I've got a wheelchair icon that seems to rotate between that and a red "not" symbol circle with a diagonal slash through it. I believe this is related to a zlob downloader or something. So here's my Full logs.
Logfile of HijackThis v1.99.1
Scan saved at 2:41:28 PM, on 4/25/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2
(6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Stardock\THINKD~1\MULTIP~1
\MULTIS~2.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Logitech\G-series
Software\LGDCore.exe
C:\Program Files\Logitech\G-series
Software\LCDMon.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program
Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\NVIDIA
Corporation\NvMixer\NVMixerTray.exe
C:\Program Files\Logitech\G-series
Software\Applets\LCDClock.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\Program
Files\HighCriteria\TotalRecorder\TotRecSched.
exe
C:\Program Files\Logitech\G-series
Software\Applets\LCDMedia.exe
C:\Program Files\Motherboard Monitor 5
\MBM5.EXE
C:\Program Files\Java\jre1.5.0_06
\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\?icrosoft.NET\n?tepad.exe
C:\Program Files\ewido\security
suite\ewidoctrl.exe
C:\Program Files\ewido\security
suite\ewidoguard.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Alcohol Soft\Alcohol 120
\StarWind\StarWindService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\Internet
Explorer\IEXPLORE.EXE
C:\Program Files\Hijackthis\HijackThis.exe
R3 - URLSearchHook: (no name) - {1DF9DFC3-
670C-4AF8-2C05-3FB6791EACCA} -
C:\WINDOWS\system32\srd.dll (file missing)
O2 - BHO: Nothing - {edbf1bc8-39ab-48eb-a0a9
-c75078eb7c8e} - C:\WINDOWS\system32
\hpC107.tmp (file missing)
O4 - HKLM\..\Run: [Launch LGDCore]
"C:\Program Files\Logitech\G-series
Software\LGDCore.exe" /SHOWHIDE
O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program
Files\Logitech\G-series Software\LCDMon.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE
C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter]
RUNDLL32.EXE C:\WINDOWS\system32
\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RemoteControl] "C:\Program
Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program
Files\NVIDIA
Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [TotalRecorderScheduler]
"C:\Program
Files\HighCriteria\TotalRecorder\TotRecSched.
exe"
O4 - HKLM\..\Run: [MBM 5] "C:\Program
Files\Motherboard Monitor 5\MBM5.EXE"
O4 - HKLM\..\Run: [SunJavaUpdateSched]
C:\Program Files\Java\jre1.5.0_06
\bin\jusched.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1
\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program
Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Rnss] "C:\PROGRA~1
\COMMON~1\SKS~1\wuauclt.exe" -vt yax
O4 - HKCU\..\Run: [Kasyhvc] C:\Program
Files\?icrosoft.NET\n?tepad.exe
O4 - Startup: Xfire.lnk = C:\Program
Files\Xfire\Xfire.exe
O9 - Extra button: (no name) - {08B0E5C0-
4FCB-11CF-AAA5-00401C608501} - C:\Program
Files\Java\jre1.5.0_06\bin\ssv.dll (file
missing)
O9 - Extra 'Tools' menuitem: Sun Java Console
- {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
(file missing)
O9 - Extra button: Messenger - {FB5F1910-
F110-11d2-BB9E-00C04F795683} - C:\Program
Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows
Messenger - {FB5F1910-F110-11d2-BB9E-
00C04F795683} - C:\Program
Files\Messenger\msmsgs.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-
A7ADCBF9BD02} (HouseCall Control) -
http://housecall60.trendmicro.com/housecall/x
scan60.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-
4EB7002E68AE} (Housecall ActiveX 6.5) -
http://housecall65.trendmicro.com/housecall/a
pplet/html/native/x86/win32/activex/hcImpl.ca
b
O16 - DPF: {74CD40EA-EF77-4BAD-808A-
B5982DA73F20} (YazzleActiveX Control) -
http://yax-
download.yazzle.net/YazzleActiveX.cab?
refid=1162
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-
5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoftware.com/activescan/as5fr
ee/asinst.cab
O20 - Winlogon Notify: Multi - C:\Program
Files\Stardock\ThinkDesk\Multiplicity\MultiWi
n32.dll
O20 - Winlogon Notify: winuqw32 -
winuqw32.dll (file missing)
O23 - Service: AVG7 Alert Manager Server
(Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1
\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service
(Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1
\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) -
GRISOFT, s.r.o. - C:\PROGRA~1
\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ewido security suite control -
ewido networks - C:\Program
Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard -
ewido networks - C:\Program
Files\ewido\security suite\ewidoguard.exe
O23 - Service: InstallDriver Table Manager
(IDriverT) - Macrovision Corporation -
C:\Program Files\Common
Files\InstallShield\Driver\11\Intel 32
\IDriverT.exe
O23 - Service: Macromedia Licensing Service -
Unknown owner - C:\Program Files\Common
Files\Macromedia Shared\Service\Macromedia
Licensing.exe
O23 - Service: Stardock Multiplicity
(Multiplicity) - Unknown owner - C:\PROGRA~1
\Stardock\THINKD~1\MULTIP~1\MULTIS~2.EXE
O23 - Service: NVIDIA Display Driver Service
(NVSvc) - NVIDIA Corporation -
C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: StarWind iSCSI Service
(StarWindService) - Rocket Division Software
- C:\Program Files\Alcohol Soft\Alcohol 120
\StarWind\StarWindService.exe
Logfile of HijackThis v1.99.1
Scan saved at 2:41:28 PM, on 4/25/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2
(6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Stardock\THINKD~1\MULTIP~1
\MULTIS~2.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Logitech\G-series
Software\LGDCore.exe
C:\Program Files\Logitech\G-series
Software\LCDMon.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program
Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\NVIDIA
Corporation\NvMixer\NVMixerTray.exe
C:\Program Files\Logitech\G-series
Software\Applets\LCDClock.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\Program
Files\HighCriteria\TotalRecorder\TotRecSched.
exe
C:\Program Files\Logitech\G-series
Software\Applets\LCDMedia.exe
C:\Program Files\Motherboard Monitor 5
\MBM5.EXE
C:\Program Files\Java\jre1.5.0_06
\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\?icrosoft.NET\n?tepad.exe
C:\Program Files\ewido\security
suite\ewidoctrl.exe
C:\Program Files\ewido\security
suite\ewidoguard.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Alcohol Soft\Alcohol 120
\StarWind\StarWindService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\Internet
Explorer\IEXPLORE.EXE
C:\Program Files\Hijackthis\HijackThis.exe
R3 - URLSearchHook: (no name) - {1DF9DFC3-
670C-4AF8-2C05-3FB6791EACCA} -
C:\WINDOWS\system32\srd.dll (file missing)
O2 - BHO: Nothing - {edbf1bc8-39ab-48eb-a0a9
-c75078eb7c8e} - C:\WINDOWS\system32
\hpC107.tmp (file missing)
O4 - HKLM\..\Run: [Launch LGDCore]
"C:\Program Files\Logitech\G-series
Software\LGDCore.exe" /SHOWHIDE
O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program
Files\Logitech\G-series Software\LCDMon.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE
C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter]
RUNDLL32.EXE C:\WINDOWS\system32
\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RemoteControl] "C:\Program
Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program
Files\NVIDIA
Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [TotalRecorderScheduler]
"C:\Program
Files\HighCriteria\TotalRecorder\TotRecSched.
exe"
O4 - HKLM\..\Run: [MBM 5] "C:\Program
Files\Motherboard Monitor 5\MBM5.EXE"
O4 - HKLM\..\Run: [SunJavaUpdateSched]
C:\Program Files\Java\jre1.5.0_06
\bin\jusched.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1
\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program
Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Rnss] "C:\PROGRA~1
\COMMON~1\SKS~1\wuauclt.exe" -vt yax
O4 - HKCU\..\Run: [Kasyhvc] C:\Program
Files\?icrosoft.NET\n?tepad.exe
O4 - Startup: Xfire.lnk = C:\Program
Files\Xfire\Xfire.exe
O9 - Extra button: (no name) - {08B0E5C0-
4FCB-11CF-AAA5-00401C608501} - C:\Program
Files\Java\jre1.5.0_06\bin\ssv.dll (file
missing)
O9 - Extra 'Tools' menuitem: Sun Java Console
- {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
(file missing)
O9 - Extra button: Messenger - {FB5F1910-
F110-11d2-BB9E-00C04F795683} - C:\Program
Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows
Messenger - {FB5F1910-F110-11d2-BB9E-
00C04F795683} - C:\Program
Files\Messenger\msmsgs.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-
A7ADCBF9BD02} (HouseCall Control) -
http://housecall60.trendmicro.com/housecall/x
scan60.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-
4EB7002E68AE} (Housecall ActiveX 6.5) -
http://housecall65.trendmicro.com/housecall/a
pplet/html/native/x86/win32/activex/hcImpl.ca
b
O16 - DPF: {74CD40EA-EF77-4BAD-808A-
B5982DA73F20} (YazzleActiveX Control) -
http://yax-
download.yazzle.net/YazzleActiveX.cab?
refid=1162
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-
5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoftware.com/activescan/as5fr
ee/asinst.cab
O20 - Winlogon Notify: Multi - C:\Program
Files\Stardock\ThinkDesk\Multiplicity\MultiWi
n32.dll
O20 - Winlogon Notify: winuqw32 -
winuqw32.dll (file missing)
O23 - Service: AVG7 Alert Manager Server
(Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1
\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service
(Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1
\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) -
GRISOFT, s.r.o. - C:\PROGRA~1
\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ewido security suite control -
ewido networks - C:\Program
Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard -
ewido networks - C:\Program
Files\ewido\security suite\ewidoguard.exe
O23 - Service: InstallDriver Table Manager
(IDriverT) - Macrovision Corporation -
C:\Program Files\Common
Files\InstallShield\Driver\11\Intel 32
\IDriverT.exe
O23 - Service: Macromedia Licensing Service -
Unknown owner - C:\Program Files\Common
Files\Macromedia Shared\Service\Macromedia
Licensing.exe
O23 - Service: Stardock Multiplicity
(Multiplicity) - Unknown owner - C:\PROGRA~1
\Stardock\THINKD~1\MULTIP~1\MULTIS~2.EXE
O23 - Service: NVIDIA Display Driver Service
(NVSvc) - NVIDIA Corporation -
C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: StarWind iSCSI Service
(StarWindService) - Rocket Division Software
- C:\Program Files\Alcohol Soft\Alcohol 120
\StarWind\StarWindService.exe