar.dll
2007-07-21 22:03 323,584 –a—— C:\WINDOWS\system32\nvwrspt.dll
2007-07-21 22:03 323,584 –a—— C:\WINDOWS\system32\nvwrsit.dll
2007-07-21 22:03 319,488 –a—— C:\WINDOWS\system32\nvwrsptb.dll
2007-07-21 22:03 319,488 –a—— C:\WINDOWS\system32\nvwrsnl.dll
2007-07-21 22:03 315,392 –a—— C:\WINDOWS\system32\nvwrsru.dll
2007-07-21 22:03 315,392 –a—— C:\WINDOWS\system32\nvwrshu.dll
2007-07-21 22:03 311,296 –a—— C:\WINDOWS\system32\nvwrsde.dll
2007-07-21 22:03 307,200 –a—— C:\WINDOWS\system32\nvexpbar.dll
2007-07-21 22:03 303,104 –a—— C:\WINDOWS\system32\nvwrstr.dll
2007-07-21 22:03 303,104 –a—— C:\WINDOWS\system32\nvwrssl.dll
2007-07-21 22:03 303,104 –a—— C:\WINDOWS\system32\nvwrsfi.dll
2007-07-21 22:03 3,600,384 –a—— C:\WINDOWS\system32\nvvitvsr.dll
2007-07-21 22:03 3,518,464 –a—— C:\WINDOWS\system32\nvvitvs.dll
2007-07-21 22:03 3,321,856 –a—— C:\WINDOWS\system32\nvgames.dll
2007-07-21 22:03 3,072,000 –a—— C:\WINDOWS\system32\nvgamesr.dll
2007-07-21 22:03 299,008 –a—— C:\WINDOWS\system32\nvwrssk.dll
2007-07-21 22:03 299,008 –a—— C:\WINDOWS\system32\nvwrsno.dll
2007-07-21 22:03 294,912 –a—— C:\WINDOWS\system32\nvwrssv.dll
2007-07-21 22:03 294,912 –a—— C:\WINDOWS\system32\nvwrspl.dll
2007-07-21 22:03 294,912 –a—— C:\WINDOWS\system32\nvwrsda.dll
2007-07-21 22:03 286,720 –a—— C:\WINDOWS\system32\nvwrseng.dll
2007-07-21 22:03 286,720 –a—— C:\WINDOWS\system32\nvwrscs.dll
2007-07-21 22:03 286,720 –a—— C:\WINDOWS\system32\nvnt4cpl.dll
2007-07-21 22:03 282,624 –a—— C:\WINDOWS\system32\nvwrsar.dll
2007-07-21 22:03 282,624 –a—— C:\WINDOWS\system32\nvrsfr.dll
2007-07-21 22:03 282,624 –a—— C:\WINDOWS\system32\nvrses.dll
2007-07-21 22:03 282,624 –a—— C:\WINDOWS\system32\nvrsel.dll
2007-07-21 22:03 278,528 –a—— C:\WINDOWS\system32\nvwrshe.dll
2007-07-21 22:03 278,528 –a—— C:\WINDOWS\system32\nvrsit.dll
2007-07-21 22:03 278,528 –a—— C:\WINDOWS\system32\nvrsde.dll
2007-07-21 22:03 274,432 –a—— C:\WINDOWS\system32\nvrspt.dll
2007-07-21 22:03 274,432 –a—— C:\WINDOWS\system32\nvrsnl.dll
2007-07-21 22:03 274,432 –a—— C:\WINDOWS\system32\nvrsesm.dll
2007-07-21 22:03 270,336 –a—— C:\WINDOWS\system32\nvrsru.dll
2007-07-21 22:03 266,240 –a—— C:\WINDOWS\system32\nvrsptb.dll
2007-07-21 22:03 266,240 –a—— C:\WINDOWS\system32\nvrsja.dll
2007-07-21 22:03 262,144 –a—— C:\WINDOWS\system32\nvrsko.dll
2007-07-21 22:03 258,048 –a—— C:\WINDOWS\system32\nvrstr.dll
2007-07-21 22:03 258,048 –a—— C:\WINDOWS\system32\nvrssl.dll
2007-07-21 22:03 258,048 –a—— C:\WINDOWS\system32\nvrssk.dll
2007-07-21 22:03 258,048 –a—— C:\WINDOWS\system32\nvrshu.dll
2007-07-21 22:03 253,952 –a—— C:\WINDOWS\system32\nvrssv.dll
2007-07-21 22:03 253,952 –a—— C:\WINDOWS\system32\nvrspl.dll
2007-07-21 22:03 253,952 –a—— C:\WINDOWS\system32\nvrsno.dll
2007-07-21 22:03 253,952 –a—— C:\WINDOWS\system32\nvrsda.dll
2007-07-21 22:03 249,856 –a—— C:\WINDOWS\system32\nvrsfi.dll


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-10 22:14 ——— d——– C:\Program\Windows Defender
2007-08-10 20:40 1184 –a—— C:\WINDOWS\system32\drivers\APPFLTR.CFG.bck
2007-08-10 20:40 1184 –a—— C:\WINDOWS\system32\drivers\APPFLTR.CFG
2007-08-10 20:23 344456 –a—— C:\WINDOWS\system32\drivers\APPFCONT.DAT.bck
2007-08-10 20:23 344456 –a—— C:\WINDOWS\system32\drivers\APPFCONT.DAT
2007-08-10 20:23 0 –ah—– C:\WINDOWS\system32\drivers\Msft_Kernel_LUsbFilt_01005.Wdf
2007-08-10 20:23 0 –ah—– C:\WINDOWS\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2007-07-29 22:16 ——— d——– C:\DOCUME~1\Pelle\APPLIC~1\OpenOffice.org2
2007-07-28 01:02 ——— d——– C:\Program\Norton SystemWorks
2007-07-28 00:27 ——— d–h—– C:\Program\InstallShield Installation Information
2007-07-28 00:18 ——— d——– C:\Program\Creative
2007-07-28 00:15 ——— d——– C:\DOCUME~1\Pelle\APPLIC~1\Creative
2007-07-21 22:20 ——— d——– C:\DOCUME~1\Pelle\APPLIC~1\nHancer
2007-07-19 00:18 1100 –a—— C:\WINDOWS\system32\d3d8caps.dat
2007-07-11 09:01 69816 –a—— C:\WINDOWS\system32\perfc01D.dat
2007-07-11 09:01 395852 –a—— C:\WINDOWS\system32\perfh01D.dat
2007-07-08 14:59 61 —hs—- C:\WINDOWS\cnerolf.bin
2007-07-03 20:52 ——— d——– C:\Program\MSI
2007-07-02 07:29 ——— d——– C:\DOCUME~1\Pelle\APPLIC~1\uTorrent
2007-06-30 22:06 120 –a—— C:\WINDOWS\system32\drivers\wnmsav.dat
2007-06-29 00:43 81920 –a—— C:\WINDOWS\system32\nvwddi.dll
2007-06-29 00:43 6807328 –a–c— C:\WINDOWS\system32\dllcache\nv4_mini.sys
2007-06-29 00:43 6807328 –a—— C:\WINDOWS\system32\drivers\nv4_mini.sys
2007-06-29 00:43 5690624 –a–c— C:\WINDOWS\system32\dllcache\nv4_disp.dll
2007-06-29 00:43 5690624 –a—— C:\WINDOWS\system32\nv4_disp.dll
2007-06-29 00:43 3600384 –a—— C:\WINDOWS\system32\nvvitvsr.dll
2007-06-29 00:43 3518464 –a—— C:\WINDOWS\system32\nvvitvs.dll
2007-06-29 00:43 335872 –a—— C:\WINDOWS\system32\nvwrses.dll
2007-06-29 00:43 335872 –a—— C:\WINDOWS\system32\nvwrsel.dll
2007-06-29 00:43 327680 –a—— C:\WINDOWS\system32\nvwrsfr.dll
2007-06-29 00:43 327680 –a—— C:\WINDOWS\system32\nvwrsesm.dll
2007-06-29 00:43 323584 –a—— C:\WINDOWS\system32\nvwrspt.dll
2007-06-29 00:43 323584 –a—— C:\WINDOWS\system32\nvwrsit.dll
2007-06-29 00:43 319488 –a—— C:\WINDOWS\system32\nvwrsptb.dll
2007-06-29 00:43 319488 –a—— C:\WINDOWS\system32\nvwrsnl.dll
2007-06-29 00:43 315392 –a—— C:\WINDOWS\system32\nvwrsru.dll
2007-06-29 00:43 315392 –a—— C:\WINDOWS\system32\nvwrshu.dll
2007-06-29 00:43 311296 –a—— C:\WINDOWS\system32\nvwrsde.dll
2007-06-29 00:43 303104 –a—— C:\WINDOWS\system32\nvwrstr.dll
2007-06-29 00:43 303104 –a—— C:\WINDOWS\system32\nvwrssl.dll
2007-06-29 00:43 303104 –a—— C:\WINDOWS\system32\nvwrsfi.dll
2007-06-29 00:43 299008 –a—— C:\WINDOWS\system32\nvwrssk.dll
2007-06-29 00:43 299008 –a—— C:\WINDOWS\system32\nvwrsno.dll
2007-06-29 00:43 294912 –a—— C:\WINDOWS\system32\nvwrssv.dll
2007-06-29 00:43 294912 –a—— C:\WINDOWS\system32\nvwrspl.dll
2007-06-29 00:43 294912 –a—— C:\WINDOWS\system32\nvwrsda.dll
2007-06-29 00:43 286720 –a—— C:\WINDOWS\system32\nvwrseng.dll
2007-06-29 00:43 286720 –a—— C:\WINDOWS\system32\nvwrscs.dll
2007-06-29 00:43 282624 –a—— C:\WINDOWS\system32\nvwrsar.dll
2007-06-29 00:43 278528 –a—— C:\WINDOWS\system32\nvwrshe.dll
2007-06-29 00:43 2416640 –a—— C:\WINDOWS\system32\nvwssr.dll
2007-06-29 00:43 2330624 –a—— C:\WINDOWS\system32\nvwss.dll
2007-06-29 00:43 212992 –a—— C:\WINDOWS\system32\nvwrsja.dll
2007-06-29 00:43 196608 –a—— C:\WINDOWS\system32\nvwrsko.dll
2007-06-29 00:43 167936 –a—— C:\WINDOWS\system32\nvwrszht.dll
2007-06-29 00:43 163840 –a—— C:\WINDOWS\system32\nvwrszhc.dll
2007-06-29 00:43 1018772 –a—— C:\WINDOWS\system32\nvucode.bin
2007-05-25 10:00 249 –a—— C:\WINDOWS\system32\PavCPL.dat
2007-05-17 18:40 2184 –a—— C:\WINDOWS\mozver.dat
2007-05-16 21:50 737280 –a—— C:\WINDOWS\iun6002.exe
2007-05-16 17:20 86528 –a–c— C:\WINDOWS\system32\dllcache\directdb.dll
2007-05-16 17:20 85504 –a–c— C:\WINDOWS\system32\dllcache\wabimp.dll
2007-05-16 17:20 683520 –a–c— C:\WINDOWS\system32\dllcache\inetcomm.dll
2007-05-16 17:20 683520 –a—— C:\WINDOWS\system32\inetcomm.dll
2007-05-16 17:20 510976 –a–c— C:\WINDOWS\system32\dllcache\wab32.dll
2007-05-16 17:20 1314816 –a–c— C:\WINDOWS\system32\dllcache\msoe.dll
2007-05-13 22:25 0 –a—— C:\WINDOWS\nsreg.dat
2007-05-12 23:10 0 -rahs—- C:\MSDOS.SYS
2007-05-12 23:10 0 -rahs—- C:\IO.SYS
2007-05-12 23:10 0 –a—— C:\CONFIG.SYS
2007-05-12 23:10 0 –a—— C:\AUTOEXEC.BAT
2007-05-12 23:07 21700 –a—— C:\WINDOWS\system32\emptyregdb.dat
2005-04-06 11:55 456384 –a—— C:\WINDOWS\inf\WG311T\WG311T13.sys
2004-10-19 19:58 35232 –a—— C:\WINDOWS\inf\WG311T\ME_INST.EXE
2004-10-19 19:58 26112 –a—— C:\WINDOWS\inf\WG311T\install.exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"APVXDWIN"="C:\Program\Panda Software\Panda Internet Security 2007\APVXDWIN.exe" [2007-04-27 20:44]
"SCANINICIO"="C:\Program\Panda Software\Panda Internet Security 2007\Inicio.exe" [2007-04-17 18:29]
"NaturalPoint"="C:\Program\NaturalPoint\TrackIR4\TrackIR.exe" [2007-01-15 16:31]
"Profiler"="C:\Program\Saitek\Software\ProfilerU.exe" [2006-09-05 09:12]
"SaiMfd"="C:\Program\Saitek\Software\SaiMfd.exe" [2006-09-28 11:19]
"CTSysVol"="C:\Program\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe" [2003-09-17 10:43]
"CTDVDDET"="C:\Program\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE" [2003-06-18 01:00]
"SBDrvDet"="C:\Program\Creative\SB Drive Det\SBDrvDet.exe" [2002-12-03 18:06]
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [2000-05-11 01:00]
"QD FastAndSafe"="" []
"Google Desktop Search"="C:\Program\Google\Google Desktop Search\GoogleDesktop.exe" [2007-05-15 17:29]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-01-23 15:44 C:\WINDOWS\KHALMNPR.Exe]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-01-23 15:44 C:\WINDOWS\KHALMNPR.Exe]
"Launch LCDMon"="C:\Program\Delade filer\Logitech\LCD Manager\lcdmon.exe" [2007-04-26 16:54]
"Launch LGDCore"="C:\Program\Delade filer\Logitech\G-series Software\LGDCore.exe" [2007-04-26 17:22]
"PCSuiteTrayApplication"="C:\Program\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-03-23 13:20]
"SunJavaUpdateSched"="C:\Program\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]
"Windows Defender"="C:\Program\Windows Defender\MSASCui.exe" [2006-11-03 19:20]
"AudioHQU"="C:\Program\Creative\SBAudigy2ZS\AudioHQ\AHQTbU.exe" [2002-01-18 01:13]
"Adobe Reader Speed Launcher"="C:\Program\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-06-29 00:43]
"nwiz"="nwiz.exe" [2007-06-29 00:43 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-06-29 00:43]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2006-01-12 15:40]
"CTHelper"="CTHELPER.EXE" [2005-12-08 12:06 C:\WINDOWS\CTHELPER.EXE]
"CTXFIREG"="CTxfiReg.exe" []

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 14:00]
"Fraps"="C:\FRAPS\FRAPS.EXE" [2006-10-26 15:09]
"nHancer"="C:\Program\KSE\nHancer 32bit\nHancer.exe" [2007-04-22 15:43]
"SpybotSD TeaTimer"="C:\Program\Spybot - Search & Destroy\TeaTimer.exe" [2005-05-31 01:04]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Nokia.PCSync"=C:\Program\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog

C:\Documents and Settings\All Users\Start-meny\Program\Autostart\
IL-2 Manager PF.lnk - F:\Tillbeh”r FB AEP PF\IL-2 Manager\il2m.exe [2004-10-30 16:42:06]
Logitech SetPoint.lnk - C:\Program\Logitech\SetPoint\SetPoint.exe [2007-05-19 19:57:49]
NETGEAR WG311T Wireless Assistant.lnk - C:\Program\NETGEAR\WG311T\wlancfg5.exe [2005-05-09 11:47:22]
Personal.lnk - C:\Program\Personal\bin\Personal.exe [2007-05-24 09:17:37]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}"= C:\Program\Qualcomm\Eudora\EuShlExt.dll [2006-08-17 14:57 86016]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avldr]
avldr.dll 2007-02-15 20:02 50736 C:\WINDOWS\system32\avldr.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=C:\Program\Google\GOOGLE~1\GOEC62~1.DLL

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup"

R1 NETFLTDI;Panda Net Driver [TDI Layer];\??\C:\WINDOWS\system32\Drivers\NETFLTDI.SYS
R3 L8042Kbd;Logitech SetPoint Keyboard Driver;C:\WINDOWS\system32\DRIVERS\L8042Kbd.sys
R3 L8042mou;SetPoint PS/2 Mouse Filter Driver;C:\WINDOWS\system32\DRIVERS\L8042mou.Sys
R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver;C:\WINDOWS\system32\DRIVERS\LHidFilt.Sys
R3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver;C:\WINDOWS\system32\DRIVERS\LMouFilt.Sys
R3 LMouKE;SetPoint Mouse Filter Driver;C:\WINDOWS\system32\DRIVERS\LMouKE.Sys
R3 LUsbFilt;Logitech SetPoint KMDF USB Filter;C:\WINDOWS\system32\Drivers\LUsbFilt.Sys
R3 NETIMFLT;PANDA NDIS IM Filter Miniport;C:\WINDOWS\system32\DRIVERS\netimflt.sys
R3 SaiH0763;SaiH0763;C:\WINDOWS\system32\DRIVERS\SaiH0763.sys
R3 Wdf01000;Wdf01000;C:\WINDOWS\system32\DRIVERS\Wdf01000.sys
S1 APPFLT;App Filter Plugin;\??\C:\WINDOWS\system32\Drivers\APPFLT.SYS
S1 DSAFLT;DSA Filter Plugin;\??\C:\WINDOWS\system32\Drivers\DSAFLT.SYS
S1 FNETMON;NetMon Filter Plugin;\??\C:\WINDOWS\system32\Drivers\fnetmon.SYS
S1 IDSFLT;Ids Filter Plugin;\??\C:\WINDOWS\system32\Drivers\IDSFLT.SYS
S1 ShldDrv;Panda File Shield Driver;C:\WINDOWS\system32\Drivers\ShlDrv51.sys
S1 SMSFLT;SMS Filter Plugin;\??\C:\WINDOWS\system32\Drivers\SMSFLT.SYS
S1 WNMFLT;Wifi Monitor Filter Plugin;\??\C:\WINDOWS\system32\Drivers\WNMFLT.SYS
S2 cpoint;Panda CPoint Driver;C:\WINDOWS\system32\drivers\cpoint.sys
S2 nHancer;nHancer Support;"C:\Program\KSE\nHancer 32bit\nHancerService.exe"
S2 PAVDRV;pavdrv;C:\WINDOWS\system32\DRIVERS\pavdrv51.sys
S2 PavProc;Panda Process Protection Driver;\??\C:\WINDOWS\system32\DRIVERS\PavProc.sys
S2 PfDetNT;PfDetNT;\??\C:\WINDOWS\system32\drivers\PfModNT.sys
S2 Stuffit Archive Name Service;Stuffit Archive Name Service;"C:\Program\Smith Micro\StuffIt11\ArcNameService.exe"
S3 AvFlt;Antivirus Filter Driver;C:\WINDOWS\system32\drivers\av5flt.sys
S3 ComFiltr;Panda Anti-Dialer;\??\C:\WINDOWS\system32\DRIVERS\COMFiltr.sys
S3 GMSIPCI;GMSIPCI;\??\D:\INSTALL\GMSIPCI.SYS
S3 hap17v2k;Creative P17V HAL Driver;C:\WINDOWS\system32\drivers\hap17v2k.sys
S3 nmwcd;Nokia USB Phone Parent;C:\WINDOWS\system32\drivers\nmwcd.sys
S3 nmwcdc;Nokia USB Generic;C:\WINDOWS\system32\drivers\nmwcdc.sys
S3 nmwcdcj;Nokia USB Port;C:\WINDOWS\system32\drivers\nmwcdcj.sys
S3 nmwcdcm;Nokia USB Modem;C:\WINDOWS\system32\drivers\nmwcdcm.sys
S3 NPDriver;Norton Unerase Protection Driver;\??\C:\WINDOWS\system32\Drivers\NPDRIVER.SYS
S3 NPUSB;NPUSB;C:\WINDOWS\system32\DRIVERS\npusb.sys
S3 PavSRK.sys;PavSRK.sys;\??\C:\WINDOWS\system32\PavSRK.sys
S3 PavTPK.sys;PavTPK.sys;\??\C:\WINDOWS\system32\PavTPK.sys
S3 SaiH0255;SaiH0255;C:\WINDOWS\system32\DRIVERS\SaiH0255.sys
S3 SaiMini;SaiMini;C:\WINDOWS\system32\DRIVERS\SaiMini.sys
S3 SaiNtBus;SaiNtBus;C:\WINDOWS\system32\drivers\SaiBus.sys
S3 sdthook;sdthook;\??\C:\WINDOWS\system32\drivers\sdthook.sys

*Newly Created Service* - CATCHME

Contents of the 'Scheduled Tasks' folder
2007-08-11 19:14:58 C:\WINDOWS\Tasks\MP Scheduled Scan.job - C:\Program\Windows Defender\MpCmdRun.exe
2007-07-13 15:30:00 C:\WINDOWS\Tasks\Norton SystemWorks One Button Checkup.job

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-12 00:53:27
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden registry entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-08-12 0:53:52
C:\ComboFix-quarantined-files.txt … 2007-08-12 00:53
C:\ComboFix2.txt … 2007-08-11 23:32

— E O F —
Delete this file if listed:
C:\WINDOWS\iun6002.exe

Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
I didn´t read the first line before rebooting so it took nearly 1 hour with the system ( CPU ) running at nearly 100% 96 % of the time! Tereafter I got BSOD "IRQ not less or equal" still referring to the LUsbFilt.
The log is here, I´ll do another reboot after deleting the .exe you told me
Logfile of HijackThis v1.99.1
Scan saved at 02:02:13, on 2007-08-12
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program\Windows Defender\MsMpEng.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\Explorer.EXE
C:\Program\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.handelsbanken.se/jarna
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.pandasoftware.com/redirector/?p…rt&lang=swe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
O2 - BHO: Länkhjälp till Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program\Delade filer\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program\Java\jre1.6.0_01\bin\ssv.dll
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program\Panda Software\Panda Internet Security 2007\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [SCANINICIO] "C:\Program\Panda Software\Panda Internet Security 2007\Inicio.exe"
O4 - HKLM\..\Run: [NaturalPoint] C:\Program\NaturalPoint\TrackIR4\TrackIR.exe
O4 - HKLM\..\Run: [Profiler] C:\Program\Saitek\Software\ProfilerU.exe
O4 - HKLM\..\Run: [SaiMfd] C:\Program\Saitek\Software\SaiMfd.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [CTDVDDET] C:\Program\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE
O4 - HKLM\..\Run: [SBDrvDet] C:\Program\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program\Delade filer\Logitech\LCD Manager\lcdmon.exe"
O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program\Delade filer\Logitech\G-series Software\LGDCore.exe" /SHOWHIDE
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [AudioHQU] C:\Program\Creative\SBAudigy2ZS\AudioHQ\AHQTbU.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTXFIREG] CTxfiReg.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Fraps] C:\FRAPS\FRAPS.EXE
O4 - HKCU\..\Run: [nHancer] "C:\Program\KSE\nHancer 32bit\nHancer.exe" /tray
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: IL-2 Manager PF.lnk = ?
O4 - Global Startup: Logitech SetPoint.lnk = ?
O4 - Global Startup: NETGEAR WG311T Wireless Assistant.lnk = C:\Program\NETGEAR\WG311T\wlancfg5.exe
O4 - Global Startup: Personal.lnk = C:\Program\Personal\bin\Personal.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java-konsol - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1F2AA8E4-9D1E-4A3C-9010-852C68EE46AC}: NameServer = 195.58.103.124,195.58.103.18
O17 - HKLM\System\CS1\Services\Tcpip\..\{1F2AA8E4-9D1E-4A3C-9010-852C68EE46AC}: NameServer = 195.58.103.124,195.58.103.18
O17 - HKLM\System\CS2\Services\Tcpip\..\{1F2AA8E4-9D1E-4A3C-9010-852C68EE46AC}: NameServer = 195.58.103.124,195.58.103.18
O20 - AppInit_DLLs: C:\Program\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: avldr - C:\WINDOWS\SYSTEM32\avldr.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program\Delade filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: nHancer Support (nHancer) - KSE - Korndörfer Software Engineering - C:\Program\KSE\nHancer 32bit\nHancerService.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Panda Software Controller - Panda Software International - C:\Program\Panda Software\Panda Internet Security 2007\PsCtrls.exe
O23 - Service: Panda Function Service (PAVFNSVR) - Panda Software International - C:\Program\Panda Software\Panda Internet Security 2007\PavFnSvr.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software International - C:\Program\Delade filer\Panda Software\PavShld\pavprsrv.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software International - C:\Program\Panda Software\Panda Internet Security 2007\pavsrv51.exe
O23 - Service: Panda Antispam Engine (pmshellsrv) - Panda Software International - C:\Program\Panda Software\Panda Internet Security 2007\AntiSpam\pskmssvc.exe
O23 - Service: Panda Host Service (PSHost) - Panda Software International - c:\program\panda software\panda internet security 2007\firewall\PSHOST.EXE
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software International - C:\Program\Panda Software\Panda Internet Security 2007\psimsvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\Program\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: Stuffit Archive Name Service - Smith Micro Software, Inc. - C:\Program\Smith Micro\StuffIt11\ArcNameService.exe
O23 - Service: Panda TPSrv (TPSrv) - Panda Software International - C:\Program\Panda Software\Panda Internet Security 2007\TPSrv.exe
And here´s the next log, after the removal:

Logfile of HijackThis v1.99.1
Scan saved at 02:14:04, on 2007-08-12
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program\Windows Defender\MsMpEng.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\Explorer.EXE
C:\Program\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.handelsbanken.se/jarna
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.pandasoftware.com/redirector/?p…rt&lang=swe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
O2 - BHO: Länkhjälp till Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program\Delade filer\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program\Java\jre1.6.0_01\bin\ssv.dll
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program\Panda Software\Panda Internet Security 2007\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [SCANINICIO] "C:\Program\Panda Software\Panda Internet Security 2007\Inicio.exe"
O4 - HKLM\..\Run: [NaturalPoint] C:\Program\NaturalPoint\TrackIR4\TrackIR.exe
O4 - HKLM\..\Run: [Profiler] C:\Program\Saitek\Software\ProfilerU.exe
O4 - HKLM\..\Run: [SaiMfd] C:\Program\Saitek\Software\SaiMfd.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [CTDVDDET] C:\Program\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE
O4 - HKLM\..\Run: [SBDrvDet] C:\Program\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program\Delade filer\Logitech\LCD Manager\lcdmon.exe"
O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program\Delade filer\Logitech\G-series Software\LGDCore.exe" /SHOWHIDE
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [AudioHQU] C:\Program\Creative\SBAudigy2ZS\AudioHQ\AHQTbU.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTXFIREG] CTxfiReg.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Fraps] C:\FRAPS\FRAPS.EXE
O4 - HKCU\..\Run: [nHancer] "C:\Program\KSE\nHancer 32bit\nHancer.exe" /tray
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: IL-2 Manager PF.lnk = ?
O4 - Global Startup: Logitech SetPoint.lnk = ?
O4 - Global Startup: NETGEAR WG311T Wireless Assistant.lnk = C:\Program\NETGEAR\WG311T\wlancfg5.exe
O4 - Global Startup: Personal.lnk = C:\Program\Personal\bin\Personal.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java-konsol - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1F2AA8E4-9D1E-4A3C-9010-852C68EE46AC}: NameServer = 195.58.103.124,195.58.103.18
O17 - HKLM\System\CS1\Services\Tcpip\..\{1F2AA8E4-9D1E-4A3C-9010-852C68EE46AC}: NameServer = 195.58.103.124,195.58.103.18
O17 - HKLM\System\CS2\Services\Tcpip\..\{1F2AA8E4-9D1E-4A3C-9010-852C68EE46AC}: NameServer = 195.58.103.124,195.58.103.18
O20 - AppInit_DLLs: C:\Program\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: avldr - C:\WINDOWS\SYSTEM32\avldr.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program\Delade filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: nHancer Support (nHancer) - KSE - Korndörfer Software Engineering - C:\Program\KSE\nHancer 32bit\nHancerService.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Panda Software Controller - Panda Software International - C:\Program\Panda Software\Panda Internet Security 2007\PsCtrls.exe
O23 - Service: Panda Function Service (PAVFNSVR) - Panda Software International - C:\Program\Panda Software\Panda Internet Security 2007\PavFnSvr.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software International - C:\Program\Delade filer\Panda Software\PavShld\pavprsrv.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software International - C:\Program\Panda Software\Panda Internet Security 2007\pavsrv51.exe
O23 - Service: Panda Antispam Engine (pmshellsrv) - Panda Software International - C:\Program\Panda Software\Panda Internet Security 2007\AntiSpam\pskmssvc.exe
O23 - Service: Panda Host Service (PSHost) - Panda Software International - c:\program\panda software\panda internet security 2007\firewall\PSHOST.EXE
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software International - C:\Program\Panda Software\Panda Internet Security 2007\psimsvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\Program\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: Stuffit Archive Name Service - Smith Micro Software, Inc. - C:\Program\Smith Micro\StuffIt11\ArcNameService.exe
O23 - Service: Panda TPSrv (TPSrv) - Panda Software International - C:\Program\Panda Software\Panda Internet Security 2007\TPSrv.exe
Should I have removed the file after the Combofix and before reboot for the fix to work? If so I´ll redo the whole tapdance in the morning, monday is back to work!!!
Had my 5 weeks of holiday now!
No not ATM it doesn´t seem to start automatically when running in safe mode! I started it up. Now I´ll have to hit the sac, I´ll be back tomorrow! Please give me instructions on what to do when I start up again. If you need to be online for the work at what time should I log in? I think I´m 7 - 8 hrs earlier than you over there so there´s a lot of time lost.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI