This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved]Securepccleaner Infection - Need Help Removing

30 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

1 Problem left.


Go HERE and Download System Repair Engine by smallfrogs
http://www.kztechs.com/eng/index.html

Save it to your Desktop
Rt Click sreng2.zip->>Extract all->>Extract it to your desktop
Open the sreng folder
Double click SREng->>Click Run
At the main Window, in the left Pane,Select Smart Scan
At the next window make sure all of the boxes are checked and Select Scan
When the scan is complete Select Save reports
Save it to your desktop and Close the tool
Double Click SREngLog.txt copy and paste that log as a reply to this thread



Do not run any other options with this tool unless instructed to do so.
Hi Trevuren - here is the log from using sreng by smallfrogs. Regards


2007-08-13,07:33:47

System Repair Engineer 2.5.16.900
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600) - Administrative User - Completed Functions Allowed

Follow item(s) have been choosed:
	All Boot Items (Including Registry, Startup Folders, Services and so on)
	Browser Add-ons
	Runing Processes (Including process model information)
	File Associations
	Winsock Provider
	Autorun.Inf
	HOSTS File
	Process Privileges Scan


Boot Items
Registry
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
	<"C:\Program Files\Messenger\msmsgs.exe" /background>  [(Verified)Microsoft Windows XP Publisher]
	<"C:\PROGRA~1\Ahead\NEROBA~1\NBJ.exe">  [Ahead Software AG]
	  [(Verified)Google Inc]
	  [Logitech]
	  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
	  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
	  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
	  [(Verified)Microsoft Windows Publisher]
	  [Ahead Software Gmbh]
	<"C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe">  [Cyberlink Corp.]
	  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
	<"C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>  [(Verified)"RealNetworks, Inc."]
	  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
	<"C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe">  [(Verified)"Logitech, Inc."]
	<"C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe">  [(Verified)"Logitech, Inc."]
	<"C:\Program Files\QuickTime\qttask.exe" -atboottime>  [Apple Computer, Inc.]
	<"C:\Program Files\iTunes\iTunesHelper.exe">  [(Verified)"Apple Computer, Inc."]
	<"C:\Program Files\Common Files\Symantec Shared\ccApp.exe">  [(Verified)Symantec Corporation]
	<"C:\Program Files\Norton AntiVirus\osCheck.exe">  [(Verified)Symantec Corporation]
	<"C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll">  [N/A]
	<"C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe">  [(Verified)"Sun Microsystems, Inc."]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
	  [(Verified)Microsoft Windows Publisher]
	  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
	<>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
	  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
	<%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
	<%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
	<%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
	<"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
	  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{4b218e3e-bc98-4770-93d3-2731b9329278}]
	<%SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection MarketplaceLinkInstall 896 %systemroot%\inf\ie.inf>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
	  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
	  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
	<"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
	  [Microsoft Corporation]

==================================
Startup Folders
[Adobe Reader Speed Launch]
   C:\PROGRA~1\Adobe\ACROBA~2.0\Reader\READER~1.EXE [Adobe Systems Incorporated]>
[Logitech Desktop Messenger]
   C:\PROGRA~1\Logitech\DESKTO~1\8876480\Program\LDMConf.exe [Logitech]>
[Logitech SetPoint]
   C:\PROGRA~1\Logitech\SetPoint\SetPoint.exe [Logitech Inc.]>
[Microsoft Office]
   C:\PROGRA~1\MICROS~2\Office10\OSA.EXE [Microsoft Corporation]>
[NBC4 LIVE ONLINE]
   C:\PROGRA~1\NBC4LI~1\LIVEON~1.EXE [N/A]>

==================================
Services
[ASP.NET State Service / aspnet_state][Stopped/Manual Start]
  
[Automatic LiveUpdate Scheduler / Automatic LiveUpdate Scheduler][Running/Auto Start]
  <"C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe">
[Symantec Event Manager / ccEvtMgr][Running/Auto Start]
  <"C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon>
[Symantec Settings Manager / ccSetMgr][Running/Auto Start]
  <"C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon>
[Symantec Lic NetConnect service / CLTNetCnService][Running/Auto Start]
  <"C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon>
[Google Updater Service / gusvc][Stopped/Manual Start]
  <"C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe">
[InstallDriver Table Manager / IDriverT][Stopped/Manual Start]
  <"C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe">
[iPod Service / iPod Service][Running/Manual Start]
  <"C:\Program Files\iPod\bin\iPodService.exe">
[Symantec IS Password Validation / ISPwdSvc][Stopped/Manual Start]
  <"C:\Program Files\Norton AntiVirus\isPwdSvc.exe">
[Kodak Camera Connection Software / KodakCCS][Running/Auto Start]
  
[LiveUpdate / LiveUpdate][Stopped/Manual Start]
  <"C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE">
[LiveUpdate Notice Service Ex / LiveUpdate Notice Ex][Running/Auto Start]
  <"C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon>
[LiveUpdate Notice Service / LiveUpdate Notice Service][Stopped/Auto Start]
  <"C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll">
[Norton UnErase Protection / NProtectService][Running/Auto Start]
  
[NVIDIA Display Driver Service / NVSvc][Running/Auto Start]
  
[ScsiAccess / ScsiAccess][Running/Auto Start]
  
[Speed Disk service / Speed Disk service][Running/Auto Start]
  
[Symantec Core LC / Symantec Core LC][Running/Manual Start]
  <"C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe">
[Symantec AppCore Service / SymAppCore][Running/Auto Start]
  <"C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe">

==================================
Drivers
[aeaudio / aeaudio][Running/Manual Start]
  
[catchme / catchme][Stopped/Manual Start]
  <\??\C:\DOCUME~1\DAVEW~1\LOCALS~1\Temp\catchme.sys>
[Kodak Camera Proxy / DcCam][Running/System Start]
  
[DcFpoint / DcFpoint][Stopped/Manual Start]
  
[Kodak DCFS2K Driver / DCFS2K][Running/Auto Start]
  
[Legacy Polling Service / DcLps][Stopped/Manual Start]
  
[DcPTP / DcPTP][Stopped/Manual Start]
  
[Symantec Eraser Control driver / eeCtrl][Running/System Start]
  <\??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys>
[EraserUtilRebootDrv / EraserUtilRebootDrv][Running/Manual Start]
  <\??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys>
[Exportit / Exportit][Stopped/System Start]
  
[VIA Rhine-Family Fast Ethernet Adapter Driver Service / FETND5BV][Running/Manual Start]
  
[VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver / FETNDIS][Stopped/Manual Start]
  
[GEAR CDRom Filter / GEARAspiWDM][Running/Manual Start]
  
[Logitech SetPoint Keyboard Driver / L8042Kbd][Stopped/Manual Start]
  
[LBeepKE / LBeepKE][Running/Auto Start]
  
[Logitech SetPoint HID Mouse Filter Driver / LHidKe][Running/Manual Start]
  
[Logitech SetPoint Mouse Filter Driver / LMouKE][Running/Manual Start]
  
[NAVENG / NAVENG][Running/Manual Start]
  <\??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20070812.007\NAVENG.SYS>
[NAVEX15 / NAVEX15][Running/Manual Start]
  <\??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20070812.007\NAVEX15.SYS>
[Norton UnErase Protection Driver / NPDriver][Running/Manual Start]
  <\??\C:\WINDOWS\system32\Drivers\NPDRIVER.SYS>
[nv / nv][Running/Manual Start]
  
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  
[SDdriver / SDdriver][Stopped/Manual Start]
  <\??\C:\WINDOWS\system32\Drivers\sddriver.sys>
[Secdrv / Secdrv][Running/Auto Start]
  
[senfilt / senfilt][Running/Manual Start]
  
[smwdm / smwdm][Running/Manual Start]
  
[Sony Digital Imaging Video2 / sonypvs1][Stopped/Manual Start]
  
[SPBBCDrv / SPBBCDrv][Stopped/Manual Start]
  <\??\C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys>
[SRTSP / SRTSP][Running/System Start]
  
[SRTSPL / SRTSPL][Stopped/Manual Start]
  
[SRTSPX / SRTSPX][Running/System Start]
  
[SYMDNS / SYMDNS][Running/Manual Start]
  <\SystemRoot\System32\Drivers\SYMDNS.SYS>
[SymEvent / SymEvent][Running/Manual Start]
  <\??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS>
[SYMFW / SYMFW][Running/Manual Start]
  <\SystemRoot\System32\Drivers\SYMFW.SYS>
[SYMIDS / SYMIDS][Running/Manual Start]
  <\SystemRoot\System32\Drivers\SYMIDS.SYS>
[SYMIDSCO / SYMIDSCO][Running/Manual Start]
  <\??\C:\PROGRA~1\COMMON~1\SYMANT~1\SymcData\IDS-DI~1\20070809.002\SymIDSCo.sys>
[SYMNDIS / SYMNDIS][Running/Manual Start]
  <\SystemRoot\System32\Drivers\SYMNDIS.SYS>
[SYMREDRV / SYMREDRV][Running/Manual Start]
  <\SystemRoot\System32\Drivers\SYMREDRV.SYS>
[SYMTDI / SYMTDI][Running/System Start]
  <\SystemRoot\System32\Drivers\SYMTDI.SYS>
[ViaIde / ViaIde][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\viaide.sys>
[viamraid / viamraid][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\viamraid.sys>
[World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
  

==================================
Browser Add-ons
[SnagIt Toolbar Loader]
  {00C6482D-C502-44C8-8409-FCE54AD9C208} 
[Adobe PDF Reader Link Helper]
  {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} 
[SSVHelper Class]
  {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} 
[Google Toolbar Helper]
  {AA58ED58-01DD-4d91-8333-CF10577473F7} 
[Google Toolbar Notifier BHO]
  {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} 
[Java Plug-in 1.6.0_01]
  {08B0E5C0-4FCB-11CF-AAA5-00401C608501} 
[Express Cleanup]
  {5E638779-1818-4754-A595-EF1C63B87A56} 
[Messenger]
  {FB5F1910-F110-11d2-BB9E-00C04F795683} 
[&Google]
  {2318C2B1-4965-11d4-9B18-009027A5CD4F} 
[SnagIt]
  {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} 
[Shockwave ActiveX Control]
  {166B1BCA-3F9C-11CF-8075-444553540000} 
[Java Plug-in 1.6.0_01]
  {8AD9C840-044E-11D1-B3E9-00805F499D93} 
[Java Plug-in 1.6.0_01]
  {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} 
[Java Plug-in 1.6.0_01]
  {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} 
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} 
[First American Res MapActiveX Control]
  {F375116A-793C-11D2-BFE1-444553540001} 
[SnagIt Toolbar Loader]
  {00C6482D-C502-44C8-8409-FCE54AD9C208} 
[Yahoo! Toolbar Helper]
  {02478D38-C3F9-4EFB-9B51-7695ECA05670} <, N/A>
[Adobe PDF Reader Link Helper]
  {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} 
[&Google]
  {2318C2B1-4965-11D4-9B18-009027A5CD4F} 
[Active Desktop Mover]
  {72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, N/A>
[SSVHelper Class]
  {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} 
[SnagIt]
  {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} 
[Google Toolbar Helper]
  {AA58ED58-01DD-4D91-8333-CF10577473F7} 
[Google Toolbar Notifier BHO]
  {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} 
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} 
[Yahoo! Toolbar]
  {EF99BD32-C1FB-11D2-892F-0090271D4F88} <, N/A>
[E&xport to Microsoft Excel]
  

==================================
Running Processes
[PID: 580 / SYSTEM][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 628 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 652 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 696 / SYSTEM][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 712 / SYSTEM][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 864 / SYSTEM][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 932 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1028 / SYSTEM][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1208 / NETWORK SERVICE][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1300 / LOCAL SERVICE][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1396 / SYSTEM][C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe]  [Symantec Corporation, 106.2.0.21]
	[C:\WINDOWS\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
	[C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
	[C:\Program Files\Common Files\Symantec Shared\ccL60U.dll]  [Symantec Corporation, 106.2.0.21]
	[C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll]  [Symantec Corporation, 106.2.0.21]
	[C:\Program Files\Common Files\Symantec Shared\ccSvc.dll]  [Symantec Corporation, 106.2.0.21]
	[C:\Program Files\Common Files\Symantec Shared\ccSet.dll]  [Symantec Corporation, 106.2.0.21]
	[C:\PROGRA~1\COMMON~1\SYMANT~1\CCSETPLG.DLL]  [Symantec Corporation, 106.2.0.21]
	[C:\PROGRA~1\NORTON~2\AVPSVC32.DLL]  [Symantec Corporation, 14.0.0.89]
	[C:\PROGRA~1\NORTON~2\AVPSVC32.loc]  [Symantec Corporation, 14.0.0.89]
	[C:\Program Files\Norton AntiVirus\AVSubmit.dll]  [Symantec Corporation, 14.0.0.89]
	[C:\Program Files\Norton AntiVirus\AVSubmit.loc]  [Symantec Corporation, 14.0.0.89]
	[C:\PROGRA~1\NORTON~2\ISDATASV.DLL]  [Symantec Corporation, 10.0.0.247]
	[C:\PROGRA~1\COMMON~1\SYMANT~1\NPC\NPCWMIMN.DLL]  [Symantec Corporation, 2007.3.00.5]
	[C:\PROGRA~1\COMMON~1\SYMANT~1\SNDSVC.DLL]  [Symantec Corporation, 7.0.0.170]
	[C:\Program Files\Common Files\Symantec Shared\ccL60.dll]  [Symantec Corporation, 106.2.0.21]
	[C:\PROGRA~1\COMMON~1\SYMANT~1\SUBMIS~1\SUBENG.DLL]  [Symantec Corporation, 2.0.0.164]
	[C:\PROGRA~1\COMMON~1\SYMANT~1\SUBMIS~1\SUBRES.loc]  [Symantec Corporation, 2.0.0.164]
	[C:\PROGRA~1\COMMON~1\SYMANT~1\SPBBC\TPROCPLG.DLL]  [Symantec Corporation, 3.0.1.10]
	[C:\PROGRA~1\COMMON~1\SYMANT~1\CCEVTPLG.DLL]  [Symantec Corporation, 106.2.0.21]
	[C:\PROGRA~1\COMMON~1\SYMANT~1\PIF\{B8E1D~1\PIFENG.DLL]  [Symantec Corporation, 1.2.0.18]
	[C:\Program Files\Common Files\Symantec Shared\ccEvtCli.dll]  [Symantec Corporation, 106.2.0.21]
	[C:\PROGRA~1\COMMON~1\SYMANT~1\FIREWALL\FWAGENT.DLL]  [Symantec Corporation, 2.0.1.1]
	[C:\PROGRA~1\COMMON~1\SYMANT~1\SPBBC\SPBBCEVT.DLL]  [Symantec Corporation, 3.3.2.3]
	[C:\PROGRA~1\COMMON~1\SYMANT~1\SRTSP\SRTSP32.DLL]  [Symantec Corporation, 10.1.5.4]
	[C:\Program Files\Common Files\Symantec Shared\ccProSub.dll]  [Symantec Corporation, 106.2.0.21]
	[C:\PROGRA~1\COMMON~1\SYMANT~1\CCSETEVT.DLL]  [Symantec Corporation, 106.2.0.21]
	[C:\WINDOWS\system32\ATL71.DLL]  [Microsoft Corporation, 7.10.3077.0]
	[C:\PROGRA~1\NORTON~2\NAVEVENT.DLL]  [Symantec Corporation, 14.0.0.89]
	[C:\WINDOWS\SYSTEM32\SYMNETI.DLL]  [Symantec Corporation, 7.0.0.170]
	[C:\Program Files\Common Files\Symantec Shared\Firewall\FWHelper.dll]  [Symantec Corporation, 2.0.1.1]
	[C:\Program Files\Norton AntiVirus\isDataCl.dll]  [Symantec Corporation, 10.0.0.247]
	[C:\Program Files\Common Files\Symantec Shared\AntiVirus\AVIfc.dll]  [Symantec Corporation, 1.0.00.194]
	[C:\Program Files\Common Files\Symantec Shared\AppCore\AppMgr32.dll]  [Symantec Corporation, 1.0.00.101]
	[C:\Program Files\Norton AntiVirus\SetEvtHp.dll]  [Symantec Corporation, 10.0.0.247]
	[C:\Program Files\Norton AntiVirus\fwPlugin.dll]  [Symantec Corporation, 10.0.0.247]
	[C:\Program Files\Norton AntiVirus\fwEvent.dll]  [Symantec Corporation, 10.0.0.247]
	[C:\PROGRA~1\COMMON~1\SYMANT~1\OPC\{31011~1\CLTNETCN.DLL]  [Symantec Corporation, 7.1.0.140]
	[C:\Program Files\Norton AntiVirus\IMCfg.dll]  [Symantec Corporation, 10.0.0.247]
	[C:\Program Files\Common Files\Symantec Shared\NPC\npcWmiDt.dll]  [Symantec Corporation, 2007.3.00.5]
	[C:\PROGRA~1\COMMON~1\SYMANT~1\PIF\{B8E1D~1\PollMgr.dll]  [Symantec Corporation, 1.2.0.18]
[PID: 1504 / SYSTEM][C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe]  [Symantec Corporation, 1.0.00.101]
	[C:\WINDOWS\system32\ATL71.DLL]  [Microsoft Corporation, 7.10.3077.0]
	[C:\WINDOWS\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
	[C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
	[C:\Program Files\Common Files\Symantec Shared\ccL60U.dll]  [Symantec Corporation, 106.2.0.21]
	[C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll]  [Symantec Corporation, 106.2.0.21]
	[C:\Program Files\Common Files\Symantec Shared\AppCore\AppMgr32.dll]  [Symantec Corporation, 1.0.00.101]
	[C:\Program Files\Common Files\Symantec Shared\AppCore\AppSet32.dll]  [Symantec Corporation, 1.0.00.101]
	[C:\Program Files\Common Files\Symantec Shared\ccSvc.dll]  [Symantec Corporation, 106.2.0.21]
	[C:\Program Files\Common Files\Symantec Shared\AntiVirus\AVScan.dll]  [Symantec Corporation, 1.0.00.194]
	[C:\Program Files\Common Files\Symantec Shared\AntiVirus\AV.loc]  [Symantec Corporation, 1.0.00.194]
	[C:\Program Files\Common Files\Symantec Shared\AntiVirus\avDefMgr.dll]  [Symantec Corporation, 1.0.00.194]
	[C:\Program Files\Common Files\Symantec Shared\DefUtDCD.dll]  [Symantec Corporation, 3.2.10.0]
	[C:\Program Files\Common Files\Symantec Shared\AntiVirus\avModule.dll]  [Symantec Corporation, 1.0.00.194]
	[C:\Program Files\Common Files\Symantec Shared\QBackup.dll]  [Symantec Corporation, 1.0.00.194]
	[C:\Program Files\Common Files\Symantec Shared\AntiVirus\AVExclu.dll]  [Symantec Corporation, 1.0.00.194]
	[C:\Program Files\Common Files\Symantec Shared\SRTSP\Srtsp32.dll]  [Symantec Corporation, 10.1.5.4]
	[C:\Program Files\Common Files\Symantec Shared\ccProSub.dll]  [Symantec Corporation, 106.2.0.21]
	[C:\PROGRA~1\COMMON~1\SYMANT~1\ccEvtCli.dll]  [Symantec Corporation, 106.2.0.21]
	[C:\Program Files\Common Files\Symantec Shared\ccScanw.dll]  [Symantec Corporation, 106.2.0.21]
	[C:\Program Files\Common Files\Symantec Shared\ecmldr32.DLL]  [Symantec Corporation, 61.3.0.17]
	[C:\Program Files\Common Files\Symantec Shared\MSL\msl.dll]  [Symantec Corporation, 5.0.071.000]
[PID: 1792 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
	[C:\WINDOWS\system32\EBPMON24.DLL]  [SEIKO EPSON CORPORATION, 1, 9, 0, 0]
	[C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_DU18LE.DLL]  [SEIKO EPSON Corporation, 0. 3. 0, 87]
	[C:\WINDOWS\system32\ECBTEG.DLL]  [SEIKO EPSON CORPORATION, 2, 0, 0, 27]
	[C:\WINDOWS\system32\EBPCHP.DLL]  [SEIKO EPSON CORPORATION, 1, 1, 0, 0]
	[C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_DMAI16.DLL]  [SEIKO EPSON Corporation, 0. 3. 3. 10]
[PID: 456 / SYSTEM][C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe]  [Symantec Corporation, 3.1.0.99]
	[C:\Program Files\Symantec\LiveUpdate\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
	[C:\Program Files\Symantec\LiveUpdate\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
	[C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll]  [Symantec Corporation, 106.2.0.21]
	[C:\Program Files\Common Files\Symantec Shared\ccL60U.dll]  [Symantec Corporation, 106.2.0.21]
[PID: 536 / SYSTEM][C:\WINDOWS\system32\drivers\KodakCCS.exe]  [Eastman Kodak Company, 1.1.5000.0]
[PID: 624 / SYSTEM][C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE]  [Symantec Corporation, 19.0.1.8]
	[C:\PROGRA~1\NORTON~1\NORTON~1\NUMISC.dll]  [Symantec Corporation, 19.0.1.8]
	[C:\PROGRA~1\NORTON~1\NORTON~1\S32KRNLL.DLL]  [Symantec Corporation, 20.0.0.181]
	[C:\PROGRA~1\NORTON~1\NORTON~1\S32UTILL.DLL]  [Symantec Corporation, 20.0.0.181]
	[C:\Program Files\Norton SystemWorks\Norton Utilities\NPComSvr.DLL]  [Symantec Corporation, 19.0.1.8]
[PID: 672 / SYSTEM][C:\WINDOWS\System32\nvsvc32.exe]  [NVIDIA Corporation, 6.14.10.5216]
[PID: 992 / SYSTEM][C:\WINDOWS\System32\ScsiAccess.EXE]  [N/A, ]
[PID: 1160 / SYSTEM][C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE]  [Symantec Corporation, 7.00.0.24]
	[C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\SDException.dll]  [Symantec Corporation, 7.00.0.24]
	[C:\Program Files\Norton SystemWorks\Norton Utilities\Speed Disk\SDOptions.dll]  [Symantec Corporation, 7.00.0.24]
[PID: 1204 / SYSTEM][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
	[C:\WINDOWS\System32\escwiad.dll]  [SEIKO EPSON CORP., 1.05]
[PID: 1996 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 4044 / Dave W][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
	[C:\Program Files\iTunes\iTunesMiniPlayer.dll]  [Apple Inc., 7.1.1.5]
	[C:\Program Files\iTunes\iTunesMiniPlayer.Resources\en.lproj\iTunesMiniPlayerLocalized.dll]  [Apple Inc., 7.1.1.5]
	[C:\Program Files\iTunes\iTunesMiniPlayer.Resources\iTunesMiniPlayer.dll]  [Apple Inc., 7.1.1.5]
	[C:\Program Files\Logitech\SetPoint\lgscroll.dll]  [Logitech Inc., 3.0.101]
	[C:\DOCUME~1\DAVEW~1\LOCALS~1\Temp\IadHide5.dll]  [BackWeb, Version 7.2.0 (Build 137R)]
	[C:\Program Files\Common Files\Symantec Shared\NPC\NSCEXT.dll]  [Symantec Corporation, 2007.3.00.5]
	[C:\WINDOWS\system32\ATL71.DLL]  [Microsoft Corporation, 7.10.3077.0]
	[C:\WINDOWS\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
	[C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
	[C:\Program Files\Common Files\Symantec Shared\ccL60U.dll]  [Symantec Corporation, 106.2.0.21]
	[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll]  [Adobe Systems Incorporated, 7.0.9.2006121800]
	[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll]  [Adobe Systems, Inc., 7.0.0.0]
[PID: 2180 / Dave W][C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe]  [Cyberlink Corp., 5.00.0000]
	[C:\Program Files\CyberLink\Shared Files\CLRCEngine2.dll]  [CyberLink Corp., 3.20.0000]
	[C:\Program Files\Logitech\SetPoint\lgscroll.dll]  [Logitech Inc., 3.0.101]
[PID: 2200 / Dave W][C:\Program Files\Common Files\Real\Update_OB\realsched.exe]  [RealNetworks, Inc., 0.1.0.3760]
	[C:\Program Files\Logitech\SetPoint\lgscroll.dll]  [Logitech Inc., 3.0.101]
[PID: 1760 / Dave W][C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe]  [Logitech Inc., 1.0.0.1341]
	[C:\Program Files\Logitech\SetPoint\lgscroll.dll]  [Logitech Inc., 3.0.101]
	[C:\Program Files\Common Files\Logitech\LComMgr\LVMaEnum.dll]  [Logitech Inc., 10.0.0.1375]
	[C:\Program Files\Common Files\Logitech\LComMgr\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
	[C:\Program Files\Common Files\Logitech\LComMgr\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
	[C:\Program Files\Common Files\Logitech\LComMgr\LVComCX.dll]  [Logitech Inc., 10.0.0.1375]
	[C:\Program Files\Common Files\Logitech\LComMgr\AolPlugin.dll]  [Logitech Inc., 1.0.0.1341]
	[C:\Program Files\Common Files\Logitech\LComMgr\YahooPlugin.dll]  [Logitech Inc., 1.0.0.1341]
[PID: 2236 / Dave W][C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe]  [Logitech Inc., 10.0.0.1375]
	[C:\Program Files\Common Files\Logitech\LComMgr\LVMaEnum.dll]  [Logitech Inc., 10.0.0.1375]
	[C:\Program Files\Common Files\Logitech\LComMgr\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
	[C:\Program Files\Common Files\Logitech\LComMgr\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
	[C:\Program Files\Logitech\SetPoint\lgscroll.dll]  [Logitech Inc., 3.0.101]
	[C:\Program Files\Common Files\Logitech\LComMgr\LVComCX.dll]  [Logitech Inc., 10.0.0.1375]
[PID: 2244 / Dave W][C:\Program Files\QuickTime\qttask.exe]  [Apple Computer, Inc., 7.1.5]
	[C:\Program Files\Logitech\SetPoint\lgscroll.dll]  [Logitech Inc., 3.0.101]
[PID: 2256 / Dave W][C:\Program Files\iTunes\iTunesHelper.exe]  [Apple Inc., 7.1.1.5]
	[C:\Program Files\iTunes\iTunesHelper.Resources\en.lproj\iTunesHelperLocalized.DLL]  [Apple Inc., 7.1.1.5]
	[C:\Program Files\iTunes\iTunesHelper.Resources\iTunesHelper.DLL]  [Apple Inc., 7.1.1.5]
	[C:\Program Files\Logitech\SetPoint\lgscroll.dll]  [Logitech Inc., 3.0.101]
[PID: 2280 / Dave W][C:\Program Files\Common Files\Symantec Shared\ccApp.exe]  [Symantec Corporation, 106.2.0.21]
	[C:\WINDOWS\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
	[C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
	[C:\Program Files\Common Files\Symantec Shared\ccL60U.dll]  [Symantec Corporation, 106.2.0.21]
	[C:\WINDOWS\system32\SymNeti.dll]  [Symantec Corporation, 7.0.0.170]
	[C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll]  [Symantec Corporation, 106.2.0.21]
	[C:\Program Files\Common Files\Symantec Shared\ccSet.dll]  [Symantec Corporation, 106.2.0.21]
	[C:\Program Files\Common Files\Symantec Shared\ccSvc.dll]  [Symantec Corporation, 106.2.0.21]
	[C:\Program Files\Common Files\Symantec Shared\AppCore\AppPlg32.dll]  [Symantec Corporation, 1.0.00.101]
	[C:\Program Files\Common Files\Symantec Shared\AppCore\AppMgr32.dll]  [Symantec Corporation, 1.0.00.101]
	[C:\WINDOWS\system32\ATL71.DLL]  [Microsoft Corporation, 7.10.3077.0]
	[C:\Program Files\Common Files\Symantec Shared\AppCore\AppSet32.dll]  [Symantec Corporation, 1.0.00.101]
	[C:\PROGRA~1\COMMON~1\SYMANT~1\CCALERT.DLL]  [Symantec Corporation, 106.2.0.21]
	[C:\PROGRA~1\COMMON~1\SYMANT~1\CCEMLPXY.DLL]  [Symantec Corporation, 106.2.0.21]
	[C:\Program Files\Norton AntiVirus\fwAlert.dll]  [Symantec Corporation, 10.0.0.247]
	[C:\Program Files\Norton AntiVirus\fwAlRes.dll]  [Symantec Corporation, 10.0.0.247]
	[C:\PROGRA~1\NORTON~2\DEFALERT.DLL]  [Symantec Corporation, 14.0.0.89]
	[C:\PROGRA~1\NORTON~2\AVPAPP32.DLL]  [Symantec Corporation, 14.0.0.89]
	[C:\Program Files\Common Files\Symantec Shared\NPC\npcTRAY.dll]  [Symantec Corporation, 2007.3.00.5]
	[C:\PROGRA~1\NORTON~1\NSWALERT.DLL]  [Symantec Corporation, 2007.10.109]
	[C:\Program Files\Common Files\Symantec Shared\CF\PEP2.dll]  [Symantec Corporation, 2006.1.00.58]
	[C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll]  [Symantec Corporation, 1.2.0.18]
	[C:\Program Files\Common Files\Symantec Shared\COH\sesHlp.dll]  [Symantec Corporation, 6,1,1,18]
	[C:\Program Files\Common Files\Symantec Shared\ccSetEvt.dll]  [Symantec Corporation, 106.2.0.21]
	[C:\PROGRA~1\NORTON~1\AlertRes.dll]  [Symantec Corporation, 2007.10.109]
	[C:\Program Files\Common Files\Symantec Shared\ccProSub.dll]  [Symantec Corporation, 106.2.0.21]
	[C:\PROGRA~1\NORTON~2\AVPAPP32.loc]  [Symantec Corporation, 14.0.0.89]
	[C:\PROGRA~1\COMMON~1\SYMANT~1\ccEvtCli.dll]  [Symantec Corporation, 106.2.0.21]
	[C:\Program Files\Common Files\Symantec Shared\AntiVirus\AVIfc.dll]  [Symantec Corporation, 1.0.00.194]
	[C:\Program Files\Common Files\Symantec Shared\NPC\DataPvdr.dll]  [Symantec Corporation, 2007.3.00.5]
	[C:\Program Files\Common Files\Symantec Shared\NPC\NSCHlpr2.dll]  [Symantec Corporation, 2007.3.00.5]
	[C:\Program Files\Norton AntiVirus\isDataCl.dll]  [Symantec Corporation, 10.0.0.247]
	[C:\Program Files\Norton AntiVirus\fwEvent.dll]  [Symantec Corporation, 10.0.0.247]
	[C:\Program Files\Norton SystemWorks\SWDataCl.dll]  [Symantec Corporation, 2007.10.109]
	[C:\Program Files\Norton AntiVirus\SetEvtHp.dll]  [Symantec Corporation, 10.0.0.247]
	[C:\PROGRA~1\COMMON~1\SYMANT~1\rcEmlPxy.dll]  [Symantec Corporation, 106.1.2.2]
	[C:\WINDOWS\system32\SymRedir.dll]  [Symantec Corporation, 7.0.0.170]
	[C:\Program Files\Common Files\Symantec Shared\NPC\pcStatus.dll]  [Symantec Corporation, 2007.3.00.5]
	[C:\Program Files\Logitech\SetPoint\lgscroll.dll]  [Logitech Inc., 3.0.101]
	[C:\Program Files\Common Files\Symantec Shared\NPC\uiLicPlg.dll]  [Symantec Corporation, 2007.3.00.5]
	[C:\Program Files\Common Files\Symantec Shared\NPC\NSCWSCR2.DLL]  [Symantec Corporation, 2007.3.00.5]
	[C:\Program Files\Common Files\Symantec Shared\NPC\npcWmiCl.dll]  [Symantec Corporation, 2007.3.00.5]
	[C:\Program Files\Common Files\Symantec Shared\NPC\npcWmiDt.dll]  [Symantec Corporation, 2007.3.00.5]
	[C:\Program Files\Common Files\Symantec Shared\AntiVirus\AVMail.dll]  [Symantec Corporation, 1.0.00.194]
	[C:\Program Files\Common Files\Symantec Shared\AntiVirus\AVExclu.dll]  [Symantec Corporation, 1.0.00.194]
	[C:\Program Files\Norton AntiVirus\IMCfg.dll]  [Symantec Corporation, 10.0.0.247]
	[C:\Program Files\Common Files\Symantec Shared\NPC\PEPEvnt.dll]  [Symantec Corporation, 2007.3.00.5]
	[C:\Program Files\Common Files\Symantec Shared\NPC\NSCEXT.dll]  [Symantec Corporation, 2007.3.00.5]
	[C:\Program Files\Common Files\Symantec Shared\CF\cfV2Pack.dll]  [Symantec Corporation, 2006.1.00.58]
	[C:\Program Files\Common Files\Symantec Shared\CF\cfEPack.dll]  [Symantec Corporation, 2006.1.00.58]
[PID: 1200 / Dave W][C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe]  [Sun Microsystems, Inc., 6.0.10.6]
	[C:\Program Files\Java\jre1.6.0_01\bin\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
[PID: 4020 / Dave W][C:\Program Files\Messenger\msmsgs.exe]  [Microsoft Corporation, 4.7.3001]
	[C:\Program Files\Logitech\SetPoint\lgscroll.dll]  [Logitech Inc., 3.0.101]
	[C:\DOCUME~1\DAVEW~1\LOCALS~1\Temp\IadHide5.dll]  [BackWeb, Version 7.2.0 (Build 137R)]
	[C:\WINDOWS\System32\quartz.dll]  [, ]
	[C:\WINDOWS\System32\devenum.dll]  [, ]
	[C:\WINDOWS\system32\msdmo.dll]  [, ]
[PID: 2092 / Dave W][C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe]  [Google Inc., 2, 0, 301, 1654]
	[C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\gtn.dll]  [Google Inc., 2, 0, 301, 7164]
	[C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\res_en.dll]  [Google Inc., 2, 0, 301, 7164]
	[C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll]  [Google Inc., 2, 0, 301, 7164]
	[C:\DOCUME~1\DAVEW~1\LOCALS~1\Temp\IadHide5.dll]  [BackWeb, Version 7.2.0 (Build 137R)]
	[C:\Program Files\Logitech\SetPoint\lgscroll.dll]  [Logitech Inc., 3.0.101]
[PID: 2096 / Dave W][C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe]  [Logitech, 2.1.2.0]
	[C:\Program Files\Logitech\Desktop Messenger\8876480\7.2.0.137-8876480SL\Program\backWeb.dll]  [BackWeb Technologies Inc., Version 7.2.0 (Build 137R)]
	[C:\Program Files\Logitech\Desktop Messenger\8876480\7.2.0.137-8876480SL\Program\bwsec.dll]  [BackWeb, Version 4.2.0 (Build 137R)]
	[C:\Program Files\Logitech\Desktop Messenger\8876480\7.2.0.137-8876480SL\Program\clntutil.dll]  [N/A, ]
	[C:\PROGRA~1\Logitech\DESKTO~1\8876480\720~1.137\program\EN\ClientRC.dll]  [BackWeb Technologies Inc., Version 7.2.0 (Build 137R)]
	[C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWfiles-8876480.dll]  [BackWeb Technologies Inc.						 , Version 7.2.0 (Build 137R)]
	[C:\Program Files\Logitech\Desktop Messenger\8876480\7.2.0.137-8876480SL\Program\BWfiles.dll]  [, Version 7.2.0 (Build 137R)]
	[C:\Program Files\Logitech\SetPoint\lgscroll.dll]  [Logitech Inc., 3.0.101]
	[C:\DOCUME~1\DAVEW~1\LOCALS~1\Temp\IadHide5.dll]  [BackWeb, Version 7.2.0 (Build 137R)]
	[C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWDocMapExt-8876480.dll]  [BackWeb Technologies Inc.						 , Version 7.2.0 (Build 137R)]
	[C:\Program Files\Logitech\Desktop Messenger\8876480\7.2.0.137-8876480SL\Program\BWDocMapExt.dll]  [, Version 7.2.0 (Build 137R)]
	[C:\Program Files\Logitech\Desktop Messenger\8876480\Program\bwscriptext-8876480.dll]  [BackWeb Technologies Inc.						 , Version 7.2.0 (Build 137R)]
	[C:\Program Files\Logitech\Desktop Messenger\8876480\7.2.0.137-8876480SL\Program\bwscriptext.dll]  [, Version 7.2.0 (Build 137R)]
	[C:\Program Files\Logitech\Desktop Messenger\8876480\Program\SyncExt.dll]  [Logitech, 2.01.02]
	[C:\Program Files\Common Files\Symantec Shared\NPC\NSCEXT.dll]  [Symantec Corporation, 2007.3.00.5]
	[C:\WINDOWS\system32\ATL71.DLL]  [Microsoft Corporation, 7.10.3077.0]
	[C:\WINDOWS\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
	[C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
	[C:\Program Files\Common Files\Symantec Shared\ccL60U.dll]  [Symantec Corporation, 106.2.0.21]
[PID: 1124 / Dave W][C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2L1.EXE]  [SEIKO EPSON CORPORATION, 3.00]
	[C:\Program Files\Logitech\SetPoint\lgscroll.dll]  [Logitech Inc., 3.0.101]
[PID: 2148 / Dave W][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
	[C:\Program Files\Logitech\SetPoint\lgscroll.dll]  [Logitech Inc., 3.0.101]
[PID: 2420 / Dave W][C:\Program Files\Logitech\SetPoint\SetPoint.exe]  [Logitech Inc., 3.0.101]
	[C:\WINDOWS\system32\KemUtil.dll]  [Logitech Inc., 3.0.101]
	[C:\Program Files\Logitech\SetPoint\SetPointCOM.dll]  [Logitech Inc., 3.0.101]
	[C:\WINDOWS\system32\kemutb.dll]  [Logitech Inc., 3.0.101]
	[C:\WINDOWS\system32\KemWnd.dll]  [Logitech Inc., 3.0.101]
	[C:\WINDOWS\system32\KemXML.dll]  [Logitech Inc., 3.0.101]
	[C:\Program Files\Logitech\SetPoint\lgscroll.dll]  [Logitech Inc., 3.0.101]
	[C:\Program Files\Logitech\SetPoint\Macros\MacroCore.dll]  [Logitech Inc., 3.0.90]
	[C:\Program Files\Logitech\SetPoint\IMHook.dll]  [Logitech Inc., 3.0.101]
	[C:\Program Files\Common Files\Logitech\KhalShared\KhalApi.dll]  [Logitech Inc., 3.0.101]
	[C:\Program Files\Logitech\SetPoint\kgame.dll]  [Logitech Inc., 3.0.101]
	[C:\Program Files\Logitech\SetPoint\GameHook.dll]  [Logitech Inc., 3.0.101]
	[C:\Program Files\Logitech\SetPoint\LCabHandler.dll]  [Logitech Inc., 3.0.101]
	[C:\Program Files\Logitech\SetPoint\Macros\MacroEmail.dll]  [Logitech Inc., 3.0.101]
	[C:\Program Files\Logitech\SetPoint\KEMHook.dll]  [Logitech Inc., 3.0.101]
	[C:\Program Files\Logitech\SetPoint\Macros\MacroMedia.dll]  [Logitech Inc., 3.0.101]
	[C:\DOCUME~1\DAVEW~1\LOCALS~1\Temp\IadHide5.dll]  [BackWeb, Version 7.2.0 (Build 137R)]
[PID: 2444 / Dave W][C:\Program Files\NBC4 LIVE ONLINE\liveonline_2536771.exe]  [N/A, ]
	[C:\Program Files\Logitech\SetPoint\lgscroll.dll]  [Logitech Inc., 3.0.101]
[PID: 2472 / Dave W][C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE]  [Logitech Inc., 3.0.74]
	[C:\Program Files\Common Files\Logitech\KhalShared\KHALAPI.DLL]  [Logitech Inc., 3.0.101]
	[C:\Program Files\Logitech\SetPoint\lgscroll.dll]  [Logitech Inc., 3.0.101]
	[C:\Program Files\Common Files\Logitech\KhalShared\KHALITCH.DLL]  [Logitech Inc., 3.0.101]
	[C:\Program Files\Common Files\Logitech\KhalShared\KHALMW.DLL]  [Logitech Inc., 3.0.101]
	[C:\Program Files\Common Files\Logitech\KhalShared\KHALHPP.DLL]  [Logitech Inc., 3.0.101]
[PID: 2308 / SYSTEM][C:\Program Files\iPod\bin\iPodService.exe]  [Apple Inc., 7.1.1.5]
	[C:\Program Files\iPod\bin\iPodService.Resources\en.lproj\iPodServiceLocalized.DLL]  [Apple Inc., 7.1.1.5]
	[C:\Program Files\iPod\bin\iPodService.Resources\iPodService.DLL]  [Apple Inc., 7.1.1.5]
[PID: 3240 / SYSTEM][C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe]  [Symantec Corporation, 1.9.1.1080]
	[C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcnet.dll]  [Symantec Corporation, 1.9.1.1080]
	[C:\WINDOWS\system32\MSVCR71.DLL]  [Microsoft Corporation, 7.10.3052.4]
[PID: 3576 / Dave W][C:\Program Files\Mozilla Firefox\firefox.exe]  [Mozilla Corporation, 1.8.0.12: 2007050813]
	[C:\Program Files\Mozilla Firefox\js3250.dll]  [Netscape Communications Corporation, 4.0]
	[C:\Program Files\Mozilla Firefox\nspr4.dll]  [Netscape Communications Corporation, 4.6.7]
	[C:\Program Files\Mozilla Firefox\xpcom_core.dll]  [Mozilla Foundation, 1.8.0.12: 2007050813]
	[C:\Program Files\Mozilla Firefox\plc4.dll]  [Netscape Communications Corporation, 4.6.7]
	[C:\Program Files\Mozilla Firefox\plds4.dll]  [Netscape Communications Corporation, 4.6.7]
	[C:\Program Files\Mozilla Firefox\smime3.dll]  [Mozilla Foundation, 3.11.5]
	[C:\Program Files\Mozilla Firefox\nss3.dll]  [Mozilla Foundation, 3.11.5]
	[C:\Program Files\Mozilla Firefox\softokn3.dll]  [Mozilla Foundation, 3.11.4]
	[C:\Program Files\Mozilla Firefox\ssl3.dll]  [Mozilla Foundation, 3.11.5]
	[C:\Program Files\Mozilla Firefox\xpcom_compat.dll]  [Mozilla Foundation, 1.8.0.12: 2007050813]
	[C:\Program Files\Common Files\Symantec Shared\NPC\NSCEXT.dll]  [Symantec Corporation, 2007.3.00.5]
	[C:\WINDOWS\system32\ATL71.DLL]  [Microsoft Corporation, 7.10.3077.0]
	[C:\WINDOWS\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
	[C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
	[C:\Program Files\Common Files\Symantec Shared\ccL60U.dll]  [Symantec Corporation, 106.2.0.21]
	[C:\DOCUME~1\DAVEW~1\LOCALS~1\Temp\IadHide5.dll]  [BackWeb, Version 7.2.0 (Build 137R)]
	[C:\Program Files\Logitech\SetPoint\lgscroll.dll]  [Logitech Inc., 3.0.101]
	[C:\Program Files\Mozilla Firefox\components\jar50.dll]  [Mozilla Foundation, 1.8.0.12: 2007050813]
	[C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_DU18LE.DLL]  [SEIKO EPSON Corporation, 0. 3. 0, 87]
	[C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_DMAI16.DLL]  [SEIKO EPSON Corporation, 0. 3. 3. 10]
	[C:\Program Files\Mozilla Firefox\freebl3.dll]  [Mozilla Foundation, 3.11.4]
	[C:\Program Files\Mozilla Firefox\nssckbi.dll]  [Mozilla Foundation, 1.62]
[PID: 3784 / SYSTEM][C:\WINDOWS\System32\wbem\wmiprvse.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 3772 / Dave W][C:\Documents and Settings\Dave W\Desktop\SREngPS.EXE]  [Smallfrogs Studio, 2.5.16.900]
	[C:\Program Files\Common Files\Symantec Shared\NPC\NSCEXT.dll]  [Symantec Corporation, 2007.3.00.5]
	[C:\WINDOWS\system32\ATL71.DLL]  [Microsoft Corporation, 7.10.3077.0]
	[C:\WINDOWS\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
	[C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
	[C:\Program Files\Common Files\Symantec Shared\ccL60U.dll]  [Symantec Corporation, 106.2.0.21]
	[C:\DOCUME~1\DAVEW~1\LOCALS~1\Temp\IadHide5.dll]  [BackWeb, Version 7.2.0 (Build 137R)]
	[C:\Program Files\Logitech\SetPoint\lgscroll.dll]  [Logitech Inc., 3.0.101]
	[C:\Documents and Settings\Dave W\Desktop\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]

==================================
File Associations
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS   OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock Provider
N/A

==================================
Autorun.Inf
N/A

==================================
HOSTS File
127.0.0.1	   localhost

==================================
Process Privileges Scan
Special Privilege Enabled: SeLoadDriverPrivilege [PID = 2096, C:\PROGRAM FILES\LOGITECH\DESKTOP MESSENGER\8876480\PROGRAM\LOGITECHDESKTOPMESSENGER.EXE]
Special Privilege Enabled: SeLoadDriverPrivilege [PID = 2420, C:\PROGRAM FILES\LOGITECH\SETPOINT\SETPOINT.EXE]
Special Privilege Enabled: SeLoadDriverPrivilege [PID = 3576, C:\PROGRAM FILES\MOZILLA FIREFOX\FIREFOX.EXE]

==================================
API HOOK
N/A

==================================
Hidden Process
N/A

==================================
I must inform you that your system has probably been compromised by a remote trojan that was hiding from all our tools. I came across it while looking for defective drivers that would be the cause of your reboot problem:

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
<%systemroot%\system32\shmgrate.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
<%systemroot%\system32\shmgrate.exe

http://www.liutilities.com/products/wintas…brary/shmgrate/

shmgrate.exe is a process which is registered as a trojan. This Trojan allows attackers to access your computer from remote locations, stealing passwords, Internet banking and personal data. This process is a security risk and should be removed from your system.



On some other sites, they say that it is a legit tool.

We must make sure before we continue.

=========================================================

1. We need to show Hidden files and folders:

To enable the viewing of Hidden files follow these steps:

1. Close all programs so that you are at your desktop.
2. Double-click on the My Computer icon.
3. Select the Tools menu and click Folder Options.
4. After the new window appears select the View tab.
5. Put a checkmark in the checkbox labeled Display the contents of system folders.
6. Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
7. Remove the checkmark from the checkbox labeled Hide file extensions for known file types.
8. Remove the checkmark from the checkbox labeled Hide protected operating system files.
9. Press the Apply button and then the OK button and shutdown My Computer.
10. Now your computer is configured to show all hidden files.


2. Now we must submit the file for analysis:



1. Click HERE to get to Jotti's site.

2. At the top of the Jotti window, use the Browse button to locate the following file on your system:

C:\Windows\system32\shmgrate.exe

3. Once you have located the file, click SUBMIT and the content of the file will be uploaded by the site and analysed.

4. Please provide me with the results of the analysis.


Then, please also submit tit here:

Please go to: VirusTotal
  • On the page you'll find a "Browse" button.
  • Next to the browse button you'll see a box to enter text.
  • Please copy/paste the following in BOLD:

    C:\Windows\system32\shmgrate.exe

  • Then click the "Send File " button just below.
  • This will scan the file. Please be patient.
  • Once scanned, copy and paste the results in your next reply.
Regards,

Trevuren
Hi Trevuren - here is the scan results using Jotti's site:—————————– Service load: 0% 100% File: shmgrate.exe Status: OK(Note: this file has been scanned before. Therefore, this file's scan results will not be stored in the database) MD5: d6c6f5126c671c6c224c4a1a0c72ef7d Packers detected: - Bit9 reports: No threat detected (more info) Scanner results Scan taken on 13 Aug 2007 21:41:30 (GMT) A-Squared Found nothing AntiVir Found nothing ArcaVir Found nothing Avast Found nothing AVG Antivirus Found nothing BitDefender Found nothing ClamAV Found nothing CPsecure Found nothing Dr.Web Found nothing F-Prot Antivirus Found nothing F-Secure Anti-Virus Found nothing Fortinet Found nothing Kaspersky Anti-Virus Found nothing NOD32 Found nothing Norman Virus Control Found nothing Panda Antivirus Found nothing Rising Antivirus Found nothing Sophos Antivirus Found nothing VirusBuster Found nothing VBA32 Found nothing Here are the results from running VirusTotal—————————— File shmgrate.exe received on 08.13.2007 23:54:36 (CET) Current status: Loading … queued waiting scanning finished NOT FOUND STOPPED Result: 0/32 (0%) Loading server information… Your file is queued in position: 8. Estimated start time is between 81 and 116 seconds. Do not close the window until scan is complete. The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result. If you are waiting for more than five minutes you have to resend your file. Your file is being scanned by VirusTotal in this moment, results will be shown as they're generated. Compact Compact Print results Print results Your file has expired or does not exists. Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time. You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished. Email: Antivirus Version Last Update Result AhnLab-V3 2007.8.9.2 2007.08.13 - AntiVir 7.4.0.60 2007.08.13 - Authentium 4.93.8 2007.08.13 - Avast 4.7.1029.0 2007.08.13 - AVG 7.5.0.476 2007.08.13 - BitDefender 7.2 2007.08.13 - CAT-QuickHeal 9.00 2007.08.13 - ClamAV 0.91 2007.08.13 - DrWeb 4.33 2007.08.13 - eSafe 7.0.15.0 2007.08.10 - eTrust-Vet 31.1.5055 2007.08.13 - Ewido 4.0 2007.08.13 - FileAdvisor 1 2007.08.13 - Fortinet 2.91.0.0 2007.08.13 - F-Prot 4.3.2.48 2007.08.13 - F-Secure 6.70.13030.0 2007.08.13 - Ikarus T3.1.1.12 2007.08.13 - Kaspersky 4.0.2.24 2007.08.13 - McAfee 5096 2007.08.13 - Microsoft 1.2704 2007.08.13 - NOD32v2 2457 2007.08.13 - Norman 5.80.02 2007.08.13 - Panda 9.0.0.4 2007.08.12 - Prevx1 V2 2007.08.13 - Rising 19.36.02.00 2007.08.13 - Sophos 4.20.0 2007.08.12 - Sunbelt 2.2.907.0 2007.08.11 - Symantec 10 2007.08.13 - TheHacker 6.1.8.168 2007.08.13 - VBA32 3.12.2.2 2007.08.13 - VirusBuster 4.3.26:9 2007.08.13 - Webwasher-Gateway 6.0.1 2007.08.13 - Additional information File size: 42496 bytes MD5: d6c6f5126c671c6c224c4a1a0c72ef7d SHA1: c7d598db84d7d726380aab72f93b696378d4f6b8 Regards and Thanks.
That's a relief!!!!

Let's see if we can get back your ability too use Safe Mode. I think this is the last ace up my sleeve. With this method, your SafeBootKey is rebuilt but you lose all customized entries placed by 3rd party programs.


1. Click on the SReng icon to start the program.
2. Choose System Repair
3. Then Advanced Repair followed by Repair Safe Mode
4. Let it run and when it is finished, EXIT the program.
5. Time to see if we can get this baby into Safe Mode.

Good Luck,

Trevuren
Hi Trevuren - alas, I was not successful in accessing Safe Mode after using SReng to Repair Safe Mode. Honestly, I'm not sure I'm doing everything correctly. After I completed your instructions, I restarted my computer. After the BIOS screen, I began tapping F8 key. I get a screen asking me to select "A" drive and three other options, or by clicking enter I can proceed using default. I pick that, because I don't know if I should pick something. When the screen goes black again, I resume tapping F8, and the "Mode" screen appears. I select "Safe Mode" (although there are a couple other options, one of which is another "Safe Mode" with Networking option) When I hit "Enter" for Safe Mode, I get the lines we previously identified as the "funny" lines Nothing happens. The lines remain on the screen. The last time I tried to get to Safe Mode screen, I let the funny lines sit on screen for 20 minutes. Should I wait longer? How imperative is it that I be able to successfully get to Safe Mode? Anyway, I'm not sure if I'm trying to access Safe Mode comletely correct. If my description sounds like I'm doing things correctly, any other thoughts? Thanks for your patience. Regards.
I need to know what those other options are when you are presented with the choice of picking "A" drive. In addition, when you get passed that screen and into the "Mode" screen, what are "all the other options"? Remember, I can not see your screen, you have to describe everything to me IN DETAIL. It may be your BIOS that is not set properly. Please provide me with the info requested and we will proceed from there. Trevuren
Hi Tervuren - I think I may have figured this out. I was able to get into Safe Mode with all my existing desktop icons available, etc. Let me explain. First, so you know what I see when I tap the F8 key after the BIOS screen passes, here is the Pop Up box that appears: Please select boot drive 1st Floppy Drive PM-Maxtor 6L080PO PS-LITE-ON DVDRW SOHW-1693S EPSON Stylus Storage ______________________ [Up Arrow] and [Down Arrow] to move selection ENTER to select boot device ESC to boot using default Before the last time I tried (and successfully got into Safe Mode), I was hitting ESC and when screen went black, I tapped F8 key until "Mode" selection screen came up. Then, when I selected "Safe Mode" and hit ENTER, those funny lines appeared and nothing happened. I believe nothing happened because the default was set on A: drive Here's how I got into "Safe Mode" the last time I tried. After BIOS screen passed, I tapped F8 button until previously described pop-up screen appeared. I then moved the selection down to "PM-MAXTOR 6LO80PO", which I finally realized was my hard drive I then hit ENTER and when the screen went black, I again tapped F8 key and the "Mode" screen came up Then, when I selected Safe Mode and hit ENTER, the funny lines appeared but about 5-10 seconds later, it disappeared and the Safe Mode sequence followed and I ended up in Safe Mode with Windows XP open. YEA! Now What??? lol Regards.
Congratulations, your log looksCLEAN

There are a few things you must do once you are completely clean:

1. Re-hide your System Files and Folders to prevent any future accidents.

Reconfigure Windows XP to hide hidden files:
  • Click Start. Open My Computer.
  • Select the Tools menu and click Folder Options. Select the View Tab.
  • Under the Hidden files and folders heading deselect "Show hidden files and folders".
  • Check the "Hide protected operating system files (recommended)" option.
  • Click Yes to confirm. Click OK.

2. Time for some housekeeping

Please download the OTMoveIt by OldTimer
  • Save it to your desktop.
  • Run the tool by clicking on the icon.
  • Click the Cleanup button.
  • The tools that we used as well as this one will be removed from your system.

3. Now Set a New Restore Point to prevent possible reinfection from an old one. Some of the malware you picked up could have been saved in System Restore. Since System Restore is a protected directory, your tools can not access it to delete these bad files which sometimes can reinfect your system. Setting a new restore point AFTER cleaning your system will help prevent this and enable your computer to "roll-back" to a clean working state.

The easiest and safest way to do this is:
  • Go to Start > Programs > Accessories > System Tools and click "System Restore".
  • Choose the radio button marked "Create a Restore Point" on the first screen then click "Next". Give the R.P. a name then click "Create". The new point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
  • Then go to Start > Run and type: Cleanmgr
  • Click "OK".
  • Click the "More Options" Tab.
  • Click "Clean Up" in the System Restore section to remove all previous restore points except the newly created one.
Here are some tips to reduce the potential for spyware infection in the future:

Make sure you keep your Windows OS current by visiting Windows update
regularly to download and install any critical updates and service packs. With out these you are leaving the backdoor open.

I strongly recommend installing the following applications:
  • Spywareblaster <= SpywareBlaster will prevent spyware from being installed.
  • Spywareguard <= SpywareGuard offers realtime protection from spyware installation attempts.
  • How to use Ad-Aware to remove Spyware <= If you suspect that you have spyware installed on your computer, here are instructions on how to download, install and then use Ad-Aware.
  • How to use Spybot to remove Spyware <= If you suspect that you have spyware installed on your computer, here are instructions on how to download, install and then use Spybot. Similar to Ad-Aware, I strongly recommend both to catch most spyware.
To protect yourself further:
  • Spyad <= IE/Spyad places over 4000 websites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (Cookies etc) from the sites listed, although you will still be able to connect to the sites.
  • MVPS Hosts file <= The MVPS Hosts file replaces your current HOSTS file with one containing well know ad sites etc. Basically, this prevents your coputer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer
  • Google Toolbar <= Get the free google toolbar to help stop pop up windows.
And also see TonyKlein's good advice
So how did I get infected in the first place?

Regards,

Trevuren
Hi Trevuren - I have successfully done all your recommendations in last message (except loading the final 3 "To protect yourself further:" entries (I'll do those too, but later). Am I done? Thanks for all the recommendations for making my puter more secure. Regards.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance.

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI