PDA

View Full Version : Curious repetetive HJT entry



Berethruu
2008-01-16, 03:23
Hi guys (and gals),
Got this curious entry in HJT that I've not seen before:

O18 - Protocol: bw90 - {E3946D81-578A-440A-B413-9A4E18C06F23} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {E3946D81-578A-440A-B413-9A4E18C06F23} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {E3946D81-578A-440A-B413-9A4E18C06F23} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {E3946D81-578A-440A-B413-9A4E18C06F23} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {E3946D81-578A-440A-B413-9A4E18C06F23} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

Thats just 4 lines of it, in the actual log file there are around 30-40 lines. In each one the "bwa0s / bwb0" part is slightly different.
I don't really require help with it as such, I was just very curious as to what it actually is :)

--Nick

ken545
2008-01-17, 03:48
Hello Nick

Welcome to Safer Networking.

Please read Before You Post (http://forums.spybot.info/showthread.php?t=288)
All advice given by anyone volunteering here, is taken at own risk.
While best efforts are made to assist in removing infections safely, unexpected stuff can happen


C:\Program Files\Logitech\Desktop Messenger <-- These are safe but show up on your log because when you installed the software for your mouse..YOU DID NOT READ THE (EULA) End User License Agreement and it installed Desktop Messenger which is not needed for your keyboard and mouse to work . You can uninstall it via the Add Remove Programs in the Control Panel.


If you feel you have malware issues than post a complete HJT log . You should have the latest version by Trendmicro, if not uninstall the older version .

Download
Trendmicros Hijackthis (http://www.trendsecure.com/portal/en-US/_download/HJTInstall.exe) to your desktop, double click it to install, follow the prompts
and by default it will install in C:\Program Files\Trendmicro\Hijackthis\Highjackthis.exe




Open HJT Scan and Save a Log File, it will open in Notepad
Go to Format and make sure Wordwrap is Unchecked
Go to Edit> Select All.....Edit > Copy and Paste the new log into this thread by using the
Post Reply and not start a New Thread.

DO NOT have HijackThis fix anything yet. Most of what it finds will be harmless or even required.