Thanks for getting back to me,
Here are my results:
SDFix: Version 1.192
Run by Trish on 2008-06-16 at 12:16
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\DOCUME~1\Trish\Desktop\SDFix
Checking Services :
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting
Checking Files :
Trojan Files Found:
C:\DOCUME~1\TRISH\APPLIC~1\MICROS~1\WINDOWS\WPBBXB.EXE - Deleted
C:\Documents and Settings\Trish\Application Data\SpeedRunner\SpeedRunner.exe - Deleted
Folder C:\Documents and Settings\Trish\Application Data\SpeedRunner - Removed
Removing Temp Files
ADS Check :
Final Check :
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-06-16 12:33:43
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\WINDOWS\system32\__c006283F.dat"
"DeviceNotSelectedTimeout"="15"
"GDIProcessHandleQuota"=dword:00002710
"Spooler"="yes"
"swapdisk"=""
"TransmissionRetryTimeout"="90"
"USERProcessHandleQuota"=dword:00002710
"LoadAppInit_DLLs"=dword:00000001
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services :
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe:*:Disabled:Logitech Desktop Messenger"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\Program Files\\Sharp\\Sharpdesk\\sdFTP.exe"="C:\\Program Files\\Sharp\\Sharpdesk\\sdFTP.exe:*:Enabled:sdFTP"
"C:\\Documents and Settings\\Trish\\Local Settings\\Temp\\is-B9D2R.tmp\\ServUSetup.tmp"="C:\\Documents and Settings\\Trish\\Local Settings\\Temp\\is-B9D2R.tmp\\ServUSetup.tmp:*:Enabled:Setup/Uninstall"
"C:\\Program Files\\Network Associates\\Common Framework\\FrameworkService.exe"="C:\\Program Files\\Network Associates\\Common Framework\\FrameworkService.exe:*:Disabled:Framework Service"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
Remaining Files :
File Backups: - C:\DOCUME~1\Trish\Desktop\SDFix\backups\backups.zip
Files with Hidden Attributes :
Mon 28 Jan 2008 1,404,240 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe"
Mon 28 Jan 2008 5,146,448 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
Mon 28 Jan 2008 2,097,488 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
Mon 30 Dec 2002 27,136 A..H. --- "C:\WINDOWS\Templates\~WRL2063.tmp"
Wed 21 Jul 2004 41,984 A..H. --- "C:\WINDOWS\Templates\~WRL3167.tmp"
Thu 12 Apr 2007 121,344 ...H. --- "C:\Documents and Settings\Trish\My Documents\~WRL1233.tmp"
Wed 1 Feb 2006 40,960 A..H. --- "C:\WINDOWS\Templates\Rams\~WRL2508.tmp"
Mon 30 Dec 2002 27,136 A..H. --- "C:\Documents and Settings\Administrator\Templates\Templates\~WRL2063.tmp"
Wed 21 Jul 2004 41,984 A..H. --- "C:\Documents and Settings\Administrator\Templates\Templates\~WRL3167.tmp"
Tue 17 Apr 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Sat 13 Nov 2004 37,376 ...H. --- "C:\Program Files\Common Files\Adobe\ESD\DLMCleanup.exe"
Thu 13 Dec 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\b04031f0b83ee952189dd8beb4ee929a\BIT5A.tmp"
Wed 7 May 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\fd0264849c01086f3c6b505dc02dbd44\BIT15B.tmp"
Wed 1 Feb 2006 40,960 A..H. --- "C:\Documents and Settings\Administrator\Templates\Templates\Rams\~WRL2508.tmp"
Thu 15 Nov 2007 3,231,232 ...H. --- "C:\Documents and Settings\Trish\Application Data\Microsoft\Word\~WRL0053.tmp"
Thu 15 Nov 2007 5,478,400 ...H. --- "C:\Documents and Settings\Trish\Application Data\Microsoft\Word\~WRL0125.tmp"
Mon 18 Jun 2007 120,320 ...H. --- "C:\Documents and Settings\Trish\Application Data\Microsoft\Word\~WRL0372.tmp"
Thu 15 Nov 2007 3,225,600 ...H. --- "C:\Documents and Settings\Trish\Application Data\Microsoft\Word\~WRL0409.tmp"
Thu 15 Nov 2007 3,232,256 ...H. --- "C:\Documents and Settings\Trish\Application Data\Microsoft\Word\~WRL0421.tmp"
Tue 12 Feb 2008 60,928 ...H. --- "C:\Documents and Settings\Trish\Application Data\Microsoft\Word\~WRL0442.tmp"
Mon 18 Jun 2007 119,296 ...H. --- "C:\Documents and Settings\Trish\Application Data\Microsoft\Word\~WRL0872.tmp"
Mon 18 Jun 2007 113,664 ...H. --- "C:\Documents and Settings\Trish\Application Data\Microsoft\Word\~WRL1174.tmp"
Tue 17 Jul 2007 35,328 ...H. --- "C:\Documents and Settings\Trish\Application Data\Microsoft\Word\~WRL1259.tmp"
Fri 13 Apr 2007 130,560 ...H. --- "C:\Documents and Settings\Trish\Application Data\Microsoft\Word\~WRL1381.tmp"
Thu 30 Aug 2007 13,874,688 ...H. --- "C:\Documents and Settings\Trish\Application Data\Microsoft\Word\~WRL1421.tmp"
Mon 18 Jun 2007 115,712 ...H. --- "C:\Documents and Settings\Trish\Application Data\Microsoft\Word\~WRL1767.tmp"
Fri 19 Oct 2007 61,952 ...H. --- "C:\Documents and Settings\Trish\Application Data\Microsoft\Word\~WRL1784.tmp"
Mon 18 Jun 2007 124,928 ...H. --- "C:\Documents and Settings\Trish\Application Data\Microsoft\Word\~WRL1858.tmp"
Mon 18 Jun 2007 124,416 ...H. --- "C:\Documents and Settings\Trish\Application Data\Microsoft\Word\~WRL1881.tmp"
Thu 15 Nov 2007 3,231,232 ...H. --- "C:\Documents and Settings\Trish\Application Data\Microsoft\Word\~WRL1915.tmp"
Mon 18 Feb 2008 66,048 ...H. --- "C:\Documents and Settings\Trish\Application Data\Microsoft\Word\~WRL2046.tmp"
Thu 15 Nov 2007 3,225,088 ...H. --- "C:\Documents and Settings\Trish\Application Data\Microsoft\Word\~WRL2062.tmp"
Wed 24 Oct 2007 69,632 ...H. --- "C:\Documents and Settings\Trish\Application Data\Microsoft\Word\~WRL2266.tmp"
Thu 30 Aug 2007 13,874,176 ...H. --- "C:\Documents and Settings\Trish\Application Data\Microsoft\Word\~WRL2467.tmp"
Mon 18 Jun 2007 116,736 ...H. --- "C:\Documents and Settings\Trish\Application Data\Microsoft\Word\~WRL2726.tmp"
Mon 18 Jun 2007 116,736 ...H. --- "C:\Documents and Settings\Trish\Application Data\Microsoft\Word\~WRL2895.tmp"
Thu 15 Nov 2007 6,288,384 ...H. --- "C:\Documents and Settings\Trish\Application Data\Microsoft\Word\~WRL2938.tmp"
Mon 16 Jul 2007 28,160 ...H. --- "C:\Documents and Settings\Trish\Application Data\Microsoft\Word\~WRL3059.tmp"
Fri 19 Oct 2007 68,608 ...H. --- "C:\Documents and Settings\Trish\Application Data\Microsoft\Word\~WRL3081.tmp"
Mon 18 Jun 2007 113,664 ...H. --- "C:\Documents and Settings\Trish\Application Data\Microsoft\Word\~WRL3174.tmp"
Thu 15 Nov 2007 4,680,704 ...H. --- "C:\Documents and Settings\Trish\Application Data\Microsoft\Word\~WRL3406.tmp"
Thu 30 Aug 2007 13,873,664 ...H. --- "C:\Documents and Settings\Trish\Application Data\Microsoft\Word\~WRL3557.tmp"
Fri 19 Oct 2007 62,464 ...H. --- "C:\Documents and Settings\Trish\Application Data\Microsoft\Word\~WRL3667.tmp"
Thu 17 May 2007 64,512 ...H. --- "C:\Documents and Settings\Trish\Application Data\Microsoft\Word\~WRL3913.tmp"
Finished!
ComboFix 08-06-15.2 - Trish 2008-06-16 12:51:09.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.518 [GMT 10:00]
Running from: C:\Documents and Settings\Trish\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Trish\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
C:\Documents and Settings\Trish\Local Settings\Temporary Internet Files\bestwiner.stt
C:\Documents and Settings\Trish\Local Settings\Temporary Internet Files\CPV.stt
.
---- Previous Run -------
.
C:\Program Files\ISM
C:\Program Files\ISM\ism.exe
C:\Program Files\ISM\Uninstall.exe
C:\Program Files\JavaCore
C:\Program Files\JavaCore\UnInstall.exe
C:\Program Files\QdrPack
C:\Program Files\QdrPack\bostrupd.exe
C:\Program Files\QdrPack\QdrPack16.exe
C:\Program Files\QdrPack\QdrPack17.exe
C:\Program Files\QdrPack\trgtys.gz
C:\Program Files\QdrPack\wadsvupd.exe
C:\Program Files\Spcron
C:\Program Files\Spcron\Spc.dll
C:\Program Files\Svconr
C:\Program Files\Temporary
C:\WINDOWS\cookies.ini
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\Cache
C:\WINDOWS\system32\mcrh.tmp
.
((((((((((((((((((((((((( Files Created from 2008-05-16 to 2008-06-16 )))))))))))))))))))))))))))))))
.
2008-06-16 12:07 . 2008-06-16 12:07 <DIR> d-------- C:\WINDOWS\ERUNT
2008-06-16 09:11 . 2008-06-14 01:37 <DIR> d-------- C:\SDFix
2008-06-16 08:46 . 2008-06-16 08:46 0 --a------ C:\WINDOWS\nsreg.dat
2008-06-12 08:21 . 2008-06-12 08:21 <DIR> d-------- C:\Program Files\iCheck
2008-06-12 08:21 . 2008-06-12 08:21 <DIR> d-------- C:\Program Files\GetPack
2008-06-12 08:21 . 2008-06-16 09:07 <DIR> d-------- C:\Program Files\GetModule
2008-06-10 14:01 . 2008-06-10 14:01 <DIR> d-------- C:\Documents and Settings\Trish\Application Data\MSN6
2008-06-10 14:01 . 2008-06-10 14:01 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\MSN6
2008-06-10 13:27 . 2008-06-10 13:27 <DIR> d-------- C:\Program Files\Trend Micro
2008-06-10 13:14 . 2008-06-10 13:14 <DIR> d-------- C:\Deckard
2008-06-10 13:10 . 1999-12-21 07:58 21,312 --a------ C:\WINDOWS\choice.exe
2008-06-10 13:09 . 2008-06-10 13:09 <DIR> d-------- C:\ie-spyad
2008-06-10 13:07 . 2008-06-10 13:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\TEMP
2008-06-10 13:03 . 2008-06-10 13:08 <DIR> d-------- C:\Program Files\SpywareBlaster
2008-06-10 13:03 . 2005-08-25 18:19 115,920 --a------ C:\WINDOWS\system32\MSINET.OCX
2008-06-10 09:33 . 2008-06-10 10:11 243 --a------ C:\WINDOWS\wininit.ini
2008-06-10 09:00 . 2008-06-10 08:58 691,545 --a------ C:\WINDOWS\unins000.exe
2008-06-10 09:00 . 2008-06-10 09:00 2,539 --a------ C:\WINDOWS\unins000.dat
2008-06-10 08:56 . 2008-06-10 09:02 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-06-10 08:56 . 2008-06-10 09:05 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-06-06 10:31 . 2008-06-06 10:31 <DIR> d-------- C:\Program Files\Panda Security
2008-06-05 11:22 . 2008-06-05 11:22 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\Softland
2008-06-05 11:20 . 2008-06-05 11:20 <DIR> d-------- C:\Program Files\Softland
2008-06-05 11:20 . 2008-06-04 12:58 22,168 --a------ C:\WINDOWS\system32\novamns5.dll
2008-06-05 11:20 . 2008-06-04 12:58 18,584 --a------ C:\WINDOWS\system32\novamis5.dll
2008-06-05 11:20 . 2008-03-27 15:42 7,477 --a------ C:\WINDOWS\system32\novas5.ctm
2008-06-05 11:00 . 2008-06-05 11:00 <DIR> d-------- C:\Program Files\Jasc Software Inc
2008-06-05 10:41 . 2008-06-05 11:14 527 --a------ C:\WINDOWS\PDFWatermark.INI
2008-06-05 10:40 . 2008-06-05 10:40 72,192 --a------ C:\WINDOWS\cadkasdeinst01e.exe
2008-06-04 08:52 . 2008-06-04 08:52 268 --ah----- C:\sqmdata13.sqm
2008-06-04 08:52 . 2008-06-04 08:52 244 --ah----- C:\sqmnoopt13.sqm
2008-06-03 08:39 . 2008-06-03 08:39 268 --ah----- C:\sqmdata12.sqm
2008-06-03 08:39 . 2008-06-03 08:39 244 --ah----- C:\sqmnoopt12.sqm
2008-05-28 21:02 . 2008-05-28 18:02 74,240 --------- C:\WINDOWS\b156.exe_old
2008-05-27 15:28 . 2008-06-05 11:16 1,024 --a------ C:\WINDOWS\system32\winpdfstamp.dat
2008-05-26 08:44 . 2003-02-28 18:26 139,536 --a------ C:\WINDOWS\system32\javaee.dll
2008-05-22 12:23 . 2008-05-22 12:23 <DIR> d--h----- C:\WINDOWS\system32\GroupPolicy
2008-05-22 12:16 . 2008-05-22 12:16 <DIR> d-------- C:\Documents and Settings\Trish\Application Data\RhinoSoft.com
2008-05-22 11:41 . 2008-05-22 11:41 <DIR> d-------- C:\Program Files\Active Ports
2008-05-22 11:41 . 1999-12-17 10:13 49,664 --a------ C:\WINDOWS\unvise32.exe
2008-05-22 11:03 . 2008-05-22 11:03 <DIR> d-------- C:\WINDOWS\IIS Temporary Compressed Files
2008-05-22 11:01 . 2006-02-28 22:00 169,984 --a--c--- C:\WINDOWS\system32\dllcache\iisui.dll
2008-05-22 11:00 . 2008-05-22 11:03 <DIR> d-------- C:\Inetpub
2008-05-22 10:27 . 2008-05-22 10:27 <DIR> d-------- C:\Program Files\Common Files\Sharp Shared
2008-05-22 10:26 . 2000-06-20 11:59 32,768 --a------ C:\WINDOWS\wangimg.exe
2008-05-22 10:26 . 2000-06-20 11:59 32,768 --a------ C:\WINDOWS\kodakimg.exe
2008-05-22 10:25 . 2008-05-22 10:25 <DIR> d-------- C:\Program Files\Sharp
2008-05-22 10:24 . 2008-05-22 10:24 <DIR> d-------- C:\Documents and Settings\Trish\WINDOWS
2008-05-20 08:37 . 2008-05-20 08:37 268 --ah----- C:\sqmdata11.sqm
2008-05-20 08:37 . 2008-05-20 08:37 244 --ah----- C:\sqmnoopt11.sqm
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-06 02:31 --------- d-----w C:\Program Files\GetRight
2008-05-22 00:27 155,995 ----a-w C:\WINDOWS\java\Packages\XBHJPFTF.ZIP
2008-05-05 22:59 737,280 ----a-w C:\WINDOWS\iun6002.exe
2008-05-05 22:52 --------- d-----w C:\Program Files\WinPcap
2007-08-28 04:48 58,952 -c--a-w C:\Documents and Settings\Administrator\MsgPlusLoader.dll
2007-08-28 04:48 40,960 -c--a-w C:\Documents and Settings\Administrator\RichEdHook.dll
2007-08-28 04:48 4,096 -c--a-w C:\Documents and Settings\Administrator\Detoured.dll
2007-08-28 04:48 344,064 -c--a-w C:\Documents and Settings\Administrator\Libsndfile.dll
2007-08-28 04:48 339,968 -c--a-w C:\Documents and Settings\Administrator\Lame_enc.dll
2007-08-28 04:48 190,024 ----a-w C:\Documents and Settings\Administrator\MsgPlus.exe
2007-08-28 04:48 1,914,440 -c--a-w C:\Documents and Settings\Administrator\MsgPlusH.dll
2007-08-07 00:43 51,848 -c--a-w C:\Program Files\lcallig.ttf
2006-08-08 23:44 58,952 -c--a-w C:\Documents and Settings\Administrator\MsgPlusLoader1.dll
2006-06-14 23:27 9,409,224 -c--a-w C:\Documents and Settings\Administrator\Install_MSN_Messenger.exe
2006-06-14 23:11 4,752,968 -c--a-w C:\Documents and Settings\Administrator\MsgPlus-363.exe
2006-06-13 00:06 21,290,704 -c--a-w C:\Program Files\AdbeRdr708_en_US.exe
2006-06-12 23:59 7,050,552 -c--a-w C:\Program Files\psa30se_en_us.exe
2006-06-12 23:56 762,512 -c--a-w C:\Program Files\ytb612_efgsip.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BE838836-5A14-461D-B964-E63B8CA523E1}]
C:\WINDOWS\system32\qoMfcaWp.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [2007-02-22 07:55 32768]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-03 09:23 68856]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]
"MessengerPlus3"="C:\Documents and Settings\Administrator\MsgPlus.exe" [2007-08-28 14:48 190024]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 12:54 5674352]
"SharpTray"="C:\Program Files\Sharp\Sharpdesk\SharpTray.exe" [2001-11-08 10:37 28672]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
"GetPack18"="C:\Program Files\GetPack\GetPack18.exe" [2008-06-10 19:08 350208]
"GetModule18"="C:\Program Files\GetModule\GetModule18.exe" [2008-06-10 07:40 351744]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SiSUSBRG"="C:\WINDOWS\SiSUSBrg.exe" [2002-07-12 12:15 106496]
"SiS Windows KeyHook"="C:\WINDOWS\System32\keyhook.exe" [2004-05-12 16:22 249856]
"SoundMan"="SOUNDMAN.EXE" [2005-01-20 22:04 77824 C:\WINDOWS\SOUNDMAN.EXE]
"ShStatEXE"="C:\Program Files\Network Associates\VirusScan\SHSTAT.exe" [2003-09-29 07:10 81990]
"McAfeeUpdaterUI"="C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" [2003-09-10 03:11 135251]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 23:46 57344]
"IntelliType"="C:\Program Files\Microsoft Hardware\Keyboard\type32.exe" [2001-06-12 18:20 69632]
"SSBkgdUpdate"="C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 10:22 155648]
"PaperPort PTD"="C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe" [2004-04-14 14:46 57393]
"IndexSearch"="C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe" [2004-04-14 15:04 40960]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 03:25 144784]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-01-23 15:44 101136 C:\WINDOWS\KHALMNPR.Exe]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-07-16 11:14 286720]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-01-23 15:44 101136 C:\WINDOWS\KHALMNPR.Exe]
"28c2af21"="C:\WINDOWS\system32\mxlmeacy.dll" [ ]
"BM2bf19cbd"="C:\WINDOWS\system32\qmdwhovu.dll" [ ]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe [2006-06-15 09:47:31 82026]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696]
hp psc 1000 series.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe [2002-12-02 21:08:34 147456]
hpoddt01.exe.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2002-12-02 20:56:10 40960]
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2007-02-22 07:55:23 450560]
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2007-08-27 10:49:45 688128]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-18 14:05:56 65588]
Start Network Scanner Tool.lnk - C:\Program Files\Sharp\Sharpdesk\sdFTP.exe [2008-05-22 10:26:21 275968]
Utility Tray.lnk - C:\WINDOWS\system32\sistray.exe [2006-06-10 07:28:42 335872]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\Sharp\\Sharpdesk\\sdFTP.exe"=
"C:\\Program Files\\Network Associates\\Common Framework\\FrameworkService.exe"=
S3 brfilt;Brother MFC Filter Driver;C:\WINDOWS\system32\Drivers\Brfilt.sys [2001-08-17 13:12]
S3 brparimg;Brother Multi Function Parallel Image driver;C:\WINDOWS\system32\DRIVERS\BrParImg.sys [2001-08-17 13:12]
S3 BrParWdm;Brother WDM Parallel Driver;C:\WINDOWS\system32\Drivers\BrParwdm.sys [2001-08-17 13:12]
S3 BrSerWDM;Brother WDM Serial driver;C:\WINDOWS\system32\Drivers\BrSerWdm.sys [2004-11-23 17:39]
S3 NPF;NetGroup Packet Filter Driver;C:\WINDOWS\system32\drivers\npf.sys [2007-01-26 03:31]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\##Win2kserver#G]
\Shell\AutoRun\command - Y:\Autorun.exe /run
\Shell\Shell00\Command - Y:\Autorun.exe /run
\Shell\Shell01\Command - Y:\Autorun.exe /action
\Shell\Shell02\Command - Y:\Autorun.exe /uninstall
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e7a7142a-bd6d-11dc-8e46-000129d4a51a}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
"2007-11-20 10:25:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-06-16 02:30:00 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2006-10-12 07:11:09 C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1151997071.job"
- C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe4-I
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-06-16 12:59:49
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\BrmfBAgS.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\PROGRA~1\NETWOR~1\COMMON~1\naPrdMgr.exe
C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.exe
C:\Program Files\Windows Live Toolbar\msn_sl.exe
C:\WINDOWS\system32\verclsid.exe
.
**************************************************************************
.
Completion time: 2008-06-16 13:10:27 - machine was rebooted [Trish]
ComboFix-quarantined-files.txt 2008-06-16 03:10:23
Pre-Run: 28,283,342,848 bytes free
Post-Run: 30,932,054,016 bytes free
212 --- E O F --- 2008-05-28 07:09:07
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:11:50 PM, on 16/06/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\BrmfBAgS.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\keyhook.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Microsoft Hardware\Keyboard\type32.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Sharp\Sharpdesk\SharpTray.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\GetPack\GetPack18.exe
C:\Program Files\GetModule\GetModule18.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\sistray.exe
C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?linkid=677
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://g.ninemsn.com.au/0SEENAU/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://go.microsoft.com/fwlink/?LinkId=74005
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: (no name) - {BE838836-5A14-461D-B964-E63B8CA523E1} - C:\WINDOWS\system32\qoMfcaWp.dll (file missing)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\System32\keyhook.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft Hardware\Keyboard\type32.exe"
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [28c2af21] rundll32.exe "C:\WINDOWS\system32\mxlmeacy.dll",b
O4 - HKLM\..\Run: [BM2bf19cbd] Rundll32.exe "C:\WINDOWS\system32\qmdwhovu.dll",s
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Documents and Settings\Administrator\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [SharpTray] "C:\Program Files\Sharp\Sharpdesk\SharpTray.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [GetPack18] "C:\Program Files\GetPack\GetPack18.exe"
O4 - HKCU\..\Run: [GetModule18] "C:\Program Files\GetModule\GetModule18.exe"
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Logitech SetPoint.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Start Network Scanner Tool.lnk = C:\Program Files\Sharp\Sharpdesk\sdFTP.exe
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites -
http://favorites.live.com/quickadd.aspx
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) -
http://a1540.g.akamai.net/7/1540/52/...x/qtplugin.cab
O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} (MeadCo ScriptX Advanced) -
https://www.hunterunited.com.au/smsx.cab
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) -
http://acs.pandasoftware.com/actives.../as2stubie.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) -
http://messenger.zone.msn.com/EN-AU/.../GAME_UNO1.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) -
http://messenger.zone.msn.com/binary...o.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary...t.cab56907.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) -
http://messenger.zone.msn.com/binary/Chess.cab57176.cab
O18 - Protocol: bw+0 - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: offline-8876480 - {EC3BBEDD-5050-4CD9-8802-81B9C0CC9E1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O23 - Service: Brother BidiAgent Service for Resource manager (brmfbags) - Brother Industries, Ltd. - C:\WINDOWS\system32\BrmfBAgS.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
--
End of file - 22303 bytes
Cheers