I believe I may have gotten rid of the problem using a combination of running
http://housecall.trendmicro.com in safe mode with networking, Malwarebytes Anti-Malware (also in safe mode) and Cureit. My computer and net are no longer laggy and I haven't gotten any alerts about mails being sent. However, I'm not sure if that means it won't come back since I did get rid of it once a few days ago only for it to suddenly come back nearly eight hours later, so here is the gmer log you asked me to post, just in case it's still around or something else is:
=================================
GMER 1.0.14.14536 -
http://www.gmer.netRootkit scan 2008-07-17 14:15:33
Windows 5.1.2600 Service Pack 2
---- System - GMER 1.0.14 ----
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwAlertResumeThread [0xF738583D]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwAllocateUserPhysicalPages [0xF7385847]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwAllocateVirtualMemory [0xF7385851]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwClose [0xF738585B]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwCompactKeys [0xF7385865]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwCompressKey [0xF738586F]
SSDT E1BF58C8 ZwConnectPort
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwCreateDirectoryObject [0xF7385879]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwCreateEvent [0xF7385883]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwCreateEventPair [0xF738588D]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwCreateFile [0xF4D9A820]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwCreateIoCompletion [0xF73858A1]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwCreateJobObject [0xF73858AB]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwCreateKey [0xF4DA5690]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwCreateMailslotFile [0xF73858BF]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwCreateMutant [0xF73858C9]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwCreateNamedPipeFile [0xF73858D3]
SSDT Vax347b.sys (Plug and Play BIOS Extension/ ) ZwCreatePagingFile [0xF74A0C70]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwCreatePort [0xF73858DD]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwCreateProcess [0xF73858E7]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwCreateProcessEx [0xF73858F1]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwCreateSection [0xF73858FB]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwCreateSemaphore [0xF7385905]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwCreateSymbolicLinkObject [0xF738590F]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwCreateThread [0xF7385919]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwCreateTimer [0xF7385923]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwCreateToken [0xF738592D]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwDeleteFile [0xF4D9AEA0]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwDeleteKey [0xF4DA66A0]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwDeleteValueKey [0xF4DA62E0]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwDeviceIoControlFile [0xF7385955]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwDuplicateObject [0xF738595F]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwEnumerateKey [0xF7385969]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwEnumerateValueKey [0xF7385973]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwFreeUserPhysicalPages [0xF738597D]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwFreeVirtualMemory [0xF7385987]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwImpersonateAnonymousToken [0xF7385991]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwImpersonateThread [0xF738599B]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwLoadDriver [0xF73859A5]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwLoadKey [0xF4DA69E0]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwLoadKey2 [0xF73859B9]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwLockRegistryKey [0xF73859C3]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwLockVirtualMemory [0xF73859CD]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwMapViewOfSection [0xF73859D7]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwOpenFile [0xF4D9ACF0]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwOpenKey [0xF73859EB]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwOpenProcess [0xF73859F5]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwOpenProcessToken [0xF73859FF]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwOpenSection [0xF7385A09]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwOpenThread [0xF7385A13]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwOpenThreadToken [0xF7385A1D]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwProtectVirtualMemory [0xF7385A27]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwQueryInformationProcess [0xF7385A31]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwQueryInformationThread [0xF7385A3B]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwQueryKey [0xF7385A45]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwQueryMultipleValueKey [0xF7385A4F]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwQueryOpenSubKeys [0xF7385A59]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwQueryValueKey [0xF7385A63]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwQueueApcThread [0xF7385A6D]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwReadFile [0xF7385A77]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwReadVirtualMemory [0xF7385A81]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwRenameKey [0xF7385A8B]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwReplaceKey [0xF4DA6CD0]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwRestoreKey [0xF4DA6F80]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwResumeProcess [0xF7385AA9]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwResumeThread [0xF7385AB3]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwSaveKey [0xF7385ABD]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwSaveKeyEx [0xF7385AC7]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwSaveMergedKeys [0xF7385AD1]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwSetContextThread [0xF7385ADB]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwSetInformationFile [0xF4D9B010]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwSetInformationKey [0xF7385AE5]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwSetInformationProcess [0xF7385AEF]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwSetInformationThread [0xF7385AF9]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwSetSystemInformation [0xF7385B03]
SSDT Vax347b.sys (Plug and Play BIOS Extension/ ) ZwSetSystemPowerState [0xF74AC4F0]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwSetValueKey [0xF4DA5E67]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwSuspendProcess [0xF7385B17]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwSuspendThread [0xF7385B21]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwSystemDebugControl [0xF7385B2B]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwTerminateJobObject [0xF7385B35]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwTerminateProcess [0xF7385B3F]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwTerminateThread [0xF7385B49]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwUnloadDriver [0xF7385B53]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwUnloadKey [0xF7385B5D]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwUnloadKeyEx [0xF7385B67]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwUnlockVirtualMemory [0xF7385B71]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwUnmapViewOfSection [0xF7385B7B]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwWriteFile [0xF7385B85]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/) ZwWriteVirtualMemory [0xF7385B8F]
---- Kernel code sections - GMER 1.0.14 ----
.text ntoskrnl.exe!_abnormal_termination + D7 804E2DA8 24 Bytes [ 79, 58, 38, F7, 83, 58, 38, ... ]
.text ntoskrnl.exe!_abnormal_termination + F3 804E2DC4 32 Bytes [ 90, 56, DA, F4, BF, 58, 38, ... ]
.text ntoskrnl.exe!_abnormal_termination + 117 804E2DE8 24 Bytes [ FB, 58, 38, F7, 05, 59, 38, ... ]
.text ntoskrnl.exe!_abnormal_termination + 197 804E2E68 1 Byte [ 7D ]
.text ntoskrnl.exe!_abnormal_termination + 199 804E2E6A 6 Bytes [ 38, F7, 87, 59, 38, F7 ]
.text ...
? srescan.sys The system cannot find the file specified. !
? C:\WINDOWS2\system32\Drivers\PROCEXP100.SYS The system cannot find the file specified. !
? System32\Drivers\hiber_WMILIB.SYS The system cannot find the file specified. !
---- Kernel IAT/EAT - GMER 1.0.14 ----
IAT \SystemRoot\System32\drivers\afd.sys[ntoskrnl.exe!IoCreateFile] [F4DAFFB0] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
IAT \SystemRoot\system32\DRIVERS\srv.sys[ntoskrnl.exe!NtOpenFile] [F4D9B570] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
IAT \SystemRoot\system32\DRIVERS\srv.sys[ntoskrnl.exe!NtSetInformationFile] [F4D9B4C0] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
IAT \SystemRoot\system32\DRIVERS\srv.sys[ntoskrnl.exe!IoCreateFile] [F4D9B670] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
IAT \SystemRoot\system32\DRIVERS\srv.sys[ntoskrnl.exe!NtCreateFile] [F4D9B1D0] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
---- User IAT/EAT - GMER 1.0.14 ----
IAT C:\WINDOWS2\system32\LVCOMSX.EXE[716] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00B62F60] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\WINDOWS2\system32\LVCOMSX.EXE[716] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00B62DB0] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\WINDOWS2\system32\LVCOMSX.EXE[716] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtClose] [00B62D70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\WINDOWS2\system32\LVCOMSX.EXE[716] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00B62DC0] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\uTorrent\uTorrent.exe[960] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtCreateFile] [003C2F60] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\uTorrent\uTorrent.exe[960] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [003C2DB0] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\uTorrent\uTorrent.exe[960] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtClose] [003C2D70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\uTorrent\uTorrent.exe[960] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [003C2DC0] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\RocketDock\RocketDock.exe[1384] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00B42F60] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\RocketDock\RocketDock.exe[1384] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00B42DB0] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\RocketDock\RocketDock.exe[1384] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtClose] [00B42D70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\RocketDock\RocketDock.exe[1384] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00B42DC0] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\WINDOWS2\Explorer.EXE[1796] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtCreateFile] [01212F60] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\WINDOWS2\Explorer.EXE[1796] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [01212DB0] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\WINDOWS2\Explorer.EXE[1796] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtClose] [01212D70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\WINDOWS2\Explorer.EXE[1796] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [01212DC0] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Documents and Settings\Dion A. Lewis\Desktop\Process XP.exe[2188] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtCreateFile] [003C2F60] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Documents and Settings\Dion A. Lewis\Desktop\Process XP.exe[2188] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [003C2DB0] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Documents and Settings\Dion A. Lewis\Desktop\Process XP.exe[2188] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtClose] [003C2D70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Documents and Settings\Dion A. Lewis\Desktop\Process XP.exe[2188] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [003C2DC0] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\PROGRA~1\MOZILL~1\FIREFOX.EXE[3016] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtCreateFile] [010E2F60] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\PROGRA~1\MOZILL~1\FIREFOX.EXE[3016] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [010E2DB0] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\PROGRA~1\MOZILL~1\FIREFOX.EXE[3016] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtClose] [010E2D70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\PROGRA~1\MOZILL~1\FIREFOX.EXE[3016] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [010E2DC0] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\WINDOWS2\system32\wscntfy.exe[3144] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtCreateFile] [008F2F60] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\WINDOWS2\system32\wscntfy.exe[3144] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [008F2DB0] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\WINDOWS2\system32\wscntfy.exe[3144] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtClose] [008F2D70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\WINDOWS2\system32\wscntfy.exe[3144] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [008F2DC0] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[3260] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00F02F60] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[3260] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00F02DB0] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[3260] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtClose] [00F02D70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[3260] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00F02DC0] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe[3276] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00AC2F60] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe[3276] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00AC2DB0] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe[3276] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtClose] [00AC2D70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe[3276] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00AC2DC0] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\WINDOWS2\system32\ICO.EXE[3568] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00B92F60] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\WINDOWS2\system32\ICO.EXE[3568] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00B92DB0] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\WINDOWS2\system32\ICO.EXE[3568] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtClose] [00B92D70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\WINDOWS2\system32\ICO.EXE[3568] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00B92DC0] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Common Files\Symantec Shared\ccApp.exe[3624] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00AA2F60] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Common Files\Symantec Shared\ccApp.exe[3624] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00AA2DB0] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Common Files\Symantec Shared\ccApp.exe[3624] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtClose] [00AA2D70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Common Files\Symantec Shared\ccApp.exe[3624] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00AA2DC0] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\PROGRA~1\SYMANT~1\VPTray.exe[3668] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00AC2F60] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\PROGRA~1\SYMANT~1\VPTray.exe[3668] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00AC2DB0] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\PROGRA~1\SYMANT~1\VPTray.exe[3668] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtClose] [00AC2D70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\PROGRA~1\SYMANT~1\VPTray.exe[3668] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00AC2DC0] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Documents and Settings\Dion A. Lewis\Desktop\gmer.exe[3704] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00802F60] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Documents and Settings\Dion A. Lewis\Desktop\gmer.exe[3704] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00802DB0] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Documents and Settings\Dion A. Lewis\Desktop\gmer.exe[3704] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtClose] [00802D70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Documents and Settings\Dion A. Lewis\Desktop\gmer.exe[3704] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00802DC0] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\WINDOWS2\system32\Pelmiced.exe[3780] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00B62F60] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\WINDOWS2\system32\Pelmiced.exe[3780] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00B62DB0] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\WINDOWS2\system32\Pelmiced.exe[3780] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtClose] [00B62D70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\WINDOWS2\system32\Pelmiced.exe[3780] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00B62DC0] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Trillian\trillian.exe[3892] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00B82F60] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Trillian\trillian.exe[3892] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00B82DB0] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Trillian\trillian.exe[3892] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtClose] [00B82D70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Trillian\trillian.exe[3892] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00B82DC0] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Logitech\iTouch\iTouch.exe[3896] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00C22F60] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Logitech\iTouch\iTouch.exe[3896] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00C22DB0] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Logitech\iTouch\iTouch.exe[3896] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtClose] [00C22D70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Logitech\iTouch\iTouch.exe[3896] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00C22DC0] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\PROGRA~1\AVG\AVG8\avgtray.exe[3936] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00C72F60] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\PROGRA~1\AVG\AVG8\avgtray.exe[3936] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00C72DB0] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\PROGRA~1\AVG\AVG8\avgtray.exe[3936] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtClose] [00C72D70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\PROGRA~1\AVG\AVG8\avgtray.exe[3936] @ C:\WINDOWS2\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00C72DC0] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
---- Devices - GMER 1.0.14 ----
Device \FileSystem\Ntfs \Ntfs 84396EB8
AttachedDevice \FileSystem\Ntfs \Ntfs pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/)
AttachedDevice \FileSystem\Ntfs \Ntfs SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)
Device \FileSystem\Fastfat \FatCdrom 83EFDFB0
Device \Driver\Tcpip \Device\Ip vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip pxtdi.sys (PREVX Security Agent for Windows. TDI module/Prevx Limited,
http://www.prevx1.com/)
AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
Device \Driver\Tcpip \Device\Tcp vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
AttachedDevice \Driver\Tcpip \Device\Tcp pxtdi.sys (PREVX Security Agent for Windows. TDI module/Prevx Limited,
http://www.prevx1.com/)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
Device \Driver\Cdrom \Device\CdRom0 84008708
Device \FileSystem\Rdbss \Device\FsWrap 840D3FB0
Device \Driver\Cdrom \Device\CdRom1 84008708
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 84004570
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 84004570
Device \Driver\atapi \Device\Ide\IdePort0 84004570
Device \Driver\atapi \Device\Ide\IdePort1 84004570
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f 84004570
Device \Driver\Cdrom \Device\CdRom2 84008708
Device \FileSystem\Srv \Device\LanmanServer 8406E0F0
Device \Driver\Tcpip \Device\Udp vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
AttachedDevice \Driver\Tcpip \Device\Udp pxtdi.sys (PREVX Security Agent for Windows. TDI module/Prevx Limited,
http://www.prevx1.com/)
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
Device \Driver\Tcpip \Device\RawIp vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
AttachedDevice \Driver\Tcpip \Device\RawIp pxtdi.sys (PREVX Security Agent for Windows. TDI module/Prevx Limited,
http://www.prevx1.com/)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 840D2A88
Device \Driver\Tcpip \Device\IPMULTICAST vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
Device \FileSystem\MRxSmb \Device\LanmanRedirector 840D2A88
Device \FileSystem\Npfs \Device\NamedPipe 840D1780
Device \FileSystem\Msfs \Device\Mailslot 840C8348
Device \Driver\Vax347s \Device\Scsi\Vax347s1 840F3680
Device \Driver\Vax347s \Device\Scsi\Vax347s1Port2Path0Target0Lun0 840F3680
Device \FileSystem\Fastfat \Fat 83EFDFB0
AttachedDevice \FileSystem\Fastfat \Fat pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited,
http://www.prevx1.com/)
AttachedDevice \FileSystem\Fastfat \Fat SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)
Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer 840C16D8
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer 840C16D8
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer 840C16D8
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer 840C16D8
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer 840C16D8
Device \FileSystem\Cdfs \Cdfs 840DC620
---- Modules - GMER 1.0.14 ----
Module _________ F7403000-F741B000 (98304 bytes)
---- Registry - GMER 1.0.14 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\Vax347s\Config\jdgg40
Reg HKLM\SYSTEM\CurrentControlSet\Services\Vax347s\Config\jdgg40@ujdew 0x20 0x02 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\Vax347s\Config\jdgg40@ljej40 0x07 0x68 0x3A 0xE0 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E9F81423-211E-46B6-9AE0-38568BC5CF6F}@DisplayName Alcohol 120%
Reg HKLM\SOFTWARE\Classes\Installer\Products\32418F9EE1126B64A90E8365B85CFCF6@ProductName Alcohol 120%
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{24BEAAA5-A423-AD78-E1B5-DE88EC632237}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{24BEAAA5-A423-AD78-E1B5-DE88EC632237}@bbbpgipcccofbhmbcaemblgbmilgekfmpiab 0x61 0x62 0x6F 0x66 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{24BEAAA5-A423-AD78-E1B5-DE88EC632237}@abbpgipcccofbhmbcanbmkijiimfbajlpa 0x61 0x62 0x70 0x66 ...
---- EOF - GMER 1.0.14 ----
=================================
Thanks for the help.