"Dan Sunesen" - 07-05-01 10:16:14 Service Pack 2
ComboFix 07-04-25.4V - Running from: "C:\Documents and Settings\Dan Sunesen\Skrivebord\"
((((((((((((((((((((((((((((((( Files Created from 2007-04-01 to 2007-05-01 ))))))))))))))))))))))))))))))))))
2007-04-27 23:20 <DIR> d-a------ C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
2007-04-27 23:16 614,400 --a------ C:\WINDOWS\system32\ExButton.dll
2007-04-27 23:16 585,728 --a------ C:\WINDOWS\system32\ExMenu.dll
2007-04-27 23:16 507,904 --a------ C:\WINDOWS\system32\ExTab.dll
2007-04-27 23:16 368,912 --a------ C:\WINDOWS\system32\vbar332.dll
2007-04-27 23:16 356,352 --a------ C:\WINDOWS\system32\eSellerateEngine.dll
2007-04-27 23:16 307,200 --a------ C:\WINDOWS\system32\ExPMenu.dll
2007-04-27 23:16 118,784 --a------ C:\WINDOWS\system32\eWebControl.dll
2007-04-27 23:16 1,658,880 --a------ C:\WINDOWS\system32\ExGrid.dll
2007-04-27 23:16 <DIR> d-------- C:\Programmer\F‘lles filer\eSellerate
2007-04-27 23:15 <DIR> d-------- C:\Programmer\AnswersThatWork
2007-04-27 14:38 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com
2007-04-27 13:55 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-04-19 17:37 208,896 --a------ C:\WINDOWS\system32\NVUNINST.EXE
2007-04-14 13:59 <DIR> d-------- C:\Programmer\LimeWire
2007-04-12 23:12 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-04-28 14:42 -------- d-------- C:\Programmer\superantispyware
2007-04-28 11:35 -------- d-------- C:\Programmer\mirc
2007-04-28 00:04 -------- d-------- C:\Programmer\spywareblaster
2007-04-28 00:03 -------- d-------- C:\Programmer\regcleaner
2007-04-27 23:28 -------- d-------- C:\Programmer\spywareguard
2007-04-19 17:36 -------- d-------- C:\Programmer\nvidia
2007-04-17 21:17 -------- d-------- C:\Programmer\winamp
2007-04-08 20:57 -------- d-------- C:\Programmer\msn messenger
2007-04-08 20:14 75280 --a------ C:\WINDOWS\system32\isafprod.dll
2007-04-08 20:14 32528 --a------ C:\WINDOWS\system32\drivers\vetmonnt.sys
2007-04-08 20:14 26640 --a------ C:\WINDOWS\system32\drivers\vet-filt.sys
2007-04-08 20:14 21648 --a------ C:\WINDOWS\system32\drivers\vetfddnt.sys
2007-04-08 20:14 21392 --a------ C:\WINDOWS\system32\drivers\vet-rec.sys
2007-03-27 11:12 61344 --a------ C:\WINDOWS\system32\perfc006.dat
2007-03-27 11:12 367738 --a------ C:\WINDOWS\system32\perfh006.dat
2007-03-27 09:55 524288 --a------ C:\WINDOWS\system32\divxsm.exe
2007-03-27 09:55 36624 --------- C:\WINDOWS\system32\drivers\PxHelp20.sys
2007-03-27 09:55 3596288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2007-03-27 09:55 200704 --a------ C:\WINDOWS\system32\ssldivx.dll
2007-03-27 09:55 129784 --------- C:\WINDOWS\system32\pxafs.dll
2007-03-27 09:55 118520 --------- C:\WINDOWS\system32\pxinsi64.exe
2007-03-27 09:55 116472 --------- C:\WINDOWS\system32\pxcpyi64.exe
2007-03-27 09:55 1044480 --a------ C:\WINDOWS\system32\libdivx.dll
2007-03-27 09:49 73728 --a------ C:\WINDOWS\system32\dpl100.dll
2007-03-27 09:49 593920 --a------ C:\WINDOWS\system32\dpugui11.dll
2007-03-27 09:49 57344 --a------ C:\WINDOWS\system32\dpv11.dll
2007-03-27 09:49 53248 --a------ C:\WINDOWS\system32\dpugui10.dll
2007-03-27 09:49 344064 --a------ C:\WINDOWS\system32\dpus11.dll
2007-03-27 09:49 294912 --a------ C:\WINDOWS\system32\dpu11.dll
2007-03-27 09:49 294912 --a------ C:\WINDOWS\system32\dpu10.dll
2007-03-27 09:49 196608 --a------ C:\WINDOWS\system32\dtu100.dll
2007-03-27 09:48 823296 --a------ C:\WINDOWS\system32\divx_xx0c.dll
2007-03-27 09:48 823296 --a------ C:\WINDOWS\system32\divx_xx07.dll
2007-03-27 09:48 802816 --a------ C:\WINDOWS\system32\divx_xx11.dll
2007-03-27 09:48 639066 --a------ C:\WINDOWS\system32\divx.dll
2007-03-17 15:45 292864 --a------ C:\WINDOWS\system32\winsrv.dll
2007-03-08 17:38 577536 --a------ C:\WINDOWS\system32\user32.dll
2007-03-08 17:38 40960 --a------ C:\WINDOWS\system32\mf3216.dll
2007-03-08 17:38 281600 --a------ C:\WINDOWS\system32\gdi32.dll
2007-03-08 17:35 1843584 --a------ C:\WINDOWS\system32\win32k.sys
2007-02-16 03:40 124472 --a------ C:\WINDOWS\system32\divxcodecupdatechecker.exe
2007-02-05 22:19 185344 --a------ C:\WINDOWS\system32\upnphost.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{AA58ED58-01DD-4d91-8333-CF10577473F7} c:\windows\downloaded program files\googletoolbar3.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"CoolSwitch"="C:\\WINDOWS\\system32\\taskswitch.exe"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"LVCOMSX"="C:\\WINDOWS\\system32\\LVCOMSX.EXE"
"LogitechVideoTray"="C:\\Programmer\\Logitech\\Video\\LogiTray.exe"
"cctray"="\"C:\\Programmer\\CA\\CA Internet Security Suite\\cctray\\cctray.exe\""
"CAVRID"="\"C:\\Programmer\\CA\\CA Internet Security Suite\\CA Anti-Virus\\CAVRID.exe\""
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit"
"!AVG Anti-Spyware"="\"C:\\Programmer\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"MsnMsgr"="\"C:\\Programmer\\MSN Messenger\\MsnMsgr.Exe\" /background"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"SUPERAntiSpyware"="C:\\Programmer\\SUPERAntiSpyware\\SUPERAntiSpyware.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=""
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages REG_MULTI_SZ msv1_0\0\0
Security Packages REG_MULTI_SZ kerberos\0msv1_0\0schannel\0wdigest\0\0
Notification Packages REG_MULTI_SZ scecli\0\0
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^Adobe Reader Hurtigstart.lnk]
"path"="C:\\Documents and Settings\\All Users\\Menuen Start\\Programmer\\Start\\Adobe Reader Hurtigstart.lnk"
"backup"="C:\\WINDOWS\\pss\\Adobe Reader Hurtigstart.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\Adobe\\ACROBA~1.0\\Reader\\READER~1.EXE "
"item"="Adobe Reader Hurtigstart"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\H]
Shell\AutoRun\command H:\autoplay.exe
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\I]
Shell\AutoRun\command I:\SETUP.EXE
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\J]
Shell\AutoRun\command J:\autoplay.exe
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e476817e-ff5b-11d9-9701-0050bf77a9b3}]
Shell\AutoRun\command H:\autoplay.exe
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e476817f-ff5b-11d9-9701-0050bf77a9b3}]
Shell\AutoRun\command I:\autoplay.exe
~ ~ ~ ~ ~ ~ ~ ~ Hijackthis Backups ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
backup-20070428-194240-463
O3 - Toolbar: (no name) - {37B85A29-692B-4205-9CAD-2626E4993404} - (no file)
backup-20070428-194240-703
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
backup-20060429-223000-598
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Programmer\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
backup-20050813-130048-809
O18 - Protocol: bwz0s - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-657
O18 - Filter: text/html - (no CLSID) - (no file)
backup-20050813-130048-582
O23 - Service: Mramansup - McAfee Corporation - (no file)
backup-20050813-130048-916
O18 - Protocol: bwy0s - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-337
O18 - Protocol: bwz0 - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-291
O18 - Protocol: bwy0 - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-114
O18 - Protocol: bww0s - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-349
O18 - Protocol: bwx0s - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-815
O18 - Protocol: bwv0s - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-996
O18 - Protocol: bwx0 - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-107
O18 - Protocol: bwu0s - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-751
O18 - Protocol: bwv0 - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-629
O18 - Protocol: bwu0 - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-893
O18 - Protocol: bww0 - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-699
O18 - Protocol: bws0s - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-223
O18 - Protocol: bwt0 - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-962
O18 - Protocol: bws0 - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-653
O18 - Protocol: bwt0s - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-208
O18 - Protocol: bwr0s - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-949
O18 - Protocol: bwr0 - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-725
O18 - Protocol: bwn0 - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-755
O18 - Protocol: bwo0s - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-314
O18 - Protocol: bwn0s - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-303
O18 - Protocol: bwp0 - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-857
O18 - Protocol: bwq0s - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-359
O18 - Protocol: bwo0 - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-659
O18 - Protocol: bwq0 - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-391
O18 - Protocol: bwp0s - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-881
O18 - Protocol: bwm0 - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-400
O18 - Protocol: bwl0s - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-507
O18 - Protocol: bwk0s - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-561
O18 - Protocol: bwl0 - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-173
O18 - Protocol: bwm0s - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-436
O18 - Protocol: bwk0 - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-121
O18 - Protocol: bwi0s - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-954
O18 - Protocol: bwj0 - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-117
O18 - Protocol: bwh0s - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-982
O18 - Protocol: bwi0 - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-468
O18 - Protocol: bwh0 - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-940
O18 - Protocol: bwj0s - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-404
O18 - Protocol: bwg0 - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-372
O18 - Protocol: bwg0s - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-220
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
backup-20050813-130048-125
O18 - Protocol: bwf0 - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-611
O18 - Protocol: bwf0s - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-865
O18 - Protocol: bwe0 - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-235
O18 - Protocol: bwe0s - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-478
O18 - Protocol: bwd0s - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-129
O18 - Protocol: bwa0 - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-412
O18 - Protocol: bwb0s - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-222
O18 - Protocol: bwb0 - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-312
O18 - Protocol: bwc0 - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-600
O18 - Protocol: bwa0s - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-180
O18 - Protocol: bwd0 - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-878
O18 - Protocol: bwc0s - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-980
O18 - Protocol: bw90 - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-843
O18 - Protocol: bw90s - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-184
O18 - Protocol: bw80s - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-774
O18 - Protocol: bw80 - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-973
O18 - Protocol: bw60s - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-915
O18 - Protocol: bw70 - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-433
O18 - Protocol: bw60 - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-353
O18 - Protocol: bw70s - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-551
O18 - Protocol: bw50s - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-663
O18 - Protocol: bw50 - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-891
O18 - Protocol: bw40s - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-393
O18 - Protocol: bw40 - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-626
O18 - Protocol: bw30s - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-981
O18 - Protocol: bw20 - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-897
O18 - Protocol: bw30 - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-562
O18 - Protocol: bw20s - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-464
O18 - Protocol: bw10 - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-705
O18 - Protocol: bw10s - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-324
O18 - Protocol: bw00s - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-971
O18 - Protocol: bw+0 - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-587
O18 - Protocol: bw00 - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-832
O18 - Protocol: bw-0s - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-839
O18 - Protocol: bw-0 - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130048-170
O18 - Protocol: bw+0s - {4C1F47C9-02B2-4B13-8F73-C04E9307E962} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
backup-20050813-130047-473
O2 - BHO: {92E1B3F7-0546-421E-9835-904D25B7BA66} - {C4F147D7-BF25-488E-A12B-EFD43E7029BF} - C:\WINDOWS\system32\winvbie.dll
backup-20050813-130047-263
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *hot-searches.com*;*lender-search.com*;localhost
backup-20050813-130047-297
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
backup-20050813-130047-659
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
backup-20050813-130047-442
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
********************************************************************
catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer,
http://www.gmer.netRootkit scan 2007-05-01 10:24:11
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
********************************************************************
Completion time: 07-05-01 10:24:23
C:\ComboFix-quarantined-files.txt ... 07-05-01 10:24