Performance drop, dodgy processes

HarudathHarudath Great Britain Icrontian
edited April 2008 in Spyware & Virus Removal
Hai all,

My PC's been really sluggish lately, and a program I didn't know I had stopped reponding. I got a message about KEYGEN.exe having a hissy fit, I looked it up and apparently it's a system file. Tried to delete it, apparently exporer.exe was using it so I removed it with unlocker- but I'd love to make sure everything's clean as I use alot of passwords on this PC.

Hijack:

Logfile of HijackThis v1.99.1
Scan saved at 19:36:31, on 06/04/2008
Platform: Windows XP SP3, v.3311 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Documents and Settings\Harudath\Desktop\F@H\smpd.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54GSv2.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
C:\Program Files\Camera Assistant Software for ViewSonic\traybar.exe
C:\Program Files\UltraMon\UltraMon.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Camera Assistant Software for ViewSonic\CEC_MAIN.exe
C:\Documents and Settings\Harudath\Desktop\Tools\Core Temp.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Harudath\Desktop\F@H\mpiexec.exe
C:\Program Files\UltraMon\UltraMonTaskbar.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\PROGRA~1\Mozilla Firefox\firefox.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Documents and Settings\Harudath\Desktop\Tools\hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [nTrayFw] C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for ViewSonic\traybar.exe"
O4 - HKLM\..\Run: [RivaTunerStartupDaemon] "C:\Program Files\RivaTuner v2.06\RivaTuner.exe" /S
O4 - HKLM\..\Run: [LogonStudio] "C:\Program Files\WinCustomize\LogonStudio\logonstudio.exe" /RANDOM
O4 - HKLM\..\Run: [UltraMon] "C:\Program Files\UltraMon\UltraMon.exe" /auto
O4 - HKLM\..\Run: [Service Host] C:\DOCUME~1\Harudath\LOCALS~1\Temp\KEYGEN.EXE
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: Registration Ghost Recon Advanced Warfighter® 2.LNK = C:\Program Files\UBISOFT\Ghost Recon Advanced Warfighter 2\Support\Register\RegistrationReminder.exe
O4 - Startup: Shortcut to Core Temp.lnk = C:\Documents and Settings\Harudath\Desktop\Tools\Core Temp.exe
O4 - Startup: Shortcut to fah.lnk = C:\Documents and Settings\Harudath\Desktop\F@H\fah.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1202401235296
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1202598969328
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll
O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe" -k runservice (file missing)
O23 - Service: MPICH2 Process Manager, Argonne National Lab (mpich2_smpd) - Unknown owner - C:\Documents and Settings\Harudath\Desktop\F@H\smpd.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: WUSB54GSv2SVC - Unknown owner - C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe" "WUSB54GSv2.exe (file missing)

Comments

  • HarudathHarudath Great Britain Icrontian
    edited April 2008
    Hmm, I can see Keygen.exe is still alive :skeptic:


    EDIT: MSN keeps crashing and sometimes when I click a link on firefox all windows instantly close, no error or anything. Dunno if that's replated though.

    EDIT 2: I definately have something going on- AVG keeps finding and deleting trojans :(
  • edited April 2008
    Hello Harudath,

    Adding your own extra post sorta leaves your request appearing from the forum as in progress here. But I checked on a hunch. You are running a release candidate service pack upgrade there, which might place this at the cutting edge of testing new XP versions, but also makes it untested for using any of our tools. Or perhaps normally used repair methods, as far as knowing what really will occur when certain changes are made. Is AVG verified as compatible with this setup now?
  • HarudathHarudath Great Britain Icrontian
    edited April 2008
    AVG works perfectly, no crashes errors noresponds or anything. Everything that previously worked with SP2 works with SP3, or so I've found at least. I've redownloaded firefox, that should help that, hopefully :tongue:
  • edited April 2008
    Truth is I have been suggesting folks uninstall these beta service packs, so we can use tried/true methods of repairs. As is this will be all manual repairs for you there.


    Let's take a look, but perhaps make sure the scan only sticks to nothing but looking to be safe here.

    Download Deckard's System Scanner (dss.exe) to your Desktop. Note: You must be logged onto an account with administrator privileges.

    Making sure dss.exe is directly on your desktop, go to Start - Run, and copy/paste the following (then press OK):

    "%userprofile%\desktop\dss.exe" /config

    When the DSS Configuration display opens click the "Check All" button (if the "Uncheck All" button shows, click that, then click "Check All"). Next, Under Main Log, uncheck the following:

    System Restore
    Temp Cleanup
    Process Modules

    Don't make any other changes at this time. Then click the "Scan!" button to start the scan.

    Once the scan has completed a textbox will appear - copy/paste those contents back here (main.txt). Also a second text file, extra.txt, will show as minimized in your Task Bar. Maximize/Open this, and copy/paste those contents back here along with the main.txt please. (The logs can also be found in the C:\Deckard\System Scanner folder)
  • HarudathHarudath Great Britain Icrontian
    edited April 2008
    MAIN

    Deckard's System Scanner v20071014.68
    Run by Harudath on 2008-04-07 23:58:44
    Computer is in Normal Mode.



    -- HijackThis (run as Harudath.exe)

    Logfile of HijackThis v1.99.1
    Scan saved at 23:58:46, on 07/04/2008
    Platform: Windows XP SP3, v.3311 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.5730.0013)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
    C:\Documents and Settings\Harudath\Desktop\F@H\smpd.exe
    C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
    C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
    C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54GSv2.exe
    C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
    C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Java\jre1.5.0\bin\jusched.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\UltraMon\UltraMon.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Documents and Settings\Harudath\Desktop\Tools\Core Temp.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Documents and Settings\Harudath\Desktop\F@H\mpiexec.exe
    C:\Program Files\UltraMon\UltraMonTaskbar.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\PROGRA~1\Mozilla Firefox\firefox.exe
    C:\Documents and Settings\Harudath\desktop\dss.exe
    C:\DOCUME~1\Harudath\Desktop\Tools\HIJACK~1\Harudath.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [nTrayFw] C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for ViewSonic\traybar.exe"
    O4 - HKLM\..\Run: [RivaTunerStartupDaemon] "C:\Program Files\RivaTuner v2.06\RivaTuner.exe" /S
    O4 - HKLM\..\Run: [LogonStudio] "C:\Program Files\WinCustomize\LogonStudio\logonstudio.exe" /RANDOM
    O4 - HKLM\..\Run: [UltraMon] "C:\Program Files\UltraMon\UltraMon.exe" /auto
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - Startup: Registration Ghost Recon Advanced Warfighter® 2.LNK = C:\Program Files\UBISOFT\Ghost Recon Advanced Warfighter 2\Support\Register\RegistrationReminder.exe
    O4 - Startup: Shortcut to Core Temp.lnk = C:\Documents and Settings\Harudath\Desktop\Tools\Core Temp.exe
    O4 - Startup: Shortcut to fah.lnk = C:\Documents and Settings\Harudath\Desktop\F@H\fah.exe
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
    O11 - Options group: [INTERNATIONAL] International*
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1202401235296
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1202598969328
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
    O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
    O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll
    O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
    O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe" -k runservice (file missing)
    O23 - Service: MPICH2 Process Manager, Argonne National Lab (mpich2_smpd) - Unknown owner - C:\Documents and Settings\Harudath\Desktop\F@H\smpd.exe
    O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
    O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: WUSB54GSv2SVC - Unknown owner - C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe" "WUSB54GSv2.exe (file missing)


    -- HijackThis Fixed Entries (C:\DOCUME~1\Harudath\Desktop\Tools\HIJACK~1\backups\)

    backup-20080407-205531-330 O4 - HKLM\..\Run: [Service Host] C:\DOCUME~1\Harudath\LOCALS~1\Temp\KEYGEN.EXE

    -- File Associations

    .cpl - cplfile - shell\cplopen\command - rundll32.exe shell32.dll,Control_RunDLL "%1",%*
    .cpl - cplfile - shell\runas\command - rundll32.exe shell32.dll,Control_RunDLLAsUser "%1",%*


    -- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled

    R1 ATITool (ATITool Overclocking Utility) - c:\windows\system32\drivers\atitool.sys <Not Verified; ; Low-Level Driver>
    R2 AegisP (AEGIS Protocol (IEEE 802.1x) v3.2.0.3) - c:\windows\system32\drivers\aegisp.sys <Not Verified; Meetinghouse Data Communications; AEGIS Client 3.2.0.3>
    R2 UltraMonUtility (UltraMon Utility Driver) - c:\program files\common files\realtime soft\ultramonmirrordrv\x32\ultramonutility.sys <Not Verified; Realtime Soft; UltraMon>
    R3 dump_wmimmc - c:\program files\games-masters.com\cabal online (europe)\gameguard\dump_wmimmc.sys (file missing)
    R3 GTNDIS5 (GTNDIS5 NDIS Protocol Driver) - c:\windows\system32\gtndis5.sys <Not Verified; Printing Communications Assoc., Inc. (PCAUSA); PCAUSA Rawether for Windows>
    R3 NPPTNT2 - c:\windows\system32\npptnt2.sys <Not Verified; INCA Internet Co., Ltd.; nProtect NPSC Kernel Mode Driver for NT>
    R3 RivaTuner32 - c:\program files\rivatuner v2.06\rivatuner32.sys
    R3 TCCrystalCpuInfo - c:\docume~1\harudath\locals~1\temp\tccpuinfo.sys (file missing)
    R3 UltraMonMirror - c:\windows\system32\drivers\ultramonmirror.sys <Not Verified; Realtime Soft; UltraMon>

    S2 Service Host Driver - c:\docume~1\harudath\locals~1\temp\svchost.sys (file missing)
    S3 TVICHW32 - c:\windows\system32\drivers\tvichw32.sys <Not Verified; EnTech Taiwan; TVicHW32 Generic Device Driver for Windows 95/98/ME/NT/2000/2003/XP/XP64>


    -- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled

    R2 ForceWare Intelligent Application Manager (IAM) - c:\program files\nvidia corporation\networkaccessmanager\bin\nsvcappflt.exe <Not Verified; ; app_filter Module>
    R2 ForcewareWebInterface (Forceware Web Interface) - "c:\program files\nvidia corporation\networkaccessmanager\apache group\apache2\bin\apache.exe" -k runservice <Not Verified; Apache Software Foundation; Apache HTTP Server>
    R2 mpich2_smpd (MPICH2 Process Manager, Argonne National Lab) - c:\documents and settings\harudath\desktop\f@h\smpd.exe
    R2 nSvcLog (ForceWare user log service) - c:\program files\nvidia corporation\networkaccessmanager\bin\nsvclog.exe <Not Verified; NVIDIA; NVIDIA nSvcLog>


    -- Device Manager: Disabled

    Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
    Description: PCI Device
    Device ID: PCI\VEN_197B&DEV_2360&SUBSYS_82081043&REV_02\4&268339C6&0&0038
    Manufacturer:
    Name: PCI Device
    PNP Device ID: PCI\VEN_197B&DEV_2360&SUBSYS_82081043&REV_02\4&268339C6&0&0038
    Service:


    -- Scheduled Tasks

    2008-03-25 12:01:00 284 --a
    C:\WINDOWS\Tasks\AppleSoftwareUpdate.job


    -- Files created between 2008-03-07 and 2008-04-07

    2008-04-06 18:00:57 0 d
    C:\Documents and Settings\Harudath\Application Data\Desktopicon
    2008-04-06 15:47:29 0 d
    C:\Program Files\QuickTime
    2008-04-06 15:47:28 0 d
    C:\Documents and Settings\All Users\Application Data\Apple Computer
    2008-04-04 00:27:12 23 --a
    C:\WINDOWS\popcinfot.dat
    2008-04-04 00:04:48 0 d
    C:\Program Files\Steam
    2008-04-03 20:00:30 0 d
    C:\Program Files\Common Files\INCA Shared
    2008-04-02 23:02:35 4682 --a
    C:\WINDOWS\system32\npptNT2.sys <Not Verified; INCA Internet Co., Ltd.; nProtect NPSC Kernel Mode Driver for NT>
    2008-04-02 22:41:10 0 d
    C:\Program Files\Games-Masters.com
    2008-04-02 20:53:34 0 d
    C:\WINDOWS\nvidia icons
    2008-04-02 20:53:22 0 d
    C:\WINDOWS\NV32282840.TMP
    2008-04-02 18:16:57 0 d
    C:\WINDOWS\NV37523220.TMP
    2008-03-26 20:11:59 0 d
    C:\Documents and Settings\Harudath\Logs
    2008-03-26 19:47:35 0 d
    C:\Logs
    2008-03-24 03:47:30 0 dr-h
    C:\$VAULT$.AVG
    2008-03-24 03:07:29 0 d
    C:\Documents and Settings\Harudath\Application Data\AVG7
    2008-03-24 03:07:14 0 d
    C:\Documents and Settings\LocalService\Application Data\AVG7
    2008-03-24 03:06:46 0 d
    C:\Documents and Settings\All Users\Application Data\Grisoft
    2008-03-24 03:06:46 0 d
    C:\Documents and Settings\All Users\Application Data\avg7
    2008-03-23 16:00:03 0 d
    C:\Program Files\LimeWire
    2008-03-23 14:09:15 0 d
    C:\Program Files\Microsoft CAPICOM 2.1.0.2
    2008-03-22 22:07:23 0 d
    C:\WINDOWS\system32\xlive
    2008-03-22 22:07:08 0 d
    C:\Program Files\Microsoft XNA
    2008-03-22 21:50:48 0 d
    C:\Program Files\Microsoft Visual Studio 8
    2008-03-22 21:50:48 0 d
    C:\Documents and Settings\All Users\Application Data\Microsoft Help
    2008-03-18 10:43:17 17856 --a
    C:\Documents and Settings\Harudath\Application Data\GDIPFONTCACHEV1.DAT
    2008-03-18 09:00:22 0 d
    C:\Documents and Settings\Harudath\Application Data\DivX
    2008-03-15 13:46:46 0 d
    C:\Documents and Settings\Harudath\Application Data\Media Player Classic
    2008-03-09 23:51:33 0 d
    C:\Documents and Settings\Harudath\Application Data\Realtime Soft
    2008-03-09 23:51:24 0 d
    C:\Program Files\UltraMon
    2008-03-09 23:51:24 0 d
    C:\Program Files\Common Files\Realtime Soft
    2008-03-09 23:51:24 0 d
    C:\Documents and Settings\All Users\Application Data\Realtime Soft
    2008-03-09 23:48:29 8 --a
    C:\WINDOWS\system32\nvModes.dat
    2008-03-09 23:47:41 0 d
    C:\Documents and Settings\All Users\Application Data\nView_Profiles


    -- Find3M Report

    2008-04-07 15:40:13 0 d
    C:\Program Files\Windows Live Safety Center
    2008-04-07 00:08:46 0 d
    C:\Program Files\DivX
    2008-04-05 01:11:03 0 d
    C:\Documents and Settings\Harudath\Application Data\mIRC
    2008-04-04 18:32:23 0 d
    C:\Program Files\World of Warcraft
    2008-04-03 20:00:30 0 d
    C:\Program Files\Common Files
    2008-04-02 23:25:27 0 d
    C:\Documents and Settings\Harudath\Application Data\LimeWire
    2008-03-24 19:52:00 1626112 --a
    C:\WINDOWS\system32\nwiz.exe
    2008-03-24 19:52:00 1019904 --a
    C:\WINDOWS\system32\nvwimg.dll
    2008-03-24 19:52:00 1703936 --a
    C:\WINDOWS\system32\nvwdmcpl.dll
    2008-03-24 19:52:00 466944 --a
    C:\WINDOWS\system32\nvshell.dll
    2008-03-24 19:52:00 286720 --a
    C:\WINDOWS\system32\nvnt4cpl.dll
    2008-03-24 19:52:00 1482752 --a
    C:\WINDOWS\system32\nview.dll
    2008-03-24 19:52:00 1339392 --a
    C:\WINDOWS\system32\nvdspsch.exe
    2008-03-24 19:52:00 442368 --a
    C:\WINDOWS\system32\nvappbar.exe
    2008-03-24 19:52:00 425984 --a
    C:\WINDOWS\system32\keystone.exe
    2008-03-24 02:48:02 0 d
    C:\Program Files\TweakNow RegCleaner Professional
    2008-02-29 20:14:31 0 d
    C:\Documents and Settings\Harudath\Application Data\U3
    2008-02-29 01:17:59 0 d
    C:\Documents and Settings\Harudath\Application Data\uTorrent
    2008-02-27 21:53:38 0 d
    C:\Program Files\FMOD SoundSystem
    2008-02-27 21:52:39 0 d--h
    C:\Program Files\InstallShield Installation Information
    2008-02-27 21:45:21 0 d
    C:\Program Files\Electronic Arts
    2008-02-25 23:08:39 0 d
    C:\Program Files\MSBuild
    2008-02-25 23:08:33 0 d
    C:\Program Files\Reference Assemblies
    2008-02-25 00:50:37 0 d
    C:\Program Files\ASUS
    2008-02-24 18:33:53 1860 --a
    C:\WINDOWS\mozver.dat
    2008-02-23 15:51:30 0 d
    C:\Program Files\Microsoft ActiveSync
    2008-02-23 15:25:38 0 d
    C:\Program Files\Messenger
    2008-02-23 15:22:25 0 d
    C:\Program Files\Movie Maker
    2008-02-23 15:21:16 0 d
    C:\Program Files\Windows NT
    2008-02-21 20:35:10 0 d
    C:\Documents and Settings\Harudath\Application Data\Leadertech
    2008-02-21 20:35:09 0 d
    C:\Program Files\ViewSonic
    2008-02-20 16:18:32 524288 --a
    C:\WINDOWS\0901.BIN
    2008-02-17 00:09:53 0 d
    C:\Program Files\ATITool
    2008-02-16 18:51:39 0 d
    C:\Documents and Settings\Harudath\Application Data\Apple Computer
    2008-02-15 01:28:34 0 d
    C:\Program Files\Futuremark
    2008-02-12 22:19:58 0 d
    C:\Program Files\AquaMark3
    2008-02-11 17:53:52 0 d
    C:\Program Files\Common Files\Futuremark Shared
    2008-02-10 22:28:22 0 d
    C:\Program Files\Lionhead Studios Ltd
    2008-02-10 14:04:31 0 d
    C:\Program Files\Windows Media Connect 2
    2008-02-10 03:06:15 0 d
    C:\Program Files\WinCustomize
    2008-02-10 03:06:15 0 d
    C:\Program Files\Common Files\Stardock
    2008-02-10 01:36:45 0 d
    C:\Documents and Settings\Harudath\Application Data\Real
    2008-02-10 01:36:09 0 d
    C:\Program Files\Real Alternative
    2008-02-10 00:39:12 0 d
    C:\Program Files\Apple Software Update
    2008-02-09 18:28:42 0 dr-h
    C:\Documents and Settings\Harudath\Application Data\SecuROM
    2008-02-09 18:06:55 0 d
    C:\Documents and Settings\Harudath\Application Data\Adobe
    2008-02-09 16:28:00 0 d
    C:\Program Files\NeoTheme
    2008-02-09 15:04:09 0 d
    C:\Program Files\SEGA
    2008-02-09 14:47:48 0 d
    C:\Documents and Settings\Harudath\Application Data\WinRAR
    2008-02-08 22:54:24 0 d
    C:\Documents and Settings\Harudath\Application Data\teamspeak2
    2008-02-08 22:54:21 0 d
    C:\Program Files\Teamspeak2_RC2
    2008-02-08 22:19:45 0 d
    C:\Program Files\Common Files\Adobe
    2008-02-08 01:39:52 0 d
    C:\Documents and Settings\Harudath\Application Data\Sun
    2008-02-07 19:52:35 0 d
    C:\Program Files\Common Files\Blizzard Entertainment
    2008-02-07 18:53:58 0 d
    C:\Program Files\uTorrent
    2008-02-07 18:42:06 0 d
    C:\Program Files\Windows Live
    2008-02-07 18:41:13 0 d--hs--c- C:\Program Files\Common Files\WindowsLiveInstaller
    2008-02-07 17:07:38 262144 --a
    C:\WINDOWS\system32\wrap_oal.dll <Not Verified; Creative Labs; Creative Labs OpenAL32>
    2008-02-07 17:07:38 86016 --a
    C:\WINDOWS\system32\OpenAL32.dll <Not Verified; Portions (C) Creative Labs Inc. and NVIDIA Corp.; Standard OpenAL(TM) Library>
    2008-02-07 10:12:33 0 d
    C:\Program Files\AGEIA Technologies
    2008-02-07 10:12:17 0 d
    C:\Program Files\Common Files\Wise Installation Wizard
    2008-02-07 10:00:19 0 d
    C:\Program Files\UBISOFT
    2008-02-07 09:59:47 0 d
    C:\Documents and Settings\Harudath\Application Data\InstallShield
    2008-02-07 09:51:33 0 d
    C:\Documents and Settings\Harudath\Application Data\Macromedia
    2008-02-07 02:39:03 0 d
    C:\Program Files\RivaTuner v2.06
    2008-02-07 02:33:33 0 d
    C:\Program Files\Camera Assistant Software for ViewSonic
    2008-02-07 02:31:27 0 --a
    C:\WINDOWS\nsreg.dat
    2008-02-07 02:31:26 0 d
    C:\Documents and Settings\Harudath\Application Data\Mozilla
    2008-02-07 02:28:41 0 d
    C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor
    2008-02-07 02:28:35 0 d
    C:\Program Files\Common Files\InstallShield
    2008-02-07 02:24:22 22 --a
    C:\WINDOWS\FileName
    2008-02-07 02:24:15 0 d
    C:\Program Files\NVIDIA Corporation
    2008-02-07 02:21:52 0 d
    C:\Program Files\Realtek
    2008-02-07 02:18:59 0 d
    C:\Documents and Settings\Harudath\Application Data\Identities
    2008-02-07 02:16:02 0 d
    C:\Program Files\microsoft frontpage
    2008-02-07 02:15:30 0 d
    C:\Program Files\Java
    2008-02-07 02:15:30 0 d
    C:\Program Files\Common Files\Java
    2008-02-07 02:13:45 0 -rahs---- C:\MSDOS.SYS
    2008-02-07 02:13:45 0 -rahs---- C:\IO.SYS
    2008-02-07 02:13:45 0 --a
    C:\CONFIG.SYS
    2008-02-07 02:13:45 0 --a
    C:\AUTOEXEC.BAT
    2008-02-07 02:12:59 0 d--h
    C:\Program Files\WindowsUpdate
    2008-02-07 02:12:03 0 d
    C:\Program Files\Common Files\MSSoap
    2008-02-07 02:11:19 21640 --a
    C:\WINDOWS\system32\emptyregdb.dat
    2008-02-07 02:10:49 0 d
    C:\Program Files\Online Services
    2008-02-07 02:10:40 0 d
    C:\Program Files\MSN Gaming Zone
    2008-02-07 02:05:38 0 d
    C:\Program Files\Common Files\ODBC
    2008-02-07 02:05:35 0 d
    C:\Program Files\Common Files\SpeechEngines
    2008-02-07 02:05:09 62 --ahs---- C:\Documents and Settings\Harudath\Application Data\desktop.ini
    2008-02-01 16:50:25 339968 --a
    C:\WINDOWS\system32\fah.exe


    -- Registry Dump

    *Note* empty entries & legit default entries are not shown


    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0\bin\jusched.exe" [07/02/2008 02:15]
    "RTHDCPL"="RTHDCPL.EXE" [14/11/2006 10:21 C:\WINDOWS\RTHDCPL.exe]
    "SkyTel"="SkyTel.EXE" [16/05/2006 11:04 C:\WINDOWS\SkyTel.exe]
    "Alcmtr"="ALCMTR.EXE" [03/05/2005 11:43 C:\WINDOWS\Alcmtr.exe]
    "nTrayFw"="C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe" [17/02/2006 11:40]
    "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [24/03/2008 19:52]
    "nwiz"="nwiz.exe" [24/03/2008 19:52 C:\WINDOWS\system32\nwiz.exe]
    "Camera Assistant Software"="C:\Program Files\Camera Assistant Software for ViewSonic\traybar.exe" [22/12/2006 19:47]
    "RivaTunerStartupDaemon"="C:\Program Files\RivaTuner v2.06\RivaTuner.exe" [30/10/2007 19:05]
    "LogonStudio"="C:\Program Files\WinCustomize\LogonStudio\logonstudio.exe" [03/09/2002 19:38]
    "UltraMon"="C:\Program Files\UltraMon\UltraMon.exe" [12/10/2006 22:27]
    "AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [24/03/2008 03:08]
    "NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [24/03/2008 19:52]
    "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [28/03/2008 23:37]
    "UnlockerAssistant"="C:\Program Files\Unlocker\UnlockerAssistant.exe" [01/03/2008 06:10]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [12/02/2008 10:29]
    "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [12/02/2008 10:29]

    C:\Documents and Settings\Harudath\Start Menu\Programs\Startup\
    Registration Ghost Recon Advanced Warfighter© 2.LNK - C:\Program Files\UBISOFT\Ghost Recon Advanced Warfighter 2\Support\Register\RegistrationReminder.exe [2/7/2008 10:03:50 AM]
    Shortcut to Core Temp.lnk - C:\Documents and Settings\Harudath\Desktop\Tools\Core Temp.exe [2/7/2008 9:54:58 AM]
    Shortcut to fah.lnk - C:\Documents and Settings\Harudath\Desktop\F@H\fah.exe [2/27/2008 11:25:47 PM]

    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
    Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2/8/2008 10:19:48 PM]
    Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2/13/2001 2:01:04 AM]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
    C:\WINDOWS\System32\dimsntfy.dll

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Service Host Driver"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
    @=&quot;Service"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
    @=&quot;Volume shadow copy"

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    eapsvcs eaphost
    dot3svc dot3svc

    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
    napagent
    hkmsvc


    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
    AutoRun\command- E:\LaunchU3.exe




    -- End of Deckard's System Scanner: finished at 2008-04-08 00:00:33





    EXTRA


    Deckard's System Scanner v20071014.68
    Extra logfile - please post this as an attachment with your post.

    -- System Information

    Microsoft Windows XP Home Edition (build 2600) SP 3.0
    Architecture: X86; Language: English

    CPU 0: Intel(R) Core(TM)2 Duo CPU E6750 @ 2.66GHz
    Percentage of Memory in Use: 55%
    Physical Memory (total/avail): 2046.48 MiB / 907.56 MiB
    Pagefile Memory (total/avail): 3939.45 MiB / 3045.52 MiB
    Virtual Memory (total/avail): 2047.88 MiB / 1918.34 MiB

    A: is Removable (No Media)
    C: is Fixed (NTFS) - 149.04 GiB total, 84.84 GiB free.
    D: is CDROM (No Media)

    \\.\PHYSICALDRIVE0 - WDC WD1600JS-55NCB1 - 149.05 GiB - 1 partition
    \PARTITION0 (bootable) - Installable File System - 149.04 GiB - C:



    -- Security Center

    AUOptions is scheduled to auto-install.


    -- Environment Variables

    ALLUSERSPROFILE=C:\Documents and Settings\All Users
    APPDATA=C:\Documents and Settings\Harudath\Application Data
    CLASSPATH=.;C:\Program Files\Java\jre1.5.0\lib\ext\QTJava.zip
    CLIENTNAME=Console
    CommonProgramFiles=C:\Program Files\Common Files
    COMPUTERNAME=HARUDATH-C90943
    ComSpec=C:\WINDOWS\system32\cmd.exe
    FP_NO_HOST_CHECK=NO
    HOMEDRIVE=C:
    HOMEPATH=\Documents and Settings\Harudath
    LOGONSERVER=\\HARUDATH-C90943
    NUMBER_OF_PROCESSORS=2
    OS=Windows_NT
    Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\Program Files\QuickTime\QTSystem\
    PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
    PROCESSOR_ARCHITECTURE=x86
    PROCESSOR_IDENTIFIER=x86 Family 6 Model 15 Stepping 11, GenuineIntel
    PROCESSOR_LEVEL=6
    PROCESSOR_REVISION=0f0b
    ProgramFiles=C:\Program Files
    PROMPT=$P$G
    QTJAVA=C:\Program Files\Java\jre1.5.0\lib\ext\QTJava.zip
    SESSIONNAME=Console
    SystemDrive=C:
    SystemRoot=C:\WINDOWS
    TEMP=C:\DOCUME~1\Harudath\LOCALS~1\Temp
    TMP=C:\DOCUME~1\Harudath\LOCALS~1\Temp
    ULTRAMON_LANGDIR=C:\Program Files\UltraMon\Resources\en
    USERDOMAIN=HARUDATH-C90943
    USERNAME=Harudath
    USERPROFILE=C:\Documents and Settings\Harudath
    windir=C:\WINDOWS
    XNAGSShared=c:\Program Files\Common Files\Microsoft Shared\XNA\
    XNAGSv2=c:\Program Files\Microsoft XNA\XNA Game Studio\v2.0\


    -- User Profiles

    Harudath (admin)


    -- Add/Remove Programs

    --> MsiExec /X{27DC856A-0916-4988-8198-8714DDD3183D}
    --> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
    3DMark06 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7F3AD00A-1819-4B15-BB7D-08B3586336D7}\setup.exe" -l0x9 -removeonly
    Adobe Flash Player ActiveX --> C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
    Adobe Flash Player Plugin --> C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
    Adobe Photoshop 7.0 --> C:\WINDOWS\ISUNINST.EXE -f"C:\Program Files\Adobe\Photoshop 7.0\Uninst.isu" -c"C:\Program Files\Adobe\Photoshop 7.0\Uninst.dll"
    Adobe Shockwave Player --> C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log
    AGEIA PhysX v7.05.17 --> MsiExec.exe /X{27DC856A-0916-4988-8198-8714DDD3183D}
    Apple Software Update --> MsiExec.exe /I{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}
    AquaMark3 --> C:\PROGRA~1\AQUAMA~1\UNWISE.EXE C:\PROGRA~1\AQUAMA~1\INSTALL.LOG
    ASUSUpdate --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{587178E7-B1DF-494E-9838-FA4DD36E873C}\setup.exe" -l0x9
    ATITool Overclocking Utility --> "C:\Program Files\ATITool\Uninstall.exe"
    µTorrent --> "C:\Program Files\uTorrent\uTorrent.exe" /UNINSTALL
    AVG 7.5 --> C:\Program Files\Grisoft\AVG7\setup.exe /UNINSTALL
    Black and White --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E51B4CD9-A0A6-4324-B26A-31B3F2DE26CE}\Setup.exe"
    CABAL Online v3.3 --> "C:\Program Files\Games-Masters.com\CABAL Online (Europe)\unins000.exe"
    Camera Assistant Software for ViewSonic --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C33F3EF6-3625-4FE5-BCBA-41361C99AF1D}\setup.exe" -l0x9 -removeonly
    Crysis ModSDK --> "C:\Program Files\InstallShield Installation Information\{566664F6-B34E-41A6-AD1D-4ED22DA334AE}\setup.exe" -runfromtemp -l0x0009 -removeonly
    Crysis(R) SP Demo --> MsiExec.exe /I{92AF2F5A-4407-4A03-A80A-5A2582264746}
    DriverAgent Plugin for Netscape by TouchStone Software --> RunDll32.exe advpack.dll, LaunchINFSection driveragent_np.inf,TVICHW32Remove
    FMOD Designer --> "C:\Program Files\FMOD SoundSystem\FMOD Designer\uninstall.exe"
    Folding@Home Windows SMP Client --> C:\WINDOWS\system32\GKSUI20.EXE C:\Documents and Settings\Harudath\Desktop\F@H\UninstallE34C.DAT
    Futuremark SystemInfo --> C:\Program Files\InstallShield Installation Information\{BEE64C14-BEF1-4610-8A68-A16EAA47B882}\setup.exe -runfromtemp -l0x0009 -removeonly
    High Definition Audio Driver Package - KB888111 -->
    HijackThis 1.99.1 --> C:\Documents and Settings\Harudath\Desktop\Tools\hijackthis\HijackThis.exe /uninstall
    Hotfix for Windows Media Format 11 SDK (KB929399) --> "C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
    J2SE Runtime Environment 5.0 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150000}
    LimeWire PRO 4.16.6 --> "C:\Program Files\LimeWire\uninstall.exe"
    Linksys Wireless-G USB Network Adapter --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C7EEF2B9-8C16-4A04-B98D-B1A952A47E55}\setup.exe" -l0x9
    LogonStudio --> C:\PROGRA~1\WINCUS~1\LOGONS~1\UNWISE.EXE C:\PROGRA~1\WINCUS~1\LOGONS~1\INSTALL.LOG
    Medieval II Total War --> C:\Program Files\InstallShield Installation Information\{C0698BDA-0D29-40EE-8570-A31106DF9AB1}\setup.exe -runfromtemp -l0x0009 -removeonly
    Medieval II Total War : Kingdoms : Americas --> C:\Program Files\InstallShield Installation Information\{75983B66-804C-40D1-BA13-64DAF652A6F1}\setup.exe -runfromtemp -l0x0009 -removeonly
    Medieval II Total War : Kingdoms : Britannia --> C:\Program Files\InstallShield Installation Information\{CEDDEE73-3D36-41C2-AA40-29355D9FBD63}\setup.exe -runfromtemp -l0x0009 -removeonly
    Medieval II Total War : Kingdoms : Crusades --> C:\Program Files\InstallShield Installation Information\{02A10468-2F1C-447C-AD8E-4DEDDEA25AE2}\setup.exe -runfromtemp -l0x0009 -removeonly
    Medieval II Total War : Kingdoms : Teutonic --> C:\Program Files\InstallShield Installation Information\{7AEE1963-7001-4C37-BC20-2FAEB74AA41C}\setup.exe -runfromtemp -l0x0009 -removeonly
    Microsoft Compression Client Pack 1.0 for Windows XP --> "C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
    Microsoft Games for Windows - LIVE Redistributable --> MsiExec.exe /X{D1B01DC9-CBAF-45F9-A387-7D00C11B630E}
    Microsoft Office XP Professional with FrontPage --> MsiExec.exe /I{90280409-6000-11D3-8CFE-0050048383C9}
    Microsoft Visual C# 2005 Express Edition - ENU --> C:\Program Files\Microsoft Visual Studio 8\Microsoft Visual C# 2005 Express Edition - ENU\setup.exe
    Microsoft Visual C# 2005 Express Edition - ENU --> MsiExec.exe /X{7E7D7935-B0C8-4032-80BA-2CDC9E43C3B8}
    Microsoft Visual C# 2005 Express Edition - ENU Service Pack 1 (KB926749) --> C:\WINDOWS\system32\msiexec.exe /promptrestart /uninstall {B6B0F76A-873E-438E-BC25-6704193DD344} /package {7E7D7935-B0C8-4032-80BA-2CDC9E43C3B8}
    Microsoft Visual C++ 2005 Redistributable --> MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
    Microsoft Visual J# .NET Redistributable Package 1.1 --> MsiExec.exe /X{1A655D51-1423-48A3-B748-8F5A0BE294C8}
    Microsoft XNA Framework Redistributable 2.0 --> MsiExec.exe /I{245F6C7A-0C22-4DE0-8202-2AAA620A1D3A}
    Microsoft XNA Game Studio 2.0 --> c:\Program Files\Microsoft XNA\XNA Game Studio\v2.0\Setup\Bootstrapper.exe
    Microsoft XNA Game Studio 2.0 --> MsiExec.exe /I{C357E2C9-091F-4B12-BB1C-2E7B19112BC4}
    Microsoft XNA Game Studio 2.0 (ARP entry) --> MsiExec.exe /I{070B87FB-CD1A-45AA-9E5E-484E5964C6ED}
    Microsoft XNA Game Studio 2.0 (Redists) --> MsiExec.exe /I{31EA6FCB-6C53-4BA7-BE88-9BA788899C2C}
    Microsoft XNA Game Studio 2.0 (shared components) --> MsiExec.exe /I{C18DA187-6C0D-4B8E-99AE-74D5C588AFB6}
    Microsoft XNA Game Studio 2.0 (spacewar) --> MsiExec.exe /I{3432C2AA-BB3E-44B3-B5ED-EF36E0241100}
    Microsoft XNA Game Studio 2.0 (xnaliveproxy) --> MsiExec.exe /I{9B96628C-8898-4FED-9612-25631C27AB13}
    Microsoft XNA Game Studio 2.0 Documentation --> MsiExec.exe /I{3B5A6E00-2B27-4E1A-8A33-E3A40DEFD4DC}
    Mozilla Firefox (2.0.0.13) --> C:\PROGRA~1\Mozilla Firefox\uninstall\helper.exe
    NeoTheme 2.0 --> C:\Program Files\NeoTheme\uninst.exe
    NVIDIA Drivers --> C:\WINDOWS\system32\nvuninst.exe UninstallGUI
    NVIDIA ForceWare Network Access Manager --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{1F6423DE-7959-4178-80E0-023C7EAA5347} /l1033
    QuickTime --> MsiExec.exe /I{1838C5A2-AB32-4145-85C1-BB9B8DFA24CD}
    Real Alternative 1.7.5 --> "C:\Program Files\Real Alternative\unins000.exe"
    Realtek High Definition Audio Driver --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\setup.exe" -l0x9 -removeonly
    RivaTuner v2.06 --> "C:\Program Files\RivaTuner v2.06\uninstall.exe"
    Security Update for CAPICOM (KB931906) --> MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
    Security Update for CAPICOM (KB931906) --> MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
    Steam --> MsiExec.exe /X{048298C9-A4D3-490B-9FF9-AB023A9238F3}
    TeamSpeak 2 RC2 --> "C:\Program Files\Teamspeak2_RC2\unins000.exe"
    Tom Clancy's Ghost Recon Advanced Warfighter® 2 --> "C:\Program Files\InstallShield Installation Information\{F78AC3C0-578C-49AB-BD4E-3107A6036A13}\Setup.exe" -runfromtemp -l0x0009 -removeonly
    TweakNow RegCleaner Professional --> "C:\Program Files\TweakNow RegCleaner Professional\unins000.exe"
    UltraMon --> MsiExec.exe /I{E67FF1A2-23C1-4102-84E9-42115F77AD32}
    Unlocker 1.8.6 --> C:\Program Files\Unlocker\uninst.exe
    ViewSonic Monitor Drivers --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B4FEA924-630D-11D4-B78E-005004566E4D}\Setup.exe" -l0x9
    Windows Live installer --> MsiExec.exe /X{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}
    Windows Live Mail --> MsiExec.exe /I{184E7118-0295-43C4-B72C-1D54AA75AAF7}
    Windows Live Messenger --> MsiExec.exe /X{508CE775-4BA4-4748-82DF-FE28DA9F03B0}
    Windows Live OneCare safety scanner --> RunDll32.exe "C:\Program Files\Windows Live Safety Center\wlscCore.dll",UninstallFunction WLSC_SCANNER_PRODUCT
    Windows Media Format 11 runtime --> "C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
    Windows XP Service Pack 3 --> "C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
    WinRAR archiver --> C:\Program Files\WinRAR\uninstall.exe
    World of Warcraft --> C:\Program Files\Common Files\Blizzard Entertainment\World of Warcraft\Uninstall.exe
    XML Paper Specification Shared Components Pack 1.0 -->


    -- Application Event Log

    Event Record #/Type70 / Error
    Event Submitted/Written: 04/07/2008 08:55:51 PM
    Event ID/Source: 1000 / Application Error
    Event Description:
    Faulting application drwtsn32.exe, version 5.1.2600.0, faulting module dbghelp.dll, version 5.1.2600.3311, fault address 0x0001295d.
    Processing media-specific event for [drwtsn32.exe!ws!]

    Event Record #/Type69 / Error
    Event Submitted/Written: 04/07/2008 08:55:47 PM
    Event ID/Source: 1000 / Application Error
    Event Description:
    Faulting application explorer.exe, version 6.0.2900.3311, faulting module unlockercom.dll, version 0.0.0.0, fault address 0x00001107.
    Processing media-specific event for [explorer.exe!ws!]

    Event Record #/Type68 / Error
    Event Submitted/Written: 04/07/2008 08:32:28 PM
    Event ID/Source: 1000 / Application Error
    Event Description:
    Faulting application firefox.exe, version 1.8.20080.31114, faulting module nvappfilter.dll, version 2.2.0.5023, fault address 0x00005548.
    Processing media-specific event for [firefox.exe!ws!]

    Event Record #/Type67 / Error
    Event Submitted/Written: 04/07/2008 08:26:29 PM
    Event ID/Source: 1000 / Application Error
    Event Description:
    Faulting application firefox.exe, version 1.8.20080.31114, faulting module nvappfilter.dll, version 2.2.0.5023, fault address 0x00005548.
    Processing media-specific event for [firefox.exe!ws!]

    Event Record #/Type64 / Success
    Event Submitted/Written: 04/07/2008 08:15:45 PM
    Event ID/Source: 12001 / usnjsvc
    Event Description:
    The Messenger Sharing USN Journal Reader service started successfully.



    -- Security Event Log

    No Errors/Warnings found.


    -- System Event Log

    Event Record #/Type2769 / Error
    Event Submitted/Written: 04/08/2008 00:00:17 AM
    Event ID/Source: 10016 / DCOM
    Event Description:
    The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID
    {BC866CF2-5486-41F7-B46B-9AA49CF3EBB1}
    to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19). This security permission can be modified using the Component Services administrative tool.

    Event Record #/Type2768 / Error
    Event Submitted/Written: 04/08/2008 00:00:17 AM
    Event ID/Source: 10016 / DCOM
    Event Description:
    The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID
    {BC866CF2-5486-41F7-B46B-9AA49CF3EBB1}
    to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19). This security permission can be modified using the Component Services administrative tool.

    Event Record #/Type2767 / Error
    Event Submitted/Written: 04/08/2008 00:00:17 AM
    Event ID/Source: 10016 / DCOM
    Event Description:
    The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID
    {BC866CF2-5486-41F7-B46B-9AA49CF3EBB1}
    to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19). This security permission can be modified using the Component Services administrative tool.

    Event Record #/Type2766 / Error
    Event Submitted/Written: 04/08/2008 00:00:17 AM
    Event ID/Source: 10016 / DCOM
    Event Description:
    The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID
    {BC866CF2-5486-41F7-B46B-9AA49CF3EBB1}
    to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19). This security permission can be modified using the Component Services administrative tool.

    Event Record #/Type2765 / Error
    Event Submitted/Written: 04/08/2008 00:00:17 AM
    Event ID/Source: 10016 / DCOM
    Event Description:
    The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID
    {BC866CF2-5486-41F7-B46B-9AA49CF3EBB1}
    to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19). This security permission can be modified using the Component Services administrative tool.



    -- End of Deckard's System Scanner: finished at 2008-04-08 00:00:33
  • edited April 2008
    I think there is a bad service running there - it is similar to some known backdoor trojans. But there is just too little documentation on SP3 to make any suggestions. The file associations you see in that log in the red hilight are incorrect for XP - are they incorrect for SP3? If you should decide to uninstall SP3 we could then likely handily address any malware on that system, but as is I just won't be able to assist here Harudath. Although sometimes I need to make calculated assumptions, for this setup for me each decision would be no more than a coin toss.
  • HarudathHarudath Great Britain Icrontian
    edited April 2008
    Hmm, I get the feeling removing SP3 isn't as simple as going to control panel and clicking remove :tongue: although that is an option >.>
  • edited April 2008
    :smiles: Truth is though it was I have been hinting at all along. Usually we just don't attempt to address issues in beta situations.
  • HarudathHarudath Great Britain Icrontian
    edited April 2008
    I went and got myself some decent antivirus software, it removed 17 tracking cookies and 3 viruses >.> So hopefully I'm clean. Here's another hijackthis log to make sure you agree with it, even if it's BETA :tongue:

    Logfile of HijackThis v1.99.1
    Scan saved at 18:52:05, on 08/04/2008
    Platform: Windows XP SP3, v.3311 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.5730.0013)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe
    C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
    C:\Program Files\F-Secure Internet Security\Anti-Virus\FSGK32.EXE
    C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE
    C:\Documents and Settings\Harudath\Desktop\F@H\smpd.exe
    C:\Program Files\F-Secure Internet Security\Common\FSMB32.EXE
    C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
    C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
    C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54GSv2.exe
    C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
    C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
    C:\Program Files\F-Secure Internet Security\Common\FCH32.EXE
    C:\Program Files\F-Secure Internet Security\Common\FAMEH32.EXE
    C:\Program Files\F-Secure Internet Security\Anti-Virus\fsqh.exe
    C:\Program Files\F-Secure Internet Security\FSPC\fspc.exe
    C:\Program Files\F-Secure Internet Security\Anti-Virus\fssm32.exe
    C:\Program Files\F-Secure Internet Security\FSAUA\program\fsaua.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe
    C:\Program Files\F-Secure Internet Security\FSAUA\program\fsus.exe
    C:\Program Files\Java\jre1.5.0\bin\jusched.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Documents and Settings\Harudath\Desktop\Tools\Core Temp.exe
    C:\Program Files\F-Secure Internet Security\FSGUI\fsguidll.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\F-Secure Internet Security\Anti-Virus\fsav32.exe
    C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\Windows Live\Messenger\usnsvc.exe
    C:\Program Files\LimeWire\LimeWire.exe
    C:\Documents and Settings\Harudath\Desktop\Tools\hijackthis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [nTrayFw] C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for ViewSonic\traybar.exe"
    O4 - HKLM\..\Run: [RivaTunerStartupDaemon] "C:\Program Files\RivaTuner v2.06\RivaTuner.exe" /S
    O4 - HKLM\..\Run: [LogonStudio] "C:\Program Files\WinCustomize\LogonStudio\logonstudio.exe" /RANDOM
    O4 - HKLM\..\Run: [UltraMon] "C:\Program Files\UltraMon\UltraMon.exe" /auto
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
    O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE" /splash
    O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure Internet Security\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - Startup: Registration Ghost Recon Advanced Warfighter® 2.LNK = C:\Program Files\UBISOFT\Ghost Recon Advanced Warfighter 2\Support\Register\RegistrationReminder.exe
    O4 - Startup: Shortcut to Core Temp.lnk = C:\Documents and Settings\Harudath\Desktop\Tools\Core Temp.exe
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
    O9 - Extra button: Parental... - {200DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll
    O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll
    O9 - Extra 'Tools' menuitem: Parental... - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Unknown file in Winsock LSP: c:\program files\f-secure internet security\fsps\program\fslsp.dll
    O10 - Unknown file in Winsock LSP: c:\program files\f-secure internet security\fsps\program\fslsp.dll
    O10 - Unknown file in Winsock LSP: c:\program files\f-secure internet security\fsps\program\fslsp.dll
    O10 - Unknown file in Winsock LSP: c:\program files\f-secure internet security\fsps\program\fslsp.dll
    O10 - Unknown file in Winsock LSP: c:\program files\f-secure internet security\fsps\program\fslsp.dll
    O10 - Unknown file in Winsock LSP: c:\program files\f-secure internet security\fsps\program\fslsp.dll
    O10 - Unknown file in Winsock LSP: c:\program files\f-secure internet security\fsps\program\fslsp.dll
    O10 - Unknown file in Winsock LSP: c:\program files\f-secure internet security\fsps\program\fslsp.dll
    O10 - Unknown file in Winsock LSP: c:\program files\f-secure internet security\fsps\program\fslsp.dll
    O10 - Unknown file in Winsock LSP: c:\program files\f-secure internet security\fsps\program\fslsp.dll
    O10 - Unknown file in Winsock LSP: c:\program files\f-secure internet security\fsps\program\fslsp.dll
    O10 - Unknown file in Winsock LSP: c:\program files\f-secure internet security\fsps\program\fslsp.dll
    O10 - Unknown file in Winsock LSP: c:\program files\f-secure internet security\fsps\program\fslsp.dll
    O10 - Unknown file in Winsock LSP: c:\program files\f-secure internet security\fsps\program\fslsp.dll
    O10 - Unknown file in Winsock LSP: c:\program files\f-secure internet security\fsps\program\fslsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
    O10 - Unknown file in Winsock LSP: c:\program files\f-secure internet security\fsps\program\fslsp.dll
    O11 - Options group: [INTERNATIONAL] International*
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1202401235296
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1202598969328
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
    O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
    O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll
    O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe
    O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
    O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe" -k runservice (file missing)
    O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FSAUA\program\fsaua.exe
    O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe
    O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE
    O23 - Service: MPICH2 Process Manager, Argonne National Lab (mpich2_smpd) - Unknown owner - C:\Documents and Settings\Harudath\Desktop\F@H\smpd.exe
    O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
    O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: WUSB54GSv2SVC - Unknown owner - C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe" "WUSB54GSv2.exe (file missing)
  • edited April 2008
    I don't see any infection in this HijackThis log. Bit of a tip of the iceberg view, but it does target some of the better known malware jump off points. Good you feel you got things resolved there. Any more infection alerts come up in future scans we can always revisit here then.
  • HarudathHarudath Great Britain Icrontian
    edited April 2008
    Anything comes up and I know exactly where to go :) Thing is I want to buy stuff online with this PC, but I don't know if it's safe enough :(
  • edited April 2008
    Here and here for starters. McAfee here as well. Not truly 100%, but I would check this before doing any online downloads. Just enter the site name in the search bar, upper right.
  • HarudathHarudath Great Britain Icrontian
    edited April 2008
    I'm not clean- f-secure found a virus that it couldn't remove so it renamed it but I doubt that's the last of it. I'm uninstalling SP3 until the matter is resolved :tongue: It actually is as simple as going to control panel and clicking remove :D
  • HarudathHarudath Great Britain Icrontian
    edited April 2008
    SP3 removed and I've got on average SIXTY processes running! WTF >.< Here's hijackthis...

    Logfile of HijackThis v1.99.1
    Scan saved at 15:23:16, on 09/04/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe
    C:\Program Files\F-Secure Internet Security\Anti-Virus\FSGK32.EXE
    C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
    C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE
    C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    C:\Documents and Settings\Harudath\Desktop\F@H\smpd.exe
    C:\Program Files\F-Secure Internet Security\Common\FSMB32.EXE
    C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
    C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
    C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
    C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
    C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54GSv2.exe
    C:\Program Files\F-Secure Internet Security\Common\FCH32.EXE
    C:\Program Files\F-Secure Internet Security\Common\FAMEH32.EXE
    C:\Program Files\F-Secure Internet Security\Anti-Virus\fsqh.exe
    C:\Program Files\F-Secure Internet Security\FSPC\fspc.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\F-Secure Internet Security\Anti-Virus\fssm32.exe
    C:\Program Files\F-Secure Internet Security\FSAUA\program\fsaua.exe
    C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe
    C:\Program Files\Java\jre1.5.0\bin\jusched.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\Camera Assistant Software for ViewSonic\traybar.exe
    C:\Program Files\UltraMon\UltraMon.exe
    C:\Program Files\Unlocker\UnlockerAssistant.exe
    C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE
    C:\Program Files\F-Secure Internet Security\FSAUA\program\fsus.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\F-Secure Internet Security\FSGUI\fsguidll.exe
    C:\Program Files\UltraMon\UltraMonTaskbar.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Camera Assistant Software for ViewSonic\CEC_MAIN.exe
    C:\Program Files\Google\Google Updater\GoogleUpdater.exe
    C:\Documents and Settings\Harudath\Desktop\Tools\Core Temp.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\F-Secure Internet Security\Anti-Virus\fsav32.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\taskmgr.exe
    C:\Documents and Settings\Harudath\Desktop\Tools\hijackthis\HijackThis.exe

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [nTrayFw] C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for ViewSonic\traybar.exe"
    O4 - HKLM\..\Run: [RivaTunerStartupDaemon] "C:\Program Files\RivaTuner v2.06\RivaTuner.exe" /S
    O4 - HKLM\..\Run: [LogonStudio] "C:\Program Files\WinCustomize\LogonStudio\logonstudio.exe" /RANDOM
    O4 - HKLM\..\Run: [UltraMon] "C:\Program Files\UltraMon\UltraMon.exe" /auto
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
    O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE" /splash
    O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure Internet Security\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - Startup: Registration Ghost Recon Advanced Warfighter® 2.LNK = C:\Program Files\UBISOFT\Ghost Recon Advanced Warfighter 2\Support\Register\RegistrationReminder.exe
    O4 - Startup: Shortcut to Core Temp.lnk = C:\Documents and Settings\Harudath\Desktop\Tools\Core Temp.exe
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
    O9 - Extra button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - C:\WINDOWS\system32\shdocvw.dll
    O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\WINDOWS\system32\shdocvw.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Unknown file in Winsock LSP: c:\program files\f-secure internet security\fsps\program\fslsp.dll
    O10 - Unknown file in Winsock LSP: c:\program files\f-secure internet security\fsps\program\fslsp.dll
    O10 - Unknown file in Winsock LSP: c:\program files\f-secure internet security\fsps\program\fslsp.dll
    O10 - Unknown file in Winsock LSP: c:\program files\f-secure internet security\fsps\program\fslsp.dll
    O10 - Unknown file in Winsock LSP: c:\program files\f-secure internet security\fsps\program\fslsp.dll
    O10 - Unknown file in Winsock LSP: c:\program files\f-secure internet security\fsps\program\fslsp.dll
    O10 - Unknown file in Winsock LSP: c:\program files\f-secure internet security\fsps\program\fslsp.dll
    O10 - Unknown file in Winsock LSP: c:\program files\f-secure internet security\fsps\program\fslsp.dll
    O10 - Unknown file in Winsock LSP: c:\program files\f-secure internet security\fsps\program\fslsp.dll
    O10 - Unknown file in Winsock LSP: c:\program files\f-secure internet security\fsps\program\fslsp.dll
    O10 - Unknown file in Winsock LSP: c:\program files\f-secure internet security\fsps\program\fslsp.dll
    O10 - Unknown file in Winsock LSP: c:\program files\f-secure internet security\fsps\program\fslsp.dll
    O10 - Unknown file in Winsock LSP: c:\program files\f-secure internet security\fsps\program\fslsp.dll
    O10 - Unknown file in Winsock LSP: c:\program files\f-secure internet security\fsps\program\fslsp.dll
    O10 - Unknown file in Winsock LSP: c:\program files\f-secure internet security\fsps\program\fslsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
    O10 - Unknown file in Winsock LSP: c:\program files\f-secure internet security\fsps\program\fslsp.dll
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1202401235296
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1202598969328
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
    O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
    O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll
    O20 - Winlogon Notify: dimsntfy - C:\WINDOWS\
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe
    O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
    O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe" -k runservice (file missing)
    O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FSAUA\program\fsaua.exe
    O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe
    O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: MPICH2 Process Manager, Argonne National Lab (mpich2_smpd) - Unknown owner - C:\Documents and Settings\Harudath\Desktop\F@H\smpd.exe
    O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
    O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: WUSB54GSv2SVC - Unknown owner - C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe" "WUSB54GSv2.exe (file missing)
  • HarudathHarudath Great Britain Icrontian
    edited April 2008
    There was something hanging around in System restore, so I turned System restore off and I'm doing another virus scan.
  • edited April 2008
    On your own there Harudath, but no, I do not recommend having System Restore disabled during any situation where changes might be made. It leaves you with one less option to fall back on, should things go south.
  • HarudathHarudath Great Britain Icrontian
    edited April 2008
    I never use system restore anyway, so it's just removing a place for the virus to go :tongue: I think I've removed everything but the problem is I can never be sure :( Thanks for all your help though.

    n.b. My PC has been randomly going into sleep/shut down. My PSU is 250W underpowered so I dont know if that's the problem or not. In any case my new one arrives in about 2 hours so we'll see :ninja:
Sign In or Register to comment.