This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Another VirusWebProtect Victim

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My XP computer was just hit by the VirusWebProtect malware which has disabled task manager, file manager, and other items that could be used to remove it from the system. The OS is basically useless in normal mode. I would appreciate any help. I'm not sure if it makes sense to follow what had been posted for others since every instance seems to be a little different. Any help would be appreciated. Thank you ! I ran HiJackThis from SAFE mode, and here is the output. It seems pretty clear that some registry keys may need to be reset. Begin HiJackThis Log: ——————————————————————————————————————— Logfile of HijackThis v1.99.1 Scan saved at 2:36:55 AM, on 6/30/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: O:\WINDOWS\System32\smss.exe O:\WINDOWS\system32\csrss.exe O:\WINDOWS\system32\winlogon.exe O:\WINDOWS\system32\services.exe O:\WINDOWS\system32\lsass.exe O:\WINDOWS\system32\svchost.exe O:\WINDOWS\system32\svchost.exe O:\WINDOWS\system32\svchost.exe D:\Program Files\Utilities\hijackthis\HijackThis.exe O:\WINDOWS\explorer.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - Default URLSearchHook is missing O2 - BHO: Flash Module - {0245D364-5F52-44ac-B6EB-7BAD6E3D7EF2} - btasv.dll (file missing) O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - O:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: QXK Olive - {1B18E700-33B1-4960-A9F0-A16A4C7290BF} - O:\WINDOWS\gfetqaxssde.dll O2 - BHO: H - {783550EA-6F83-4ddc-AC5E-14D06154B942} - mar12.dll (file missing) O3 - Toolbar: gxvpsafm - {A497D131-ABE9-4267-8C94-8D7FDBCF99AC} - O:\WINDOWS\gxvpsafm.dll O4 - HKLM\..\Run: [MSConfig] O:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE O:\WINDOWS\system32\NvCpl.dll,NvStartup O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - O:\PROGRA~1\MICROS~2\INetRepl.dll O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - O:\PROGRA~1\MICROS~2\INetRepl.dll O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - O:\PROGRA~1\MICROS~2\INetRepl.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - O:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - O:\Program Files\Messenger\msmsgs.exe O10 - Broken Internet access because of LSP provider 'rsvp322.dll' missing O17 - HKLM\System\CCS\Services\Tcpip\..\{05B98D6F-5886-4A9F-B828-0621FA67226E}: NameServer = 85.255.115.4,85.255.112.14 O17 - HKLM\System\CCS\Services\Tcpip\..\{2FB60702-9F83-46F3-A7F4-B6BD66808138}: NameServer = 85.255.115.4,85.255.112.14 O17 - HKLM\System\CCS\Services\Tcpip\..\{49CE07A4-979F-49EC-B6F0-93AE59D659C3}: NameServer = 85.255.115.4,85.255.112.14 O17 - HKLM\System\CCS\Services\Tcpip\..\{E1FFBB1C-BCB6-4292-91DA-03E593F96C40}: NameServer = 85.255.115.4,85.255.112.14 O17 - HKLM\System\CCS\Services\Tcpip\..\{F63B5927-712F-43FD-8E7E-DAC529300393}: NameServer = 85.255.115.4,85.255.112.14 O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.115.4 85.255.112.14 O17 - HKLM\System\CS1\Services\Tcpip\..\{05B98D6F-5886-4A9F-B828-0621FA67226E}: NameServer = 85.255.115.4,85.255.112.14 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.115.4 85.255.112.14 O18 - Protocol: bw+0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw+0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw-0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw-0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw00 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw00s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw10 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw10s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw20 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw20s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw30 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw30s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw40 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw40s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw50 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw50s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw60 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw60s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw70 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw70s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw80 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw80s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw90 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw90s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwa0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwa0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwb0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwb0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwc0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwc0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwd0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwd0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwe0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwe0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwf0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwf0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll O18 - Protocol: bwg0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwg0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwh0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwh0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwi0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwi0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwj0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwj0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwk0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwk0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwl0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwl0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwm0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwm0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwn0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwn0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwo0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwo0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwp0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwp0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwq0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwq0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwr0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwr0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bws0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bws0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwt0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwt0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwu0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwu0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwv0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwv0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bww0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bww0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwx0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwx0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwy0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwy0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwz0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwz0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: offline-8876480 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - O:\WINDOWS\system32\WPDShServiceObj.dll O21 - SSODL: qegbdmwf - {E850F003-99A7-48C1-8DAC-DAA6482E9DD4} - O:\WINDOWS\qegbdmwf.dll O21 - SSODL: pntqkflv - {50FA4DE1-ADB6-454C-8B7B-375EC1445180} - O:\WINDOWS\pntqkflv.dll O23 - Service: ASP.NET State Service aspnet_stateseclogon (aspnet_stateseclogon) - Unknown owner - O:\WINDOWS\system32\12520437v.exe (file missing) O23 - Service: Windows Audio AudioSrvSharedAccess (AudioSrvSharedAccess) - Unknown owner - *&€|û.exe (file missing) O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - O:\WINDOWS\system32\CTsvcCDA.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - O:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: InteractiveLogon InteractiveLogonSysmonLog (InteractiveLogonSysmonLog) - Unknown owner - O:\WINDOWS\system32\1033f.exe (file missing) O23 - Service: Workstation lanmanworkstationcisvc (lanmanworkstationcisvc) - Unknown owner - O:\WINDOWS\system32\activedst.exe (file missing) O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - O:\WINDOWS\system32\nvsvc32.exe O23 - Service: PDEngine - Raxco Software, Inc. - O:\Program Files\Raxco\PerfectDisk\PDEngine.exe O23 - Service: PDScheduler (PDSched) - Raxco Software, Inc. - O:\Program Files\Raxco\PerfectDisk\PDSched.exe O23 - Service: System Restore Service srservice Management Service (srservice Management Service) - Unknown owner - *&€|û.exe (file missing) O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - O:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - O:\WINDOWS\system32\ZoneLabs\vsmon.exe O23 - Service: Windows Management Service - Unknown owner - O:\WINDOWS\system32\.exe (file missing) ——————————————– End of HiJackThis log
Hi

Download and Run FixWarout
Please download FixWareout from one of these sites:
http://downloads.subratam.org/Fixwareout.exe
http://www.bleepingcomputer.com/files/lonny/Fixwareout.exe

Save it to your desktop and run it. Click Next, then Install, then make sure "Run fixit" is checked and click Finish. The fix will begin; follow the prompts. You will be asked to reboot your computer; please do so. Your system may take longer than usual to load; this is normal.

At the end of the fix, you may need to restart your computer again.

Finally, please post the contents of the logfile C:\fixwareout\report.txt

Now lets check some settings on your system.
(2000/XP) Only
In the windows control panel. If you are using Windows XP's Category View, select the Network and Internet Connections category otherwise double click on Network Connections. Then right click on your default connection, usually local area connection for cable and dsl, and left click on properties. Click the Networking tab. Double-click on the Internet Protocol (TCP/IP) item and select the radio dial that says Obtain DNS servers automatically
Press OK twice to get out of the properties screen and reboot if it asks.
That option might not be avaiable on some systems
Next Go start run type cmd and hit OK
type
ipconfig /flushdns
then hit enter, type exit hit enter
(that space between g and / is needed)


If you already have Combofix, please delete this copy and download it again as it's being updated regularly.

Please visit this webpage for download links, and instructions for running the tool:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Use this link to download and save Combofix to your Desktop.
http://download.bleepingcomputer.com/sUBs/+/ComboFix.exe

Please ensure you read this guide carefully and install the Recovery Console first.

The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.

Once Recovery Console is installed, you should see a blue screen prompt like the one below:

[external image: Posted Image]

Click Yes to allow Combofix to continue scanning for malware.

When done, a log will be produced. Please post that log and a new HijackThis log in your next reply.


1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.



In your next reply post:
report.txt
ComboFix.txt
New HijackThis log taken after the above scan has run
Hello Scotty,

Thanks so much for taking my case. Your suggestions have improved my problems greatly! The system appears to be back to normal.

[The only deviation was that I did not setup the recovery console from combofix since I have a multiboot/OS system and did not want to disturb booting of the main disk. I also had to right click on start –> properties –> customize –> advanced to get explorer (My Computer) back so I could run the programs suggested. The malware seemed to regularly clear all the shortcuts on the desktop, except for the three shortcuts that it seems to want to keep there]

As requested, I have three listings, from Wareout, Combofix, and Hijackthis as folllows. Please advise of any further actions.

————————————————————————————————————————

Username "Martin" - 06/30/2008 19:38:30 [Fixwareout edited 9/01/2007]

~~~~~ Prerun check
HKLM\SOFTWARE\~\Winlogon\ "System"="cseno.exe"
Service: "Windows Management Service" = O:\WINDOWS\System32\dmpyw.exe

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters
"nameserver"="85.255.115.4 85.255.112.14" HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{05B98D6F-5886-4A9F-B828-0621FA67226E}
"nameserver"="85.255.115.4,85.255.112.14" HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{2FB60702-9F83-46F3-A7F4-B6BD66808138}
"nameserver"="85.255.115.4,85.255.112.14" HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{49CE07A4-979F-49EC-B6F0-93AE59D659C3}
"nameserver"="85.255.115.4,85.255.112.14" HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{E1FFBB1C-BCB6-4292-91DA-03E593F96C40}
"nameserver"="85.255.115.4,85.255.112.14" HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{F63B5927-712F-43FD-8E7E-DAC529300393}
"nameserver"="85.255.115.4,85.255.112.14" HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{05B98D6F-5886-4A9F-B828-0621FA67226E}
"DhcpNameServer"="[removed],[removed]" HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{49CE07A4-979F-49EC-B6F0-93AE59D659C3}
"DhcpNameServer"="[removed],[removed]" HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{E1FFBB1C-BCB6-4292-91DA-03E593F96C40}
"DhcpNameServer"="[removed],[removed]" HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{F63B5927-712F-43FD-8E7E-DAC529300393}
"DhcpNameServer"="[removed],[removed]"

System was rebooted successfully.

~~~~~ Postrun check
HKLM\SOFTWARE\~\Winlogon\ "system"=""
….
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls "0mdm" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls "1mdm" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls "2mdm" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls "3mdm" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}98B0215A2FE3-90DB-6084-9961-D078466F{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}A637C4218DF7-BC48-F514-3062-32E64158{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "wypmd" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion "onesc" Value deleted
HKCR\CLSID\{8802AC76-50A9-4362-8C05-E1E26C656C1E}\_h\4 Deleted.
O:\WINDOWS\System32\adubk.exe Deleted
O:\WINDOWS\System32\allcg.exe Deleted
O:\WINDOWS\System32\bbofq.exe Deleted
O:\WINDOWS\System32\ecopx.exe Deleted
O:\WINDOWS\System32\ewget.exe Deleted
O:\WINDOWS\System32\fkfcv.exe Deleted
O:\WINDOWS\System32\fxprd.exe Deleted
O:\WINDOWS\System32\gatfg.exe Deleted
O:\WINDOWS\System32\gjrto.exe Deleted
O:\WINDOWS\System32\gtptq.exe Deleted
O:\WINDOWS\System32\huhuk.exe Deleted
O:\WINDOWS\System32\ibmnp.exe Deleted
O:\WINDOWS\System32\ipaej.exe Deleted
O:\WINDOWS\System32\izwgp.exe Deleted
O:\WINDOWS\System32\junva.exe Deleted
O:\WINDOWS\System32\ljwae.exe Deleted
O:\WINDOWS\System32\mcdyy.exe Deleted
O:\WINDOWS\System32\nobxg.exe Deleted
O:\WINDOWS\System32\pikaz.exe Deleted
O:\WINDOWS\System32\qehse.exe Deleted
O:\WINDOWS\System32\rerfj.exe Deleted
O:\WINDOWS\System32\rpuvn.exe Deleted
O:\WINDOWS\System32\suzgd.exe Deleted
O:\WINDOWS\System32\sxphp.exe Deleted
O:\WINDOWS\System32\tjgdf.exe Deleted
O:\WINDOWS\System32\tmbzo.exe Deleted
O:\WINDOWS\System32\tnrja.exe Deleted
O:\WINDOWS\System32\tphyu.exe Deleted
O:\WINDOWS\System32\txogo.exe Deleted
O:\WINDOWS\System32\ufizf.exe Deleted
O:\WINDOWS\System32\xkxro.exe Deleted
O:\WINDOWS\System32\yiwkq.exe Deleted
O:\WINDOWS\System32\ziqvh.exe Deleted
O:\WINDOWS\System32\zykph.exe Deleted
….
~~~~~ Misc files.
O:\Documents and Settings\Martin\Application Data\Install.dat Deleted
O:\Program Files\SpyVampire Deleted
O:\Program Files\Microsoft Security Adviser Deleted
O:\WINDOWS\system32\{536A2747-387C-4E7D-8593-33CF1569CC51}.exe Deleted
O:\WINDOWS\system32\{D9471D8B-711C-4C6B-A85D-0EA4AAC96A65}.exe Deleted
O:\WINDOWS\System32\kernel32.exe Deleted
….
~~~~~ Checking for older varients.
….
~~~~~ Other
O:\WINDOWS\Temp\cseno.ren 52829 02/20/2007

~~~~~ Current runs (hklm hkcu "run" Keys Only)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSConfig"="O:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\MSConfig.exe /auto"
"NvCplDaemon"="RUNDLL32.EXE O:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
….
Hosts file was reset, If you use a custom hosts file please replace it…
~~~~~ End report ~~~~~

—————————————————————————————————————————–
ComboFix 08-06-30.1 - Martin 2008-06-30 20:02:16.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.673 [GMT -4:00]
Running from: V:\Downloads\win\30jun08\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

O:\Documents and Settings\admin2\Desktop\Error Cleaner.url
O:\Documents and Settings\admin2\Desktop\Privacy Protector.url
O:\Documents and Settings\admin2\Desktop\Spyware&Malware Protection.url
O:\Documents and Settings\admin2\Favorites\Error Cleaner.url
O:\Documents and Settings\admin2\Favorites\Privacy Protector.url
O:\Documents and Settings\admin2\Favorites\Spyware&Malware Protection.url
O:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
O:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
O:\Documents and Settings\Martin\~tmp1174.exe
O:\Documents and Settings\Martin\Desktop\Error Cleaner.url
O:\Documents and Settings\Martin\Desktop\Privacy Protector.url
O:\Documents and Settings\Martin\Desktop\Spyware&Malware Protection.url
O:\Documents and Settings\Martin\Favorites\Error Cleaner.url
O:\Documents and Settings\Martin\Favorites\Privacy Protector.url
O:\Documents and Settings\Martin\Favorites\Spyware&Malware Protection.url
O:\WINDOWS\avp.exe
O:\WINDOWS\erwg.exe
O:\WINDOWS\gfetqaxssde.dll
O:\WINDOWS\gxvpsafm.dll
O:\WINDOWS\pntqkflv.dll
O:\WINDOWS\services.exe
O:\WINDOWS\system32\1_exception.nls
O:\WINDOWS\system32\alog.txt
O:\WINDOWS\system32\aswwer.dll
O:\WINDOWS\system32\blphc9u1j0e3av.scr
O:\WINDOWS\system32\btasv.dll
O:\WINDOWS\system32\cmds.txt
O:\WINDOWS\system32\conf.dat
O:\WINDOWS\system32\cookie.dat
O:\WINDOWS\system32\cookie1.dat
O:\WINDOWS\system32\driver.exe
O:\WINDOWS\system32\drivers\ip6fw.sys
O:\WINDOWS\system32\drivers\runtime2.sys
O:\WINDOWS\system32\help.txt
O:\WINDOWS\system32\ksys.sys
O:\WINDOWS\system32\LDR3.tmp
O:\WINDOWS\system32\LDR5.tmp
O:\WINDOWS\system32\LDR7.tmp
O:\WINDOWS\system32\pfxzmtsmtspm.dll
O:\WINDOWS\system32\pfxzmtwbmail.dll
O:\WINDOWS\system32\phc9u1j0e3av.bmp
O:\WINDOWS\system32\ps.dat
O:\WINDOWS\system32\ps1.dat
O:\WINDOWS\system32\rc.dat
O:\WINDOWS\system32\rsvp322.dll
O:\WINDOWS\system32\rsvp322.dllyrt
O:\WINDOWS\system32\sfxzmtwbmail.dll
O:\WINDOWS\system32\spywarewarning.mht
O:\WINDOWS\system32\sysmon32.exe
O:\WINDOWS\system32\winsys64.exe

—– BITS: Possible infected sites —–

hxxp://supertds.com
hxxp://67.18.114.98
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_NDNET1
——-\Legacy_RUNTIME
——-\Legacy_RUNTIME2
——-\Service_NDnet1
——-\Service_runtime


((((((((((((((((((((((((( Files Created from 2008-06-01 to 2008-07-01 )))))))))))))))))))))))))))))))
.

2008-06-30 19:38 . 2008-06-30 19:45 d——– O:\fixwareout
2008-06-30 08:33 . 2008-06-30 08:33 d——– O:\Documents and Settings\admin2\Application Data\TmpRecentIcons
2008-06-30 08:33 . 2008-06-30 08:33 d——– O:\Documents and Settings\admin2
2008-06-28 16:44 . 2008-06-28 16:44 d——– O:\Program Files\SmartPropoPlus
2008-06-28 16:41 . 2008-06-28 16:41 d——– O:\Program Files\Parallel Port Joystick
2008-06-28 16:06 . 2008-06-28 16:07 d——– O:\Documents and Settings\Martin\Application Data\GetRightToGo
2008-06-28 00:38 . 2008-06-27 22:49 180,224 –a—— O:\WINDOWS\qegbdmwf.dll
2008-06-28 00:38 . 2008-06-27 22:49 81,920 –a—— O:\WINDOWS\tovafrnm.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-30 05:52 2,872,832 —-a-w O:\WINDOWS\Internet Logs\xDB71.tmp
2008-06-30 05:52 18,432 —-a-w O:\WINDOWS\Internet Logs\xDB72.tmp
2008-06-30 05:34 64,000 —-a-w O:\WINDOWS\Internet Logs\xDB70.tmp
2008-06-30 05:34 2,869,760 —-a-w O:\WINDOWS\Internet Logs\xDB6F.tmp
2008-06-28 13:41 ——— d—–w O:\Documents and Settings\Martin\Application Data\nView_Wallpaper
2008-06-28 13:27 689,664 —-a-w O:\WINDOWS\Internet Logs\xDB6E.tmp
2008-06-28 13:27 2,853,888 —-a-w O:\WINDOWS\Internet Logs\xDB6D.tmp
2008-05-28 04:27 775,168 —-a-w O:\WINDOWS\Internet Logs\xDB6C.tmp
2008-05-28 04:25 2,839,552 —-a-w O:\WINDOWS\Internet Logs\xDB6B.tmp
2008-04-04 05:12 23,552 —-a-w O:\WINDOWS\Internet Logs\xDB6A.tmp
2008-04-04 05:12 2,802,176 —-a-w O:\WINDOWS\Internet Logs\xDB69.tmp
2008-04-02 06:28 57,856 —-a-w O:\WINDOWS\Internet Logs\xDB68.tmp
2008-04-02 06:18 2,802,176 —-a-w O:\WINDOWS\Internet Logs\xDB67.tmp
2008-04-02 05:00 22,528 —-a-w O:\WINDOWS\Internet Logs\xDB66.tmp
2008-04-02 04:56 2,802,176 —-a-w O:\WINDOWS\Internet Logs\xDB65.tmp
2008-04-02 04:52 923,648 —-a-w O:\WINDOWS\Internet Logs\xDB64.tmp
2008-04-02 04:52 2,803,200 —-a-w O:\WINDOWS\Internet Logs\xDB63.tmp
2007-03-03 22:17 29,656 —-a-w O:\Documents and Settings\Martin\xx_blpu.exe
2005-11-11 04:41 61 –sh–w O:\WINDOWS\cnerolf.dat
2007-07-27 06:06 149 –sha-w O:\WINDOWS\system32\1017217493.dat
2007-06-19 05:23 30,980 –sh–r O:\WINDOWS\system32\1041l.exe
2007-06-19 05:23 53 –sha-w O:\WINDOWS\system32\1041l.exe1017217493.dat
2007-06-01 05:54 30,980 –sh–r O:\WINDOWS\system32\adsmsextf.exe
2007-06-01 05:54 53 –sha-w O:\WINDOWS\system32\adsmsextf.exe1017217493.dat
2007-07-27 06:05 11,776 –sha-w O:\WINDOWS\system32\advapi32r.dll
.

——- Sigcheck ——-

2002-08-29 02:58 332928 244a2f9816bc9b593957281ef577d976 O:\WINDOWS\$NtServicePackUninstall$\tcpip.sys
2004-08-04 00:14 359040 1745b00fc1141404b28f4b94f69a8871 O:\WINDOWS\ServicePackFiles\i386\tcpip.sys
2004-08-04 00:14 359040 1745b00fc1141404b28f4b94f69a8871 O:\WINDOWS\system32\drivers\tcpip.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSConfig"="O:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2004-08-04 01:56 158208]
"NvCplDaemon"="O:\WINDOWS\system32\NvCpl.dll" [2006-08-11 21:43 7630848]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{88485281-8b4b-4f8d-9ede-82e29a064277}"= "O:\PROGRA~1\MarkAny\CONTEN~1\MACSMA~1.DLL" [2004-11-23 17:51 192512]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"qegbdmwf"= {E850F003-99A7-48C1-8DAC-DAA6482E9DD4} - O:\WINDOWS\qegbdmwf.dll [2008-06-27 22:49 180224]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"midi3"= KORGUMDD.DRV
"MIDI5"= usbmn2x2.dll
"midi2"= usbmn2x2.dll
"VIDC.NTN1"= nuvision.ax
"midi6"= usbmn4x4.dll
"midi7"= usbmn2x2.dll
"midi8"= usbmn4x4.dll
"msacm.dvacm"= O:\PROGRA~1\COMMON~1\ULEADS~1\Vio\Dvacm.acm
"midi4"= usbmn4x4.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli scecli

[HKLM\~\startupfolder\O:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=O:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=O:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\O:^Documents and Settings^All Users^Start Menu^Programs^Startup^Hawking Wireless Utility.lnk]
path=O:\Documents and Settings\All Users\Start Menu\Programs\Startup\Hawking Wireless Utility.lnk
backup=O:\WINDOWS\pss\Hawking Wireless Utility.lnkCommon Startup

[HKLM\~\startupfolder\O:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=O:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=O:\WINDOWS\pss\Logitech Desktop Messenger.lnkCommon Startup

[HKLM\~\startupfolder\O:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Harmony Remote Software 7.lnk]
path=O:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Harmony Remote Software 7.lnk
backup=O:\WINDOWS\pss\Logitech Harmony Remote Software 7.lnkCommon Startup

[HKLM\~\startupfolder\O:^Documents and Settings^Martin^Start Menu^Programs^Startup^PowerReg Scheduler.exe]
path=O:\Documents and Settings\Martin\Start Menu\Programs\Startup\PowerReg Scheduler.exe
backup=O:\WINDOWS\pss\PowerReg Scheduler.exeStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CreativeTaskScheduler]
——— 2006-11-16 21:42 53341 O:\Program Files\Creative\Shared Files\CTSched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTSyncU.exe]
——— 2007-07-17 12:03 868352 O:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FastUser]
–a—— 2001-10-08 12:59 49216 O:\WINDOWS\system32\Fast.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FusionRemote]
–a—— 2006-10-26 18:06 2267136 O:\Program Files\DVICO\FusionHDTV\Remote\FusionRC.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
–a—— 2006-11-13 13:39 1289000 O:\Program Files\Microsoft ActiveSync\wcescomm.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM]
–a—— 2006-10-18 22:19 32768 O:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LiveMonitor]
–a—— 2006-09-05 17:45 497152 O:\Program Files\MSI\Live Update 3\LMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\M-Audio Delta Taskbar Icon]
–a—— 2004-08-27 00:43 56320 O:\WINDOWS\system32\delttray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MAAgent]
–a—— 2007-01-30 21:36 57344 O:\Program Files\MarkAny\ContentSafer\MaAgent.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
–a—— 2004-08-04 01:56 1667584 O:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBJ]
——— 2005-05-19 20:38 1957888 O:\Program Files\Ahead\Nero BackItUp\NBJ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
–a—— 2001-07-09 12:50 155648 O:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
–a—— 2006-08-11 21:43 7630848 O:\WINDOWS\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Profiler]
–a—— 2004-01-28 09:19 159744 O:\Program Files\Saitek\Software\Profiler.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SaiSmart]
–a—— 2004-01-28 09:19 98304 O:\Program Files\Saitek\Software\SaiSmart.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSTray]
–a—— 2007-09-20 18:21 132624 T:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows update loader]
–a—— 2007-02-20 03:45 28160 C:\windows\xpupdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\xx_Shell]
–a—— 2007-03-03 18:17 29656 O:\Documents and Settings\Martin\xx_blpu.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zone Labs Client]
–a—— 2005-04-19 18:06 935688 O:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DeltTray]
–a—— 2004-08-27 00:43 56320 O:\WINDOWS\system32\delttray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
–a—— 2006-08-11 21:43 86016 O:\WINDOWS\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
–a—— 2006-08-11 21:43 1519616 O:\WINDOWS\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
–a—— 2004-12-01 03:54 77824 O:\WINDOWS\SOUNDMAN.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"O:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"O:\\Program Files\\Logitech\\Harmony Remote\\PatchHelper.exe"=
"O:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:6\\downloads\\utorrent.exe"=
"O:\Program Files\Microsoft ActiveSync\rapimgr.exe"= O:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"O:\Program Files\Microsoft ActiveSync\wcescomm.exe"= O:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"O:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= O:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"O:\\WINDOWS\\system32\\muzapp.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

R0 Defrag32b;Defrag32Boot;O:\WINDOWS\system32\drivers\Defrag32b.sys [2005-06-28 10:17]
R2 Asapi;Asapi;O:\WINDOWS\system32\drivers\Asapi.sys [2000-05-12 15:48]
R2 cx88xbar;FusionHDTV 88x, WDM Crossbar;O:\WINDOWS\system32\drivers\zl88xbar.sys [2006-08-09 21:25]
R2 Defrag32;Defrag32;O:\WINDOWS\system32\drivers\Defrag32.sys [2005-06-28 10:17]
R2 Zulu88Tune;FusionHDTV 88x, WDM Tuner(LG062F);O:\WINDOWS\system32\drivers\zl88tune.sys [2006-08-09 21:25]
R2 Zulu88Vid;FusionHDTV 88x, WDM Video Capture;O:\WINDOWS\system32\drivers\zl88vcap.sys [2006-08-09 21:25]
R3 CXAVSAUD;FusionHDTV 880, WDM Audio Capture;O:\WINDOWS\system32\drivers\zl88aud.sys [2006-08-09 21:25]
R3 L6DP;L6DP;O:\WINDOWS\system32\Drivers\l6dp.sys [2005-11-14 15:03]
R3 PPJoyBus;Parallel Port Joystick Bus device driver;O:\WINDOWS\system32\drivers\PPJoyBus.sys [2004-10-24 08:11]
R3 PPortJoystick;Parallel Port Joystick device driver;O:\WINDOWS\system32\drivers\PPortJoy.sys [2004-10-24 08:11]
R3 rxpvbus;Reality XP Avionics Bus Driver;O:\WINDOWS\system32\DRIVERS\rxpvbus.sys [2005-08-28 22:04]
R3 USBMN4X4;M-Audio USB MidiSport 4x4;O:\WINDOWS\system32\drivers\usbmn4x4.sys [2005-10-09 18:42]
R3 Zulu88BDA;FusionHDTV 88x, BDA DVB Tuner/Demod;O:\WINDOWS\system32\drivers\zl88bda.sys [2006-08-09 21:25]
R3 Zulu88Ts;FusionHDTV 88x, BDA Receiver(ATSC-A);O:\WINDOWS\system32\drivers\zl88tcap.sys [2006-08-09 21:25]
S2 aspnet_stateseclogon;ASP.NET State Service aspnet_stateseclogon;O:\WINDOWS\system32\12520437v.exe []
S2 InteractiveLogonSysmonLog;InteractiveLogon InteractiveLogonSysmonLog;O:\WINDOWS\system32\1033f.exe []
S2 lanmanworkstationcisvc;Workstation lanmanworkstationcisvc;O:\WINDOWS\system32\activedst.exe []
S2 PDSched;PDScheduler;O:\Program Files\Raxco\PerfectDisk\PDSched.exe [2005-06-28 14:07]
S3 BRGSp50;BRGSp50 NDIS Protocol Driver;O:\WINDOWS\system32\Drivers\BRGSp50.sys [2005-06-08 19:44]
S3 KORGUMDS;KORG USB-MIDI Driver for Windows XP;O:\WINDOWS\system32\Drivers\KORGUMDS.SYS [2004-02-19 01:05]
S3 L6TPortB;Service - Line 6 TonePort UX2;O:\WINDOWS\system32\Drivers\L6TPortB.sys [2005-11-14 15:01]
S3 msvad_multi;Samson Audio (WDM);O:\WINDOWS\system32\drivers\SWAudWDM.sys [2005-11-10 16:58]
S3 NuVision;Hauppauge WinTV USB Pro (NTSC FM);O:\WINDOWS\system32\DRIVERS\NUVision.sys [2005-07-08 16:40]
S3 SaiH0464;SaiH0464;O:\WINDOWS\system32\DRIVERS\SaiH0464.sys [2004-01-30 09:29]
S3 SamsonLLDriver;Samson C01U LL Driver;O:\WINDOWS\system32\Drivers\SamsonLLDriver.sys [2005-11-10 16:58]
S3 SynasUSB;SynasUSB;O:\WINDOWS\system32\drivers\SynasUSB.sys [2002-03-14 14:02]
S3 US224;US224 Driver;O:\WINDOWS\system32\Drivers\US224.sys [2004-07-30 11:49]
S3 US224DL;US224 Firmware Downloader;O:\WINDOWS\system32\Drivers\US224DL.sys [2004-07-30 12:02]
S3 Us224WdmService;US224 Wdm Audio;O:\WINDOWS\system32\Drivers\US224Wdm.sys [2004-07-30 11:49]
S3 USB22LDR;M-Audio USB MidiSport 2x2 Loader;O:\WINDOWS\system32\drivers\usb22ldr.sys [2005-10-10 13:00]
S3 USB44LDR;M-Audio USB MidiSport 4x4 Loader;O:\WINDOWS\system32\drivers\usb44ldr.sys [2005-10-09 18:42]
S3 USBMN2X2;M-Audio USB MidiSport 2x2;O:\WINDOWS\system32\drivers\usbmn2x2.sys [2005-10-10 13:00]
S3 ZD1211BU(Hawking);Hawking Hi-Gain Wireless-G USB Dish Adapter(Hawking);O:\WINDOWS\system32\DRIVERS\zd1211Bu.sys [2005-10-28 12:38]

.
- - - - ORPHANS REMOVED - - - -

BHO-{0245D364-5F52-44ac-B6EB-7BAD6E3D7EF2} - btasv.dll
BHO-{783550EA-6F83-4ddc-AC5E-14D06154B942} - mar12.dll
Toolbar-{A497D131-ABE9-4267-8C94-8D7FDBCF99AC} - O:\WINDOWS\gxvpsafm.dll
SSODL-pntqkflv-{50FA4DE1-ADB6-454C-8B7B-375EC1445180} - O:\WINDOWS\pntqkflv.dll
MSConfigStartUp-avp - O:\WINDOWS\avp.exe
MSConfigStartUp-CoolSwitch - O:\WINDOWS\System32\taskswitch.exe
MSConfigStartUp-lphc9u1j0e3av - O:\WINDOWS\system32\lphc9u1j0e3av.exe
MSConfigStartUp-RegistryMonitor - O:\WINDOWS\sysfade.exe
MSConfigStartUp-RegistryMonitor1 - O:\WINDOWS\system32\qtplugin.exe
MSConfigStartUp-startdrv - O:\WINDOWS\Temp\startdrv.exe
MSConfigStartUp-Windows Control Service - O:\WINDOWS\system32\wincs32.exe
MSConfigStartUp-BluetoothAuthenticationAgent - bthprops.cpl,,BluetoothAuthenticationAgent
MSConfigStartUp-smgr - mgrs.exe


**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-30 20:06:28
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet004\Services\AudioSrvSharedAccess]
"ImagePath"="*&€|\14û\06 srv"

[HKEY_LOCAL_MACHINE\System\ControlSet004\Services\srservice Management Service]
"ImagePath"="*&€|\14û\06 srv"
.
———————— Other Running Processes ————————
.
O:\WINDOWS\system32\CTSVCCDA.EXE
O:\WINDOWS\system32\nvsvc32.exe
O:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O:\WINDOWS\system32\ZoneLabs\vsmon.exe
.
**************************************************************************
.
Completion time: 2008-06-30 20:10:20 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-01 00:10:16

Pre-Run: 5,998,559,232 bytes free
Post-Run: 6,343,671,808 bytes free

294

———————————————————————————————-

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:16, on 6/30/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
O:\WINDOWS\System32\smss.exe
O:\WINDOWS\system32\winlogon.exe
O:\WINDOWS\system32\services.exe
O:\WINDOWS\system32\lsass.exe
O:\WINDOWS\system32\svchost.exe
O:\WINDOWS\System32\svchost.exe
O:\WINDOWS\system32\svchost.exe
O:\WINDOWS\system32\spoolsv.exe
O:\WINDOWS\system32\CTsvcCDA.exe
O:\WINDOWS\system32\nvsvc32.exe
O:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O:\WINDOWS\system32\ZoneLabs\vsmon.exe
O:\WINDOWS\System32\Fast.exe
O:\WINDOWS\Explorer.EXE
O:\WINDOWS\system32\wuauclt.exe
O:\WINDOWS\Explorer.EXE
V:\Downloads\win\30jun08\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=…6Ojg5&lid=2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - O:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [MSConfig] O:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE O:\WINDOWS\system32\NvCpl.dll,NvStartup
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - O:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - O:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - O:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - O:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - O:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.line6.net
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.115.4 85.255.112.14
O17 - HKLM\System\CS1\Services\Tcpip\..\{05B98D6F-5886-4A9F-B828-0621FA67226E}: NameServer = 85.255.115.4,85.255.112.14
O18 - Protocol: bw+0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: offline-8876480 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O21 - SSODL: qegbdmwf - {E850F003-99A7-48C1-8DAC-DAA6482E9DD4} - O:\WINDOWS\qegbdmwf.dll
O23 - Service: ASP.NET State Service aspnet_stateseclogon (aspnet_stateseclogon) - Unknown owner - O:\WINDOWS\system32\12520437v.exe (file missing)
O23 - Service: Windows Audio AudioSrvSharedAccess (AudioSrvSharedAccess) - Unknown owner - *&€|û.exe (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - O:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - O:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InteractiveLogon InteractiveLogonSysmonLog (InteractiveLogonSysmonLog) - Unknown owner - O:\WINDOWS\system32\1033f.exe (file missing)
O23 - Service: Workstation lanmanworkstationcisvc (lanmanworkstationcisvc) - Unknown owner - O:\WINDOWS\system32\activedst.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - O:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PDEngine - Raxco Software, Inc. - O:\Program Files\Raxco\PerfectDisk\PDEngine.exe
O23 - Service: PDScheduler (PDSched) - Raxco Software, Inc. - O:\Program Files\Raxco\PerfectDisk\PDSched.exe
O23 - Service: System Restore Service srservice Management Service (srservice Management Service) - Unknown owner - *&€|û.exe (file missing)
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - O:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - O:\WINDOWS\system32\ZoneLabs\vsmon.exe

–
End of file - 16011 bytes
————————————————————————————————-
Hello,

Thanks again.

I installed and ran Avira anti-virus, as suggested. Then I obtained a new HiJackThis log, which is copied below.

[This computer seems quite good, except that, if I am plugged into the internet, I get a periodic IE window trying to get me to run an anti-spyware product, which I don't remember. At one point it turned the screen background to blue, which was remedied by a re-boot.]

Connected with this thread, I have included another HiJackThis log from another computer. This is from my office computer, which has suddenly become cripled after I ran the Avira product. I would really appreciate your insight on this, if possible. The symptoms for this computer is that after re-booting, the Avira product repeatedly finds two viruses (SRVdll.dll and TR/Dla.Agent.auy.7). After performing a quarantine action numerous times, the os gradually slows until within 5 minutes, or so, nothing works, including TaskManager. I obtained the HiJackThis log by booting in safe mode and running the program. I ran the product on this computer since it looked like a good solid virus checker, and my office computer had many "annoyances"; however, as mention, it is now essentially cripled. For me, this seconday problem is much more severe than the original problem.


Thanks again.


Computer 1 HiJackThis Log
————————————————————-


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:11, on 7/2/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
O:\WINDOWS\System32\smss.exe
O:\WINDOWS\system32\winlogon.exe
O:\WINDOWS\system32\services.exe
O:\WINDOWS\system32\lsass.exe
O:\WINDOWS\system32\svchost.exe
O:\WINDOWS\System32\svchost.exe
O:\WINDOWS\system32\svchost.exe
O:\WINDOWS\system32\spoolsv.exe
O:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O:\WINDOWS\Explorer.EXE
O:\WINDOWS\system32\CTsvcCDA.exe
O:\WINDOWS\system32\nvsvc32.exe
O:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O:\WINDOWS\system32\ZoneLabs\vsmon.exe
O:\WINDOWS\System32\Fast.exe
O:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
O:\Program Files\Microsoft ActiveSync\wcescomm.exe
O:\PROGRA~1\MICROS~2\rapimgr.exe
O:\WINDOWS\Explorer.EXE
O:\WINDOWS\system32\wuauclt.exe
V:\Downloads\win\30jun08\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=…6Ojg5&lid=2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - O:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE O:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [avgnt] "O:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [H/PC Connection Agent] "O:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - O:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - O:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - O:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - O:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - O:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.line6.net
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.115.4 85.255.112.14
O17 - HKLM\System\CS1\Services\Tcpip\..\{05B98D6F-5886-4A9F-B828-0621FA67226E}: NameServer = 85.255.115.4,85.255.112.14
O18 - Protocol: bw+0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: offline-8876480 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O21 - SSODL: qegbdmwf - {3353CCE0-239E-49A6-A696-D66C105DE8D9} - O:\WINDOWS\qegbdmwf.dll (file missing)
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - O:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - O:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: ASP.NET State Service aspnet_stateseclogon (aspnet_stateseclogon) - Unknown owner - O:\WINDOWS\system32\12520437v.exe (file missing)
O23 - Service: Windows Audio AudioSrvSharedAccess (AudioSrvSharedAccess) - Unknown owner - *&€|û.exe (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - O:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - O:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InteractiveLogon InteractiveLogonSysmonLog (InteractiveLogonSysmonLog) - Unknown owner - O:\WINDOWS\system32\1033f.exe (file missing)
O23 - Service: Workstation lanmanworkstationcisvc (lanmanworkstationcisvc) - Unknown owner - O:\WINDOWS\system32\activedst.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - O:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PDEngine - Raxco Software, Inc. - O:\Program Files\Raxco\PerfectDisk\PDEngine.exe
O23 - Service: PDScheduler (PDSched) - Raxco Software, Inc. - O:\Program Files\Raxco\PerfectDisk\PDSched.exe
O23 - Service: System Restore Service srservice Management Service (srservice Management Service) - Unknown owner - *&€|û.exe (file missing)
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - O:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - O:\WINDOWS\system32\ZoneLabs\vsmon.exe

–
End of file - 16746 bytes
________________________________________________

Computer 2 HiJackThis log

——————————————————————————————–

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:38:50 PM, on 7/2/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Safe mode

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\Explorer.EXE
G:\win\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://wbztv.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://as.starware.com/dp/search?x=wKX1ILE…bxRFJyNqKOtj0Y=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://as.starware.com/dp/search?x=wKX1ILE…MKXFEquYSX8A7k=
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by AT&T WorldNet Service
R3 - URLSearchHook: {B5AB638F-D76C-415B-A8F2-F3CEAC502212} - - (no file)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://D%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (D:\Documents and Settings\MARTIN\Application Data\Mozilla\Profiles\default\w5tz6bcb.slt\prefs.js)
O2 - BHO: EarthLink BHO Guard - {00000000-0000-0000-0000-000000000002} - c:\Program Files\Bank of America\Toolbar\EScamBlk.dll
O2 - BHO: BHObj Class - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - D:\WINDOWS\nem220.dll (file missing)
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - D:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: ChangerBHO Class - {0edc6c20-a31c-11db-8ab9-0800200c9a66} - D:\WINDOWS\system32\mscoriezbb.dll
O2 - BHO: EarthLink ScamBlocker V3 - {15F4D456-5BAA-4076-8486-EECB38CD3E57} - c:\Program Files\Bank of America\Toolbar\EScamBlk.dll
O2 - BHO: ui Class - {16DCA182-CFB2-4a4d-9E6A-6292559688CE} - D:\WINDOWS\system32\SPORD0R.dll
O2 - BHO: ContextualAds Class - {3AAC4C68-AFC8-11DB-80EF-8AF955D89593} - D:\Program Files\TrustIn Contextual\trustincontext.dll
O2 - BHO: (no name) - {45A4902E-4479-4EAE-A186-8D0F7E4C78DE} - D:\Program Files\Starware316\bin\Starware316.dll
O2 - BHO: ChangerBHO Class - {4c03732f-43bb-4d80-ba45-66fd05db11df} - D:\WINDOWS\system32\clba.dll
O2 - BHO: EarthLink PopUp Blocker V2 - {512ACF1B-64D9-4928-B382-A80556F28DB4} - c:\Program Files\Bank of America\Toolbar\ElnkPuB.dll
O2 - BHO: Clicker Class - {631f7200-642e-11db-bd13-0800200c9a66} - D:\WINDOWS\system32\mscoriezb.dll
O2 - BHO: KontekstualAds Class - {72217827-914b-46c6-a6ee-c00c70842ebf} - D:\Program Files\TrustIn Kontekstual\InTru.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - D:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Uninstall Legacy Earthlink Toolbar - {E713904C-DF05-4C79-BBAD-02DB923253BE} - c:\Program Files\Bank of America\Toolbar\uninsttb.dll
O2 - BHO: WeeklyExecuter Class - {f015f320-ab08-11db-abbd-0800200c9a66} - D:\WINDOWS\inetloader.dll
O2 - BHO: SpoofBHO Class - {F631AAE2-4C20-11DC-8929-D3F855D89593} - D:\WINDOWS\se_spoof.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - D:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O3 - Toolbar: YourSiteBar - {86227D9C-0EFE-4f8a-AA55-30386A3F5686} - D:\Program Files\YourSiteBar\ysb.dll
O3 - Toolbar: Seekmo Toolbar - {53E0B6E8-A51D-448B-B692-40B67B285543} - D:\Program Files\Seekmo Programs\Seekmo Toolbar\SeekmoTB.dll
O3 - Toolbar: Starware316 - {9FB3908C-6565-4CB0-95F8-E9F85258723C} - D:\Program Files\Starware316\bin\Starware316.dll
O3 - Toolbar: Bank of America Toolbar - {C7768536-96F8-4001-B1A2-90EE21279187} - c:\Program Files\Bank of America\Toolbar\Toolbar.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - D:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SM1BG] D:\WINDOWS\SM1BG.EXE
O4 - HKLM\..\Run: [SynTPLpr] D:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] D:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Zone Labs Client] D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [Internet Optimizer] "D:\Program Files\Internet Optimizer\optimize.exe"
O4 - HKLM\..\Run: [ReJf5vH] D:\WINDOWS\rmwvyehb.exe
O4 - HKLM\..\Run: [NapsterShell] D:\Program Files\Napster\napster.exe /systray
O4 - HKLM\..\Run: [Easy Synchronization] D:\Program Files\Logitech\Easy Synchronization\LogitechEasySync.exe
O4 - HKLM\..\Run: [CTCheck] D:\Program Files\Creative\ZEN Media Explorer\CTCheck.exe
O4 - HKLM\..\Run: [avgnt] "D:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [MSConfig] D:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\RunServices: [ITUNES] itunes.exe
O4 - HKLM\..\RunServices: [USB Fix 1.1] wuservices.exe
O4 - HKLM\..\RunOnce: [Easy Synchronization] D:\Program Files\Logitech\Easy Synchronization\LogitechEasySync.exe –ports
O4 - HKCU\..\Run: [Creative Detector] "C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R
O4 - HKCU\..\Run: [Regscan] D:\WINDOWS\system32\regscan.exe
O4 - HKCU\..\Run: [CTSyncU.exe] "D:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
O4 - HKUS\S-1-5-18\..\Run: [Microsoft Update] Svhost.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Microsoft SpA Service] winbd32.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Windows Processe Manager] mspn32.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Microsoft System Services] msmsgr.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Service Drivers] msnpg.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [MotherBoard Sounds] sounds.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [MSMSGS] "D:\Program Files\Messenger\msmsgs.exe" /background (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [USB Fix 1.1] wuservices.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Compaq Service Drivers] msnsvc.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunServices: [Windows Processe Manager] mspn32.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Microsoft Update] Svhost.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunServices: [Windows Processe Manager] mspn32.exe (User 'Default user')
O4 - Startup: Webshots.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: SoftStuff Wallpaper Changer.lnk = D:\Program Files\SoftStuff\softstrt.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Logitech SetPoint.lnk = ?
O8 - Extra context menu item: &Google Search - res://d:\windows\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://d:\windows\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://d:\windows\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: EarthLink Google Search - res://c:\Program Files\Bank of America\Toolbar\SearchUI.dll/search.html
O8 - Extra context menu item: Open Client to monitor &1 - D:\WINDOWS\web\AOpenClient.htm
O8 - Extra context menu item: Open Client to monitor &2 - D:\WINDOWS\web\AOpenClient.htm
O8 - Extra context menu item: Send to &Bluetooth Device… - D:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Similar Pages - res://d:\windows\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://d:\windows\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: AnyWho - {0264505A-6793-44E0-AC75-9DCE3B13185C} - D:\Program Files\AT&T\WnClient\Programs\AnyWho.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\j2re1.4.1_06\bin\npjpi141_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\j2re1.4.1_06\bin\npjpi141_06.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: d:\windows\system32\nwprovau.dll
O10 - Unknown file in Winsock LSP: d:\windows\system32\srvdll.dll
O10 - Unknown file in Winsock LSP: d:\windows\system32\srvdll.dll
O15 - Trusted Zone: *.line6.net
O15 - Trusted Zone: http://extract.cr.usgs.gov
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1202771356082
O17 - HKLM\System\CCS\Services\Tcpip\..\{1678435A-8246-4353-A411-20F5B7A8AD2D}: NameServer = 64.105.204.26,64.105.124.154
O17 - HKLM\System\CS1\Services\Tcpip\..\{1678435A-8246-4353-A411-20F5B7A8AD2D}: NameServer = 12.127.16.83,12.127.17.83
O17 - HKLM\System\CS2\Services\Tcpip\..\{1678435A-8246-4353-A411-20F5B7A8AD2D}: NameServer = 64.105.204.26,64.105.124.154
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - D:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - D:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - D:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - D:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - D:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - D:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - D:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Imapi Helper - Alex Feinman - D:\Program Files\Alex Feinman\ISO Recorder\ImapiHelper.exe
O23 - Service: iPod Service - Apple Inc. - D:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech Inc. - D:\Program Files\Common Files\Logitech\Bluetooth\LBTSERV.EXE
O23 - Service: Logitech Easy Synchronization - Unknown owner - D:\Program Files\Logitech\Easy Synchronization\servicestub.exe
O23 - Service: MAV - Unknown owner - D:\DOCUME~1\Martin\LOCALS~1\Temp\MAV.exe (file missing)
O23 - Service: MSWindowsUpdate009 - Unknown owner - D:\WINDOWS\system32\QClient9.exe (file missing)
O23 - Service: NT login service (ntlogin32) - Unknown owner - D:\WINDOWS\System32\libsysmgr.exe (file missing)
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - D:\WINDOWS\system32\pctspk.exe
O23 - Service: PDAgent - Raxco Software, Inc. - D:\Program Files\Raxco\PerfectDisk\PDAgent.exe
O23 - Service: PDEngine - Raxco Software, Inc. - D:\Program Files\Raxco\PerfectDisk\PDEngine.exe
O23 - Service: Pml Driver HPZ12 - HP - D:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Rio MSC Manager (RioMSC) - Digital Networks North America, Inc. - D:\WINDOWS\System32\RioMSC.exe
O23 - Service: ServiceLayer - Nokia. - D:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Sony DADC Austria AG. - D:\WINDOWS\System32\UAService7.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - D:\WINDOWS\system32\ZONELABS\vsmon.exe

–
End of file - 13411 bytes
———————————————————————————————
Okay, we need to proceed with these one at a time. Lets stay with computer 1. If the two computers are connected please seperate them until both are clean or we will end up going round in circles.

Go to http://virusscan.jotti.org
Copy the following line into the white textbox:
O:\Documents and Settings\Martin\xx_blpu.exe
Click Submit.
Please post the results of this scan to this thread.

Do the same for these
O:\WINDOWS\cnerolf.dat
O:\WINDOWS\system32\1017217493.dat
O:\WINDOWS\system32\1041l.exe
O:\WINDOWS\system32\adsmsextf.exe


If Jotti is busy or unavailable, please try
Virustotal
First of all, thanks for the prompt replies. The subject computer continues to perform well. There has been no further evidence of problems, either when connected to the Internet, or when not. The scans of the files requested found nothing, the details, scraped off the screen, are shown below. I also noticed that the Avira virus scan program had not completed, as reflected in the previous HiJackThis log posted earlier. Sorry about this. I still have one physical drive left to scan and will post another HiJackThis log when that is complete unless you think this is not necessary. Finallly, as suggested, I will hold off on the other computer problem. However, I am in the process of doing a complete Avira scan on that system, using the boot CD process that the company suggests at their website, when deleted files keep returning repeatedly. Cheers! ——————————————————— (1) FILE - O:\Documents and Settings\Martin\xx_blpu.exe Note: No Results because File no longer on computer ——————————————————– ——————————————————– (2) FILE - O:\WINDOWS\cnerolf.dat ——————————————————– Service load: 0% 100% File: cnerolf.dat Status: OK MD5: 30bb618d270829354ebbcd0f3a030ed5 A-Squared Found nothing AntiVir Found nothing ArcaVir Found nothing Avast Found nothing AVG Antivirus Found nothing BitDefender Found nothing ClamAV Found nothing CPsecure Found nothing Dr.Web Found nothing F-Prot Antivirus Found nothing F-Secure Anti-Virus Found nothing Fortinet Found nothing Ikarus Found nothing Kaspersky Anti-Virus Found nothing NOD32 Found nothing Norman Virus Control Found nothing Panda Antivirus Found nothing Sophos Antivirus Found nothing VirusBuster Found nothing VBA32 Found nothing ———————————————- (3)FILE - O:\WINDOWS\system32\1017217493.dat ———————————————- Service load: 0% 100% File: 1017217493.dat Status: OK MD5: bb938f31218239538445d6e37926f75b Packers detected: - A-Squared Found nothing AntiVir Found nothing ArcaVir Found nothing Avast Found nothing AVG Antivirus Found nothing BitDefender Found nothing ClamAV Found nothing CPsecure Found nothing Dr.Web Found nothing F-Prot Antivirus Found nothing F-Secure Anti-Virus Found nothing Fortinet Found nothing Ikarus Found nothing Kaspersky Anti-Virus Found nothing NOD32 Found nothing Norman Virus Control Found nothing Panda Antivirus Found nothing Sophos Antivirus Found nothing VirusBuster Found nothing VBA32 Found nothing ——————————————————– (4) FILE - O:\WINDOWS\system32\1041l.exe ——————————————————– Service load: 0% 100% File: 1041l.exe1017217493.dat Status: OK MD5: 5281fa12fa16bb1763753aefa37765be Packers detected: - Scanner results Scan taken on 03 Jul 2008 01:34:48 (GMT) A-Squared Found nothing AntiVir Found nothing ArcaVir Found nothing Avast Found nothing AVG Antivirus Found nothing BitDefender Found nothing ClamAV Found nothing CPsecure Found nothing Dr.Web Found nothing F-Prot Antivirus Found nothing F-Secure Anti-Virus Found nothing Fortinet Found nothing Ikarus Found nothing Kaspersky Anti-Virus Found nothing NOD32 Found nothing Norman Virus Control Found nothing Panda Antivirus Found nothing Sophos Antivirus Found nothing VirusBuster Found nothing VBA32 Found nothing ——————————————————– (5) FILE - O:\WINDOWS\system32\adsmsextf.exe ——————————————————– Service load: 0% 100% File: adsmsextf.exe1017217493.dat Status: OK(Note: file has been scanned before. Therefore, this file's scan results will not be stored in the database) MD5: 5281fa12fa16bb1763753aefa37765be Packers detected: - Scanner results Scan taken on 03 Jul 2008 01:38:42 (GMT) A-Squared Found nothing AntiVir Found nothing ArcaVir Found nothing Avast Found nothing AVG Antivirus Found nothing BitDefender Found nothing ClamAV Found nothing CPsecure Found nothing Dr.Web Found nothing F-Prot Antivirus Found nothing F-Secure Anti-Virus Found nothing Fortinet Found nothing Ikarus Found nothing Kaspersky Anti-Virus Found nothing NOD32 Found nothing Norman Virus Control Found nothing Panda Antivirus Found nothing Sophos Antivirus Found nothing VirusBuster Found nothing VBA32 Found nothing
Hi


Remember to disconnect from the Internet before carrying out the next instruction, and to save the following script before you do.You must
also manually disable your anti-virus and anti-spyware programs. See the link below for instructions on doing this.

http://www.bleepingcomputer.com/forums/topic114351.html

Open Notepad - it must be Notepad, not Wordpad.
Copy the text below in the code box by highlighting all the text with your mouse and pressing Ctrl+C

File::
O:\WINDOWS\qegbdmwf.dll
O:\WINDOWS\tovafrnm.exe
C:\windows\xpupdate.exe
O:\Documents and Settings\Martin\xx_blpu.exe

Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows update loader]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\xx_Shell]

Go to the Notepad window and click Edit > Paste
Then click File > Save
Name the file "CFScript.txt" (including the quotes)
Save the file to your Desktop

[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe


Run HijackThis, select Do a system scan only and place checks against the following entries (if they are still present):

O15 - Trusted Zone: *.line6.net
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.115.4 85.255.112.14
O17 - HKLM\System\CS1\Services\Tcpip\..\{05B98D6F-5886-4A9F-B828-0621FA67226E}: NameServer = 85.255.115.4,85.255.112.14


WITH ALL OTHER WINDOWS CLOSED Click on Fix Checked exit HijackThis and reboot.


Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.


Once you have installed the Scanner, and the updated definitions, you can disconnect from the Internet and disable your anti-virus, to reduce scanning time. Re-enable the anti-virus before reconnecting to the Internet.
Instructions on disabling a variety of security programs can be found at the link below.

http://www.bleepingcomputer.com/forums/topic114351.html


In your next reply post:
ComboFix.txt
Kaspersky report
New HijackThis log taken after the above scan has run
Sorry for the delay - still working on Kaspersky system scan - will post results, as requested, when complete……….
Hello,

This is a follow-up to the last post requesting:

ComboFix.txt
Kaspersky report
New HijackThis log taken after the above scan has run

Note: Kaspersky was run for each drive separately; only drives with detections are shown)

————————————————————————————————————————–

ComboFix 08-06-30.1 - Martin 2008-07-03 19:15:47.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.696 [GMT -4:00]
Running from: O:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: O:\Documents and Settings\Martin\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\windows\xpupdate.exe
O:\Documents and Settings\Martin\xx_blpu.exe
O:\WINDOWS\qegbdmwf.dll
O:\WINDOWS\tovafrnm.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

O:\WINDOWS\tovafrnm.exe

.
((((((((((((((((((((((((( Files Created from 2008-06-03 to 2008-07-03 )))))))))))))))))))))))))))))))
.

2008-07-02 01:12 . 2008-07-02 01:12 d——– O:\Program Files\Avira
2008-07-02 01:12 . 2008-07-02 01:12 d——– O:\Documents and Settings\All Users\Application Data\Avira
2008-06-30 19:38 . 2008-06-30 19:45 d——– O:\fixwareout
2008-06-30 08:33 . 2008-06-30 08:33 d——– O:\Documents and Settings\admin2\Application Data\TmpRecentIcons
2008-06-30 08:33 . 2008-06-30 08:33 d——– O:\Documents and Settings\admin2
2008-06-28 16:44 . 2008-06-28 16:44 d——– O:\Program Files\SmartPropoPlus
2008-06-28 16:41 . 2008-06-28 16:41 d——– O:\Program Files\Parallel Port Joystick
2008-06-28 16:06 . 2008-06-28 16:07 d——– O:\Documents and Settings\Martin\Application Data\GetRightToGo

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-03 01:56 2,913,792 —-a-w O:\WINDOWS\Internet Logs\xDB75.tmp
2008-07-03 01:29 20,992 —-a-w O:\WINDOWS\Internet Logs\xDB76.tmp
2008-07-02 12:36 2,913,280 —-a-w O:\WINDOWS\Internet Logs\xDB73.tmp
2008-07-02 07:18 186,368 —-a-w O:\WINDOWS\Internet Logs\xDB74.tmp
2008-07-02 07:17 ——— d—–w O:\Documents and Settings\Martin\Application Data\nView_Wallpaper
2008-06-30 05:52 2,872,832 —-a-w O:\WINDOWS\Internet Logs\xDB71.tmp
2008-06-30 05:52 18,432 —-a-w O:\WINDOWS\Internet Logs\xDB72.tmp
2008-06-30 05:34 64,000 —-a-w O:\WINDOWS\Internet Logs\xDB70.tmp
2008-06-30 05:34 2,869,760 —-a-w O:\WINDOWS\Internet Logs\xDB6F.tmp
2008-06-28 13:27 689,664 —-a-w O:\WINDOWS\Internet Logs\xDB6E.tmp
2008-06-28 13:27 2,853,888 —-a-w O:\WINDOWS\Internet Logs\xDB6D.tmp
2008-05-28 04:27 775,168 —-a-w O:\WINDOWS\Internet Logs\xDB6C.tmp
2008-05-28 04:25 2,839,552 —-a-w O:\WINDOWS\Internet Logs\xDB6B.tmp
2008-04-04 05:12 23,552 —-a-w O:\WINDOWS\Internet Logs\xDB6A.tmp
2008-04-04 05:12 2,802,176 —-a-w O:\WINDOWS\Internet Logs\xDB69.tmp
2005-11-11 04:41 61 –sh–w O:\WINDOWS\cnerolf.dat
2007-07-27 06:06 149 –sha-w O:\WINDOWS\system32\1017217493.dat
2007-06-19 05:23 53 –sha-w O:\WINDOWS\system32\1041l.exe1017217493.dat
2007-06-01 05:54 53 –sha-w O:\WINDOWS\system32\adsmsextf.exe1017217493.dat
.

——- Sigcheck ——-

2002-08-29 02:58 332928 244a2f9816bc9b593957281ef577d976 O:\WINDOWS\$NtServicePackUninstall$\tcpip.sys
2004-08-04 00:14 359040 1745b00fc1141404b28f4b94f69a8871 O:\WINDOWS\ServicePackFiles\i386\tcpip.sys
2004-08-04 00:14 359040 1745b00fc1141404b28f4b94f69a8871 O:\WINDOWS\system32\drivers\tcpip.sys
.
((((((((((((((((((((((((((((( snapshot@2008-06-30_20.10.01.32 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-07-01 00:05:58 2,048 –s-a-w O:\WINDOWS\bootstat.dat
+ 2008-07-03 23:19:31 2,048 –s-a-w O:\WINDOWS\bootstat.dat
+ 2008-01-21 22:12:56 41,792 —-a-w O:\WINDOWS\system32\drivers\avgntdd.sys
+ 2008-01-21 22:11:28 22,336 —-a-w O:\WINDOWS\system32\drivers\avgntmgr.sys
+ 2008-03-04 17:28:53 79,424 —-a-w O:\WINDOWS\system32\drivers\avipbb.sys
+ 2004-08-04 04:00:08 29,056 —-a-w O:\WINDOWS\system32\drivers\ip6fw.sys
+ 2007-03-01 14:34:22 28,352 —-a-w O:\WINDOWS\system32\drivers\ssmdrv.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="O:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 13:39 1289000]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="O:\WINDOWS\system32\NvCpl.dll" [2006-08-11 21:43 7630848]
"avgnt"="O:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-02-12 10:06 262401]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{88485281-8b4b-4f8d-9ede-82e29a064277}"= "O:\PROGRA~1\MarkAny\CONTEN~1\MACSMA~1.DLL" [2004-11-23 17:51 192512]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"midi3"= KORGUMDD.DRV
"MIDI5"= usbmn2x2.dll
"midi2"= usbmn2x2.dll
"VIDC.NTN1"= nuvision.ax
"midi6"= usbmn4x4.dll
"midi7"= usbmn2x2.dll
"midi8"= usbmn4x4.dll
"msacm.dvacm"= O:\PROGRA~1\COMMON~1\ULEADS~1\Vio\Dvacm.acm
"midi4"= usbmn4x4.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli scecli

[HKLM\~\startupfolder\O:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=O:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=O:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\O:^Documents and Settings^All Users^Start Menu^Programs^Startup^Hawking Wireless Utility.lnk]
path=O:\Documents and Settings\All Users\Start Menu\Programs\Startup\Hawking Wireless Utility.lnk
backup=O:\WINDOWS\pss\Hawking Wireless Utility.lnkCommon Startup

[HKLM\~\startupfolder\O:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=O:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=O:\WINDOWS\pss\Logitech Desktop Messenger.lnkCommon Startup

[HKLM\~\startupfolder\O:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Harmony Remote Software 7.lnk]
path=O:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Harmony Remote Software 7.lnk
backup=O:\WINDOWS\pss\Logitech Harmony Remote Software 7.lnkCommon Startup

[HKLM\~\startupfolder\O:^Documents and Settings^Martin^Start Menu^Programs^Startup^PowerReg Scheduler.exe]
path=O:\Documents and Settings\Martin\Start Menu\Programs\Startup\PowerReg Scheduler.exe
backup=O:\WINDOWS\pss\PowerReg Scheduler.exeStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CreativeTaskScheduler]
——— 2006-11-16 21:42 53341 O:\Program Files\Creative\Shared Files\CTSched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTSyncU.exe]
——— 2007-07-17 12:03 868352 O:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FastUser]
–a—— 2001-10-08 12:59 49216 O:\WINDOWS\system32\Fast.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FusionRemote]
–a—— 2006-10-26 18:06 2267136 O:\Program Files\DVICO\FusionHDTV\Remote\FusionRC.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
–a—— 2006-11-13 13:39 1289000 O:\Program Files\Microsoft ActiveSync\wcescomm.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM]
–a—— 2006-10-18 22:19 32768 O:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LiveMonitor]
–a—— 2006-09-05 17:45 497152 O:\Program Files\MSI\Live Update 3\LMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\M-Audio Delta Taskbar Icon]
–a—— 2004-08-27 00:43 56320 O:\WINDOWS\system32\delttray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MAAgent]
–a—— 2007-01-30 21:36 57344 O:\Program Files\MarkAny\ContentSafer\MaAgent.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
–a—— 2004-08-04 01:56 1667584 O:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBJ]
——— 2005-05-19 20:38 1957888 O:\Program Files\Ahead\Nero BackItUp\NBJ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
–a—— 2001-07-09 12:50 155648 O:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
–a—— 2006-08-11 21:43 7630848 O:\WINDOWS\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Profiler]
–a—— 2004-01-28 09:19 159744 O:\Program Files\Saitek\Software\Profiler.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SaiSmart]
–a—— 2004-01-28 09:19 98304 O:\Program Files\Saitek\Software\SaiSmart.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSTray]
–a—— 2007-09-20 18:21 132624 T:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zone Labs Client]
–a—— 2005-04-19 18:06 935688 O:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DeltTray]
–a—— 2004-08-27 00:43 56320 O:\WINDOWS\system32\delttray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
–a—— 2006-08-11 21:43 86016 O:\WINDOWS\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
–a—— 2006-08-11 21:43 1519616 O:\WINDOWS\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
–a—— 2004-12-01 03:54 77824 O:\WINDOWS\SOUNDMAN.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"O:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"O:\\Program Files\\Logitech\\Harmony Remote\\PatchHelper.exe"=
"O:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:6\\downloads\\utorrent.exe"=
"O:\Program Files\Microsoft ActiveSync\rapimgr.exe"= O:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"O:\Program Files\Microsoft ActiveSync\wcescomm.exe"= O:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"O:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= O:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"O:\\WINDOWS\\system32\\muzapp.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

R0 Defrag32b;Defrag32Boot;O:\WINDOWS\system32\drivers\Defrag32b.sys [2005-06-28 10:17]
R2 Asapi;Asapi;O:\WINDOWS\system32\drivers\Asapi.sys [2000-05-12 15:48]
R2 cx88xbar;FusionHDTV 88x, WDM Crossbar;O:\WINDOWS\system32\drivers\zl88xbar.sys [2006-08-09 21:25]
R2 Defrag32;Defrag32;O:\WINDOWS\system32\drivers\Defrag32.sys [2005-06-28 10:17]
R2 Zulu88Tune;FusionHDTV 88x, WDM Tuner(LG062F);O:\WINDOWS\system32\drivers\zl88tune.sys [2006-08-09 21:25]
R2 Zulu88Vid;FusionHDTV 88x, WDM Video Capture;O:\WINDOWS\system32\drivers\zl88vcap.sys [2006-08-09 21:25]
R3 CXAVSAUD;FusionHDTV 880, WDM Audio Capture;O:\WINDOWS\system32\drivers\zl88aud.sys [2006-08-09 21:25]
R3 L6DP;L6DP;O:\WINDOWS\system32\Drivers\l6dp.sys [2005-11-14 15:03]
R3 PPJoyBus;Parallel Port Joystick Bus device driver;O:\WINDOWS\system32\drivers\PPJoyBus.sys [2004-10-24 08:11]
R3 PPortJoystick;Parallel Port Joystick device driver;O:\WINDOWS\system32\drivers\PPortJoy.sys [2004-10-24 08:11]
R3 rxpvbus;Reality XP Avionics Bus Driver;O:\WINDOWS\system32\DRIVERS\rxpvbus.sys [2005-08-28 22:04]
R3 USBMN4X4;M-Audio USB MidiSport 4x4;O:\WINDOWS\system32\drivers\usbmn4x4.sys [2005-10-09 18:42]
R3 Zulu88BDA;FusionHDTV 88x, BDA DVB Tuner/Demod;O:\WINDOWS\system32\drivers\zl88bda.sys [2006-08-09 21:25]
R3 Zulu88Ts;FusionHDTV 88x, BDA Receiver(ATSC-A);O:\WINDOWS\system32\drivers\zl88tcap.sys [2006-08-09 21:25]
S2 aspnet_stateseclogon;ASP.NET State Service aspnet_stateseclogon;O:\WINDOWS\system32\12520437v.exe []
S2 InteractiveLogonSysmonLog;InteractiveLogon InteractiveLogonSysmonLog;O:\WINDOWS\system32\1033f.exe []
S2 lanmanworkstationcisvc;Workstation lanmanworkstationcisvc;O:\WINDOWS\system32\activedst.exe []
S2 PDSched;PDScheduler;O:\Program Files\Raxco\PerfectDisk\PDSched.exe [2005-06-28 14:07]
S3 BRGSp50;BRGSp50 NDIS Protocol Driver;O:\WINDOWS\system32\Drivers\BRGSp50.sys [2005-06-08 19:44]
S3 KORGUMDS;KORG USB-MIDI Driver for Windows XP;O:\WINDOWS\system32\Drivers\KORGUMDS.SYS [2004-02-19 01:05]
S3 L6TPortB;Service - Line 6 TonePort UX2;O:\WINDOWS\system32\Drivers\L6TPortB.sys [2005-11-14 15:01]
S3 msvad_multi;Samson Audio (WDM);O:\WINDOWS\system32\drivers\SWAudWDM.sys [2005-11-10 16:58]
S3 NuVision;Hauppauge WinTV USB Pro (NTSC FM);O:\WINDOWS\system32\DRIVERS\NUVision.sys [2005-07-08 16:40]
S3 SaiH0464;SaiH0464;O:\WINDOWS\system32\DRIVERS\SaiH0464.sys [2004-01-30 09:29]
S3 SamsonLLDriver;Samson C01U LL Driver;O:\WINDOWS\system32\Drivers\SamsonLLDriver.sys [2005-11-10 16:58]
S3 SynasUSB;SynasUSB;O:\WINDOWS\system32\drivers\SynasUSB.sys [2002-03-14 14:02]
S3 US224;US224 Driver;O:\WINDOWS\system32\Drivers\US224.sys [2004-07-30 11:49]
S3 US224DL;US224 Firmware Downloader;O:\WINDOWS\system32\Drivers\US224DL.sys [2004-07-30 12:02]
S3 Us224WdmService;US224 Wdm Audio;O:\WINDOWS\system32\Drivers\US224Wdm.sys [2004-07-30 11:49]
S3 USB22LDR;M-Audio USB MidiSport 2x2 Loader;O:\WINDOWS\system32\drivers\usb22ldr.sys [2005-10-10 13:00]
S3 USB44LDR;M-Audio USB MidiSport 4x4 Loader;O:\WINDOWS\system32\drivers\usb44ldr.sys [2005-10-09 18:42]
S3 USBMN2X2;M-Audio USB MidiSport 2x2;O:\WINDOWS\system32\drivers\usbmn2x2.sys [2005-10-10 13:00]
S3 ZD1211BU(Hawking);Hawking Hi-Gain Wireless-G USB Dish Adapter(Hawking);O:\WINDOWS\system32\DRIVERS\zd1211Bu.sys [2005-10-28 12:38]

.
- - - - ORPHANS REMOVED - - - -

SSODL-qegbdmwf-{3353CCE0-239E-49A6-A696-D66C105DE8D9} - O:\WINDOWS\qegbdmwf.dll


**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-03 19:20:04
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet004\Services\AudioSrvSharedAccess]
"ImagePath"="*&€|\14û\06 srv"

[HKEY_LOCAL_MACHINE\System\ControlSet004\Services\srservice Management Service]
"ImagePath"="*&€|\14û\06 srv"
.
———————— Other Running Processes ————————
.
O:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O:\WINDOWS\system32\CTSVCCDA.EXE
O:\WINDOWS\system32\nvsvc32.exe
O:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O:\WINDOWS\system32\ZoneLabs\vsmon.exe
O:\Program Files\Microsoft ActiveSync\rapimgr.exe
.
**************************************************************************
.
Completion time: 2008-07-03 19:24:31 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-03 23:24:29
ComboFix2.txt 2008-07-01 00:10:22

Pre-Run: 6,199,144,448 bytes free
Post-Run: 6,178,672,640 bytes free

233
—————————————————————————————————————

KASPERSKY ONLINE SCANNER 7 REPORT
Friday, July 4, 2008
Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Friday, July 04, 2008 17:05:00
Records in database: 913326


Scan settings
Scan using the following database extended
Scan archives yes
Scan mail databases yes

Scan area Folder
D:\

Scan statistics
Files scanned 18305
Threat name 28
Infected objects 46
Suspicious objects 0
Duration of the scan 00:11:11

File name Threat name Threats count
D:\Documents and Settings\Martin Brien\Local Settings\Temp\bundle_mediamotor1004.exe Infected: not-a-virus:AdWare.Win32.Sahat.aj 1

D:\Documents and Settings\Martin Brien\Local Settings\Temp\HCPBNS3P.dll Infected: not-a-virus:AdWare.Win32.Sahat.w 1

D:\Documents and Settings\Martin Brien\Local Settings\Temp\liqp7c25q_.dll Infected: not-a-virus:AdWare.Win32.Sahat.ad 1

D:\Documents and Settings\Martin Brien\Local Settings\Temp\res1A.tmp Infected: not-a-virus:AdWare.Win32.180Solutions.g 1

D:\Documents and Settings\Martin Brien\Local Settings\Temp\resA0.tmp Infected: not-a-virus:AdWare.Win32.180Solutions.g 1

D:\Documents and Settings\Martin Brien\Local Settings\Temp\setup4021.cab Infected: not-a-virus:AdWare.Win32.Sahat.ad 1

D:\Documents and Settings\Martin Brien\Local Settings\Temp\sp.html Infected: Trojan.JS.StartPage.u 1

D:\Documents and Settings\Martin Brien\Local Settings\Temp\THI1F66.tmp\twaintec.dll Infected: not-a-virus:AdWare.Win32.BiSpy.f 1

D:\Documents and Settings\Martin Brien\Local Settings\Temp\THI863.tmp\dlmax.dll Infected: not-a-virus:AdWare.Win32.DlMax.a 1

D:\Documents and Settings\Martin Brien\Local Settings\Temp\twaintec.dll Infected: not-a-virus:AdWare.Win32.BiSpy.t 1

D:\Documents and Settings\Martin Brien\Local Settings\Temporary Internet Files\Content.IE5\0B7PXVXG\v3cab[1].cab Infected: not-a-virus:AdWare.Win32.EliteBar.aq 1

D:\Documents and Settings\Martin Brien\Local Settings\Temporary Internet Files\Content.IE5\D8GSTKEC\exe82[1].exe Infected: not-a-virus:AdWare.Win32.MediaMotor.i 1

D:\Documents and Settings\Martin Brien\Local Settings\Temporary Internet Files\Content.IE5\HC0Y4D98\bundle_mediamotor1004[1].exe Infected: not-a-virus:AdWare.Win32.Sahat.aj 1

D:\Documents and Settings\Martin Brien\Local Settings\Temporary Internet Files\Content.IE5\HC0Y4D98\pay[1].htm Infected: Trojan-Clicker.JS.Linker.j 1

D:\Documents and Settings\Martin Brien\Local Settings\Temporary Internet Files\Content.IE5\HC0Y4D98\ysb[1].dll Infected: Trojan-Downloader.Win32.IstBar.ms 1

D:\package_MARKETING27.exe Infected: not-a-virus:AdWare.Win32.BargainBuddy.n 1

D:\Program Files\180searchassistant\salmhook.dll Infected: not-a-virus:AdWare.Win32.180Solutions.j 1

D:\Program Files\Media Access\MediaAccC.dll Infected: not-a-virus:AdWare.Win32.WinAD.ao 1

D:\Program Files\Media Access\MediaAccK.exe Infected: not-a-virus:AdWare.Win32.WinAD.an 1

D:\Program Files\Media Gateway\MediaGateway.exe Infected: not-a-virus:AdWare.Win32.WinAD.bj 1

D:\Program Files\Microsoft Antispyware\Quarantine\3591E955-7A50-490E-B578-CC2099\82403E94-AD64-483A-A452-D36DA2 Infected: not-a-virus:AdWare.Win32.WebRebates.b 1

D:\Program Files\Microsoft Antispyware\Quarantine\DC44ECBD-D963-4D50-908D-055A55\B052DD13-EE79-44E7-A619-6DDD90 Infected: not-a-virus:AdWare.Win32.SaveNow.bc 1

D:\Program Files\YourSiteBar\ysb.dll Infected: Trojan-Downloader.Win32.IstBar.ms 1

D:\temp\cdt_bbi8016.exe Infected: not-a-virus:AdWare.Win32.BargainBuddy.j 4

D:\temp\cdt_bbi8016.exe Infected: not-a-virus:AdWare.Win32.BargainBuddy.y 1

D:\temp\FLEOK\msbb.exe Infected: not-a-virus:AdWare.Win32.180Solutions 1

D:\temp\msbb.exe Infected: not-a-virus:AdWare.Win32.180Solutions 1

D:\temp\msbbhook.dll Infected: not-a-virus:AdWare.Win32.180Solutions 1

D:\temp\WebRebates_CDT_InstallSilent.exe Infected: not-a-virus:AdWare.Win32.WebRebates.g 1

D:\temp\WebRebates_CDT_InstallSilent.exe Infected: not-a-virus:AdWare.Win32.WebRebates.a 3

D:\WINDOWS\bundle_mediamotor1004.exe Infected: not-a-virus:AdWare.Win32.Sahat.aj 1

D:\WINDOWS\dlmax.dll Infected: not-a-virus:AdWare.Win32.DlMax.a 1

D:\WINDOWS\Downloaded Program Files\ClientAX.dll Infected: not-a-virus:AdWare.Win32.180Solutions.g 1

D:\WINDOWS\exe82.exe.bak Infected: not-a-virus:AdWare.Win32.MediaMotor.i 1

D:\WINDOWS\system32\exdl.exe Infected: not-a-virus:AdWare.Win32.BargainBuddy.j 1

D:\WINDOWS\system32\exul.exe Infected: not-a-virus:AdWare.Win32.BargainBuddy.j 1

D:\WINDOWS\system32\i Infected: Trojan-Downloader.BAT.Ftp.ab 1

D:\WINDOWS\twaintec.dl$ Infected: not-a-virus:AdWare.Win32.BiSpy.t 1

D:\WINDOWS\_default.pif Infected: Trojan-Downloader.Win32.WinShow.ak 1

D:\WINDOWS\_default.pif Infected: Trojan-Downloader.Win32.Agent.an 1

D:\WINDOWS\_default.pif Infected: Trojan-Downloader.Win32.Agent.bq 1

The selected area was scanned.


KASPERSKY ONLINE SCANNER 7 REPORT
Friday, July 4, 2008
Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Friday, July 04, 2008 17:05:00
Records in database: 913326


Scan settings
Scan using the following database extended
Scan archives yes
Scan mail databases yes

Scan area Folder
G:\

Scan statistics
Files scanned 34449
Threat name 1
Infected objects 2
Suspicious objects 0
Duration of the scan 00:12:46

File name Threat name Threats count
G:\System Volume Information\_restore{750D7422-8E23-4850-BE00-44F060F917F1}\RP172\A0061180.exe Infected: Trojan-Downloader.Win32.Wren.i 1

G:\System Volume Information\_restore{750D7422-8E23-4850-BE00-44F060F917F1}\RP172\A0061181.exe Infected: Trojan-Downloader.Win32.Wren.i 1

The selected area was scanned.

KASPERSKY ONLINE SCANNER 7 REPORT
Friday, July 4, 2008
Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Friday, July 04, 2008 17:05:00
Records in database: 913326


Scan settings
Scan using the following database extended
Scan archives yes
Scan mail databases yes

Scan area Folder
K:\

Scan statistics
Files scanned 93214
Threat name 4
Infected objects 9
Suspicious objects 0
Duration of the scan 00:44:05

File name Threat name Threats count
K:\System Volume Information\_restore{750D7422-8E23-4850-BE00-44F060F917F1}\RP172\A0061182.exe Infected: Trojan-Downloader.Win32.INService.bl 1

K:\System Volume Information\_restore{750D7422-8E23-4850-BE00-44F060F917F1}\RP172\A0061183.exe Infected: Trojan-Downloader.Win32.INService.gen 1

K:\Utils\win\kf141\keyfinder.exe Infected: not-a-virus:PSWTool.Win32.RAS.a 2

K:\Utils\win\Windows_XP_Service_Pack_2_by_Unknown_www.crack.cd_\WinXP keyChanger.exe Infected: not-a-virus:PSWTool.Win32.RAS.a 2

K:\Utils\win\keyfinder.exe Infected: not-a-virus:PSWTool.Win32.RAS.a 2

K:\dreamfleet\dfa36R2.exe Infected: not-a-virus:AdWare.Win32.EShoper.p 1

The selected area was scanned.

KASPERSKY ONLINE SCANNER 7 REPORT
Thursday, July 3, 2008
Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Thursday, July 03, 2008 17:13:27
Records in database: 910775


Scan settings
Scan using the following database extended
Scan archives yes
Scan mail databases yes

Scan area Folder
O:\

Scan statistics
Files scanned 46030
Threat name 3
Infected objects 6
Suspicious objects 0
Duration of the scan 00:52:43

File name Threat name Threats count
O:\QooBox\Quarantine\O\WINDOWS\pntqkflv.dll.vir Infected: Trojan.Win32.Vapsup.hhr 1

O:\QooBox\Quarantine\O\WINDOWS\system32\spywarewarning.mht.vir Infected: not-virus:Hoax.Win32.SysCare.h 1

O:\WINDOWS\sp1 tools\kf141\keyfinder.exe Infected: not-a-virus:PSWTool.Win32.RAS.a 2

O:\WINDOWS\sp1 tools\Windows_XP_Service_Pack_2_by_Unknown_www.crack.cd_\WinXP keyChanger.exe Infected: not-a-virus:PSWTool.Win32.RAS.a 2

The selected area was scanned.


———————————————————————————–

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:17, on 7/7/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
O:\WINDOWS\System32\smss.exe
O:\WINDOWS\system32\winlogon.exe
O:\WINDOWS\system32\services.exe
O:\WINDOWS\system32\lsass.exe
O:\WINDOWS\system32\svchost.exe
O:\WINDOWS\System32\svchost.exe
O:\WINDOWS\system32\svchost.exe
O:\WINDOWS\system32\spoolsv.exe
O:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O:\WINDOWS\system32\CTsvcCDA.exe
O:\WINDOWS\system32\nvsvc32.exe
O:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O:\WINDOWS\System32\Fast.exe
O:\WINDOWS\Explorer.EXE
O:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
O:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
O:\Program Files\Microsoft ActiveSync\wcescomm.exe
O:\PROGRA~1\MICROS~2\rapimgr.exe
O:\Program Files\Hawking\HWU8DD\HWU8DD.exe
O:\WINDOWS\Explorer.EXE
O:\WINDOWS\system32\wscntfy.exe
V:\Downloads\win\30jun08\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=…6Ojg5&lid;=2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - O:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - O:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE O:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [avgnt] "O:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [SunJavaUpdateSched] "O:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKCU\..\Run: [H/PC Connection Agent] "O:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - O:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - O:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - O:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - O:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - O:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - O:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - O:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl.sun.com/webapps/download/AutoDL?BundleId=21871
O18 - Protocol: bw+0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: offline-8876480 - {5A1DE887-E72A-43E4-B075-D09B4A808EC3} - O:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - O:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - O:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: ASP.NET State Service aspnet_stateseclogon (aspnet_stateseclogon) - Unknown owner - O:\WINDOWS\system32\12520437v.exe (file missing)
O23 - Service: Windows Audio AudioSrvSharedAccess (AudioSrvSharedAccess) - Unknown owner - *&€|û.exe (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - O:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - O:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InteractiveLogon InteractiveLogonSysmonLog (InteractiveLogonSysmonLog) - Unknown owner - O:\WINDOWS\system32\1033f.exe (file missing)
O23 - Service: Workstation lanmanworkstationcisvc (lanmanworkstationcisvc) - Unknown owner - O:\WINDOWS\system32\activedst.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - O:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PDEngine - Raxco Software, Inc. - O:\Program Files\Raxco\PerfectDisk\PDEngine.exe
O23 - Service: PDScheduler (PDSched) - Raxco Software, Inc. - O:\Program Files\Raxco\PerfectDisk\PDSched.exe
O23 - Service: System Restore Service srservice Management Service (srservice Management Service) - Unknown owner - *&€|û.exe (file missing)
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - O:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - O:\WINDOWS\system32\ZoneLabs\vsmon.exe

–
End of file - 17062 bytes
——————————————————————————–
——————————————————————————–
Hi

  • Please download this tool from Microsoft.
  • Double click on MGADiag.exe to run it.
  • Click Continue.
  • The program will run. It takes a while to finish the diagnosis, please be patient.
  • Once done, click on Copy.
  • Open Notepad and paste the contents in. Save this file and post it in your next reply.
Hello and thanks again for all your help. —————————————————————————————— This appears to be the end of this thread since you have asked to check on the os key which will be reported as blocked. I understand that this website cannot support systems that it knows do not pass the MS genuine test. I appreciate the time you have saved me and have made a donation to the website. ——————————————————————————————— For the record, I would also like to remind readers that many, if not perhaps most, of the personal computer users with blocked keys are not unethical people. The fact is that the MS system for licensing is not perfect, any many users are faced with the dilemma of re-purchasing a license or using ones obtained by dubious means. This has caused some people to have a sour attitude about the company (you think??). I own MS stock, and it seems to still be ok. [My sob story (violins please!) is that the computer that I enlisted help with dates back more than 10 years ago to a Win98 system. I purchased a WinXP Pro upgrade from my local computer store (I think it was $200). Some years later, I re-formated the disk to allow multi-boot with linux and was not able to get support from Microsoft to continue to use the key on the CD case. I then decided to use an unauthorized key, rather than re-purchase another license. Now, many years later, MS seems to have a better process for key re-authorization. However, I am reluctant to use it, since I am worried that if the system becomes inoperable, the standard MS support policy of reformat and reinstall will be my only recourse. And that is the reason why people come to websites like What The Tech in the first place!]
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI