Here is the fresh HijackThis log:
Logfile of HijackThis v1.99.1
Scan saved at 10:18:51 AM, on 7/17/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\CA\eTrust\Antivirus\InoRpc.exe
C:\Program Files\CA\eTrust\Antivirus\InoRT.exe
C:\Program Files\CA\eTrust\Antivirus\InoTask.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\CA\eTrust\Antivirus\realmon.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\Program Files\Novosoft\Handy Backup\hbagent.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\Hijackthis\HijackThis.exe
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Business Objects\JRE\bin\jusched.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = corp.paceengrs.com
O17 - HKLM\Software\..\Telephony: DomainName = corp.paceengrs.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = corp.paceengrs.com
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
Here is the Blacklight log:
07/17/06 10:22:35 [Info]: BlackLight Engine 1.0.42 initialized
07/17/06 10:22:35 [Info]: OS: 5.1 build 2600 (Service Pack 2)
07/17/06 10:22:37 [Note]: 7019 4
07/17/06 10:22:37 [Note]: 7005 0
07/17/06 10:22:43 [Note]: 7006 0
07/17/06 10:22:43 [Note]: 7011 2200
07/17/06 10:22:43 [Note]: 7026 0
07/17/06 10:22:43 [Note]: 7026 0
07/17/06 10:22:56 [Note]: FSRAW library version 1.7.1019
07/17/06 10:25:53 [Info]: Hidden file: c:\WINDOWS\system32\csrqk.exe
07/17/06 10:25:53 [Note]: 7002 32
07/17/06 10:25:53 [Note]: 7003 1
07/17/06 10:25:53 [Note]: 10002 1
07/17/06 10:25:53 [Info]: Hidden file: c:\WINDOWS\system32\dmqee.exe
07/17/06 10:25:53 [Note]: 7002 32
07/17/06 10:25:53 [Note]: 7003 1
07/17/06 10:25:53 [Note]: 10002 1
07/17/06 10:25:57 [Info]: Hidden file: c:\WINDOWS\system32\{252CE89A-369A-48C8-A994-77C5BA23A844}.exe
07/17/06 10:25:57 [Note]: 10002 1
07/17/06 10:25:58 [Info]: Hidden file: c:\WINDOWS\system32\{82FDD3F7-866E-45B5-A0C5-BCFC693AA205}.exe
07/17/06 10:25:58 [Note]: 10002 1
07/17/06 10:25:58 [Info]: Hidden file: c:\WINDOWS\system32\{96206F22-1153-44CE-9192-D6C7ABCB45D5}.exe
07/17/06 10:25:58 [Note]: 10002 1
07/17/06 10:25:58 [Info]: Hidden file: c:\WINDOWS\system32\{B2A43A4A-CB16-4765-9BB1-8EEC601E45BF}.exe
07/17/06 10:25:58 [Note]: 10002 1
07/17/06 10:31:42 [Note]: 7007 0