I've run Hijack this in safe mode, which seems to return a better result (including a process called "dukk.exe"). Otherwise it's the two processes at the end that keep reappearing whenever I restart.
Thanks!
- Greg
Logfile of HijackThis v1.97.7
Scan saved at 10:09:40 PM, on 10/25/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINNT\GWHotKey.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\PROGRA~1\LEXMAR~1\ACMonitor_X83.exe
C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X83.exe
C:\Program Files\DIGStream\digstream.exe
C:\WINNT\GWMDMMSG.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mm_tray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Updater.exe
C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
C:\Program Files\AIM95\aim.exe
C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
C:\Program Files\Linksys\Configure Utility\Config.exe
C:\WINNT\system32\LVComS.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mim.exe
C:\Program Files\ORiNOCO\Client Manager\CmLUC.exe
C:\WINNT\System32\Ati2evxx.exe
C:\WINNT\R3JlZ29yeQAA\command.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINNT\system32\RioMSC.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\wdfmgr.exe
C:\WINNT\vsbgjvv.exe
C:\WINNT\system32\fxssvc.exe
C:\WINNT\System32\alg.exe
C:\Program Files\HijackThis.exe
C:\WINNT\system32\wuauclt.exe
O4 - HKLM\..\Run: [winsync] C:\WINNT\system32\kxggks.exe reg_run
O4 - HKLM\..\Run: [zvdmbwn] C:\WINNT\zvdmbwn.exe