Again Thanks for the Help. I hope I did everthing right. Okay
Here is the first Report You Requested (After the AVG Anti Spyware Scan)---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 1:00:05 PM 11/11/2006
+ Scan result:
C:\System Volume Information\_restore{00EFF98B-5705-4D9A-BA78-7681A60AFB54}\RP44\A0009766.DLL -> Adware.FunWeb : Cleaned.
C:\Program Files\MyWebSearch\bar\1.bin\M3IDLE.DLL -> Adware.IWon : Cleaned.
C:\System Volume Information\_restore{00EFF98B-5705-4D9A-BA78-7681A60AFB54}\RP26\A0007858.ocx -> Adware.MediaMotor : Cleaned.
C:\System Volume Information\_restore{00EFF98B-5705-4D9A-BA78-7681A60AFB54}\RP26\A0007859.exe -> Adware.MediaMotor : Cleaned.
C:\System Volume Information\_restore{00EFF98B-5705-4D9A-BA78-7681A60AFB54}\RP26\A0007860.exe -> Adware.MediaMotor : Cleaned.
C:\System Volume Information\_restore{00EFF98B-5705-4D9A-BA78-7681A60AFB54}\RP26\A0007861.ocx -> Adware.MediaMotor : Cleaned.
C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE -> Adware.MyWebSearch : Cleaned.
C:\Program Files\NewDotNet -> Adware.NewDotNet : Cleaned.
C:\System Volume Information\_restore{00EFF98B-5705-4D9A-BA78-7681A60AFB54}\RP26\A0007850.dll -> Adware.NewDotNet : Cleaned.
C:\System Volume Information\_restore{00EFF98B-5705-4D9A-BA78-7681A60AFB54}\RP26\A0007851.exe -> Adware.NewDotNet : Cleaned.
C:\System Volume Information\_restore{00EFF98B-5705-4D9A-BA78-7681A60AFB54}\RP26\A0007852.exe -> Adware.NewDotNet : Cleaned.
C:\System Volume Information\_restore{00EFF98B-5705-4D9A-BA78-7681A60AFB54}\RP26\A0007853.exe -> Adware.NewDotNet : Cleaned.
C:\System Volume Information\_restore{00EFF98B-5705-4D9A-BA78-7681A60AFB54}\RP26\A0007854.exe -> Adware.NewDotNet : Cleaned.
C:\System Volume Information\_restore{00EFF98B-5705-4D9A-BA78-7681A60AFB54}\RP46\A0009911.exe -> Adware.NewDotNet : Cleaned.
C:\System Volume Information\_restore{00EFF98B-5705-4D9A-BA78-7681A60AFB54}\RP26\A0007856.exe -> Adware.SaveNow : Cleaned.
C:\System Volume Information\_restore{00EFF98B-5705-4D9A-BA78-7681A60AFB54}\RP26\A0007857.exe -> Adware.SaveNow : Cleaned.
C:\System Volume Information\_restore{00EFF98B-5705-4D9A-BA78-7681A60AFB54}\RP26\A0007855.exe -> Adware.SurfSide : Cleaned.
C:\System Volume Information\_restore{00EFF98B-5705-4D9A-BA78-7681A60AFB54}\RP26\A0007862.exe -> Adware.ZenoSearch : Cleaned.
C:\System Volume Information\_restore{00EFF98B-5705-4D9A-BA78-7681A60AFB54}\RP26\A0007847.exe -> Downloader.Adload.hg : Cleaned.
C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\GEVLDQQC\ab_02[1].exe -> Downloader.Agent.bai : Cleaned.
C:\Documents and Settings\NetworkService\Local Settings\Temp\Temporary Internet Files\Content.IE5\HWVTTUUL\ab_02[1].exe -> Downloader.Agent.bai : Cleaned.
C:\System Volume Information\_restore{00EFF98B-5705-4D9A-BA78-7681A60AFB54}\RP26\A0007697.exe -> Downloader.Agent.bai : Cleaned.
C:\System Volume Information\_restore{00EFF98B-5705-4D9A-BA78-7681A60AFB54}\RP26\A0007894.exe -> Downloader.Agent.bai : Cleaned.
C:\System Volume Information\_restore{00EFF98B-5705-4D9A-BA78-7681A60AFB54}\RP46\A0009921.dll -> Downloader.Agent.bai : Cleaned.
C:\System Volume Information\_restore{00EFF98B-5705-4D9A-BA78-7681A60AFB54}\RP46\A0009922.dll -> Downloader.Agent.bai : Cleaned.
C:\Program Files\MyWebSearch\bar\1.bin\F3HTTPCT.DLL -> Downloader.IstBar : Cleaned.
C:\System Volume Information\_restore{00EFF98B-5705-4D9A-BA78-7681A60AFB54}\RP26\A0007849.ocx -> Downloader.IstBar : Cleaned.
C:\System Volume Information\_restore{00EFF98B-5705-4D9A-BA78-7681A60AFB54}\RP26\A0007848.exe -> Downloader.Qoologic.at : Cleaned.
C:\System Volume Information\_restore{00EFF98B-5705-4D9A-BA78-7681A60AFB54}\RP26\A0007845.exe -> Downloader.Small.cyh : Cleaned.
C:\System Volume Information\_restore{00EFF98B-5705-4D9A-BA78-7681A60AFB54}\RP26\A0007846.exe -> Downloader.Small.cyh : Cleaned.
C:\System Volume Information\_restore{00EFF98B-5705-4D9A-BA78-7681A60AFB54}\RP26\A0007843.exe -> Downloader.Small.cyq : Cleaned.
C:\System Volume Information\_restore{00EFF98B-5705-4D9A-BA78-7681A60AFB54}\RP26\A0007840.exe -> Downloader.Small.dxm : Cleaned.
C:\System Volume Information\_restore{00EFF98B-5705-4D9A-BA78-7681A60AFB54}\RP26\A0007841.exe -> Downloader.Small.dxm : Cleaned.
C:\System Volume Information\_restore{00EFF98B-5705-4D9A-BA78-7681A60AFB54}\RP26\A0007842.exe -> Downloader.Small.dxm : Cleaned.
C:\System Volume Information\_restore{00EFF98B-5705-4D9A-BA78-7681A60AFB54}\RP26\A0007652.exe -> Downloader.Tibs.ir : Cleaned.
C:\System Volume Information\_restore{00EFF98B-5705-4D9A-BA78-7681A60AFB54}\RP26\A0007837.exe -> Downloader.Tibs.ir : Cleaned.
C:\System Volume Information\_restore{00EFF98B-5705-4D9A-BA78-7681A60AFB54}\RP26\A0007838.exe -> Downloader.Tibs.ir : Cleaned.
C:\System Volume Information\_restore{00EFF98B-5705-4D9A-BA78-7681A60AFB54}\RP26\A0007839.exe -> Downloader.Tibs.ir : Cleaned.
C:\System Volume Information\_restore{00EFF98B-5705-4D9A-BA78-7681A60AFB54}\RP25\A0004604.exe -> Downloader.Zlob.avo : Cleaned.
C:\System Volume Information\_restore{00EFF98B-5705-4D9A-BA78-7681A60AFB54}\RP26\A0007891.exe -> Downloader.Zlob.avo : Cleaned.
C:\System Volume Information\_restore{00EFF98B-5705-4D9A-BA78-7681A60AFB54}\RP26\A0007893.exe -> Downloader.Zlob.avo : Cleaned.
C:\System Volume Information\_restore{00EFF98B-5705-4D9A-BA78-7681A60AFB54}\RP26\A0007905.exe -> Downloader.Zlob.avo : Cleaned.
C:\System Volume Information\_restore{00EFF98B-5705-4D9A-BA78-7681A60AFB54}\RP26\A0007844.exe -> Dropper.Agent.mu : Cleaned.
C:\System Volume Information\_restore{00EFF98B-5705-4D9A-BA78-7681A60AFB54}\RP25\A0004592.dll -> Hijacker.Small.ja : Cleaned.
C:\System Volume Information\_restore{00EFF98B-5705-4D9A-BA78-7681A60AFB54}\RP26\A0007598.dll -> Hijacker.Small.ja : Cleaned.
C:\System Volume Information\_restore{00EFF98B-5705-4D9A-BA78-7681A60AFB54}\RP26\A0007599.exe -> Hijacker.Small.ja : Cleaned.
C:\System Volume Information\_restore{00EFF98B-5705-4D9A-BA78-7681A60AFB54}\RP26\A0007711.exe -> Hijacker.Small.ja : Cleaned.
C:\System Volume Information\_restore{00EFF98B-5705-4D9A-BA78-7681A60AFB54}\RP26\A0007723.exe -> Hijacker.Small.ja : Cleaned.
C:\System Volume Information\_restore{00EFF98B-5705-4D9A-BA78-7681A60AFB54}\RP26\A0007921.exe -> Hijacker.Small.ja : Cleaned.
C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Compaq_Owner\Cookies\
[email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@adrevolver[1].txt -> TrackingCookie.Adrevolver : Cleaned.
C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@advertising[1].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@bluestreak[2].txt -> TrackingCookie.Bluestreak : Cleaned.
C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@casalemedia[1].txt -> TrackingCookie.Casalemedia : Cleaned.
C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Compaq_Owner\Cookies\
[email protected][2].txt -> TrackingCookie.Euroclick : Cleaned.
C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\Compaq_Owner\Cookies\
[email protected][2].txt -> TrackingCookie.Pointroll : Cleaned.
C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\Compaq_Owner\Cookies\
[email protected][1].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@trafficmp[2].txt -> TrackingCookie.Trafficmp : Cleaned.
C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Documents and Settings\Compaq_Owner\Cookies\
[email protected][2].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\System Volume Information\_restore{00EFF98B-5705-4D9A-BA78-7681A60AFB54}\RP26\A0007606.exe -> Trojan.Kolweb.b : Cleaned.
C:\System Volume Information\_restore{00EFF98B-5705-4D9A-BA78-7681A60AFB54}\RP26\A0007607.dll -> Trojan.Kolweb.b : Cleaned.
::Report end
I did get the PendingFileRenameOperations prompt. The exact message was ((PendingFileRenameOperations Registry Data has been Removed by External Process!
Second Report (((After comboxfix)))Compaq_Owner - 06-11-11 13:55:04.68 Service Pack 2
ComboFix 06.11.9 - Running from: "C:\Documents and Settings\Compaq_Owner\Desktop"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\Documents and Settings\LocalService\Application Data\NetMon
((((((((((((((((((((((((((((((( Files Created from 2006-10-11 to 2006-11-11 ))))))))))))))))))))))))))))))))))
2006-11-11 11:11 816,672 --a------ C:\WINDOWS\system32\drivers\avg7core.sys
2006-11-11 11:11 4,960 --a------ C:\WINDOWS\system32\drivers\avgtdi.sys
2006-11-11 11:11 4,224 --a------ C:\WINDOWS\system32\drivers\avg7rsw.sys
2006-11-11 11:11 3,968 --a------ C:\WINDOWS\system32\drivers\avgclean.sys
2006-11-11 11:11 28,416 --a------ C:\WINDOWS\system32\drivers\avg7rsxp.sys
2006-11-11 11:11 18,240 --a------ C:\WINDOWS\system32\drivers\avgmfx86.sys
2006-11-11 03:23 1,946 --a------ C:\WINDOWS\system32\tmp.reg
2006-11-08 23:15 28,672 --a------ C:\WINDOWS\system32\f3PSSavr.scr
2006-10-28 13:31 118,784 --a------ C:\WINDOWS\dsdxirmv.exe
2006-10-27 01:05 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2006-10-27 00:53 26,624 --a------ C:\WINDOWS\system32\rpcc.dll
2006-10-23 10:45 983,107 --a------ C:\WINDOWS\system32\LXCZGF.DLL
2006-10-23 10:45 90,112 --a------ C:\WINDOWS\system32\LXCZCUR.DLL
2006-10-23 10:45 87,040 --a------ C:\WINDOWS\system32\wiafbdrv.dll
2006-10-23 10:45 73,728 --a------ C:\WINDOWS\system32\lxczpwr.dll
2006-10-23 10:45 69,632 --a------ C:\WINDOWS\system32\lxczscin.dll
2006-10-23 10:45 69,632 --a------ C:\WINDOWS\system32\LXCZCU.DLL
2006-10-23 10:45 57,344 --a------ C:\WINDOWS\system32\lxczcinf.dll
2006-10-23 10:45 49,152 --a------ C:\WINDOWS\system32\lxczcoin.dll
2006-10-23 10:45 40,960 --a------ C:\WINDOWS\system32\lxczvs.dll
2006-10-23 10:45 40,960 --a------ C:\WINDOWS\system32\INSTMON.EXE
2006-10-23 10:45 356,352 --a------ C:\WINDOWS\system32\LXCZUTIL.DLL
2006-10-23 10:45 311,296 --a------ C:\WINDOWS\system32\LEXBCES.EXE
2006-10-23 10:45 201,216 --a------ C:\WINDOWS\system32\LEXP2P32.DLL
2006-10-23 10:45 200,704 --a------ C:\WINDOWS\system32\LEXLMPM.DLL
2006-10-23 10:45 198,144 --a------ C:\WINDOWS\system32\LEX2KUSB.DLL
2006-10-23 10:45 174,592 --a------ C:\WINDOWS\system32\LEXPPS.EXE
2006-10-23 10:45 155,648 --a------ C:\WINDOWS\system32\LEXPING.EXE
2006-10-23 10:45 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2006-10-23 10:45 147,456 --a------ C:\WINDOWS\system32\LEXBCE.DLL
2006-10-23 10:44 458,752 --a------ C:\WINDOWS\system32\LXCZJSWR.DLL
2006-10-23 10:43 299,520 --a------ C:\WINDOWS\uninst.exe
2006-10-23 01:15 446,464 -ra------ C:\WINDOWS\system32\softcoin.dll
2006-10-23 01:15 327,680 -ra------ C:\WINDOWS\system32\gencoin.dll
2006-10-23 01:03 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2006-10-20 08:45 180,224 --a------ C:\WINDOWS\system32\ReWire.dll
2006-10-17 13:33 6,049,280 --------- C:\WINDOWS\system32\ieframe.dll
2006-10-17 13:33 50,688 --------- C:\WINDOWS\system32\msfeedsbs.dll
2006-10-17 13:33 458,752 --------- C:\WINDOWS\system32\msfeeds.dll
2006-10-17 13:33 180,736 --------- C:\WINDOWS\system32\ieui.dll
2006-10-17 13:05 206,336 --------- C:\WINDOWS\system32\WinFXDocObj.exe
2006-10-17 12:58 61,952 --------- C:\WINDOWS\system32\icardie.dll
2006-10-17 12:58 12,288 --------- C:\WINDOWS\system32\msfeedssync.exe
2006-10-17 12:57 266,752 --------- C:\WINDOWS\system32\iertutil.dll
2006-10-17 12:27 380,928 --------- C:\WINDOWS\system32\ieapfltr.dll
2006-10-13 13:09 8,464 --a------ C:\WINDOWS\system32\sporder.dll
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-11-11 13:40 -------- d-------- C:\Program Files\Hijackthis
2006-11-11 13:38 -------- d-------- C:\Program Files\CCleaner
2006-11-11 11:12 -------- d-------- C:\Documents and Settings\Compaq_Owner\Application Data\AVG7
2006-11-11 11:11 -------- d-------- C:\Program Files\Grisoft
2006-11-11 02:37 -------- d-------- C:\Program Files\Morpheus
2006-11-09 22:55 -------- d-------- C:\Program Files\FunWebProducts
2006-11-08 23:15 -------- d-------- C:\Program Files\Internet Explorer
2006-11-08 14:02 -------- d-------- C:\Documents and Settings\Compaq_Owner\Application Data\AdobeUM
2006-11-07 23:57 -------- d---s---- C:\Documents and Settings\Compaq_Owner\Application Data\Microsoft
2006-11-05 19:57 160 --a------ C:\Documents and Settings\Compaq_Owner\Application Data\wklnhst.dat
2006-11-05 12:50 -------- d-------- C:\Program Files\Image-Line
2006-11-05 12:49 -------- d-------- C:\Program Files\VstPlugins
2006-10-31 08:54 -------- d-------- C:\Documents and Settings\Compaq_Owner\Application Data\HP
2006-10-28 13:52 -------- d-------- C:\Documents and Settings\Compaq_Owner\Application Data\Sonic
2006-10-28 13:52 -------- d-------- C:\Documents and Settings\Compaq_Owner\Application Data\Leadertech
2006-10-28 13:34 -------- d-------- C:\Documents and Settings\Compaq_Owner\Application Data\Cakewalk
2006-10-28 13:33 -------- d-------- C:\Program Files\Cakewalk
2006-10-28 13:31 -------- d--h----- C:\Program Files\InstallShield Installation Information
2006-10-27 02:48 -------- d--h----- C:\Program Files\WindowsUpdate
2006-10-27 02:48 -------- d-------- C:\Program Files\ComPlus Applications
2006-10-27 00:17 -------- d-------- C:\Program Files\microsoft frontpage
2006-10-27 00:17 -------- d-------- C:\Program Files\BHO Plugin
2006-10-27 00:15 4327 --ahs---- C:\Documents and Settings\Compaq_Owner\Application Data\C420940D68404048A18250B4D80E27A7.sta
2006-10-27 00:15 17358 --ahs---- C:\Documents and Settings\Compaq_Owner\Application Data\C420940D68404048A18250B4D80E27A7.rul
2006-10-26 23:57 -------- d-------- C:\Program Files\Common Files
2006-10-23 10:45 -------- d-------- C:\Program Files\Lexmark 1200 Series
2006-10-23 10:16 -------- d-------- C:\Documents and Settings\Compaq_Owner\Application Data\Help
2006-10-20 09:00 -------- d-------- C:\Documents and Settings\Compaq_Owner\Application Data\Lavasoft
2006-10-20 08:59 -------- d-------- C:\Program Files\Lavasoft
2006-10-20 08:31 -------- d-------- C:\Documents and Settings\Compaq_Owner\Application Data\HPQ
2006-10-18 22:52 -------- d-------- C:\Program Files\Java
2006-10-18 11:08 -------- d-------- C:\Documents and Settings\Compaq_Owner\Application Data\Real
2006-10-17 13:33 413696 --a------ C:\WINDOWS\system32\vbscript.dll
2006-10-17 13:33 231424 --a------ C:\WINDOWS\system32\webcheck.dll
2006-10-17 13:33 156160 --a------ C:\WINDOWS\system32\msls31.dll
2006-10-17 13:06 78336 --a------ C:\WINDOWS\system32\ieencode.dll
2006-10-17 13:05 40960 --a------ C:\WINDOWS\system32\licmgr10.dll
2006-10-17 13:05 105984 --a------ C:\WINDOWS\system32\url.dll
2006-10-17 13:04 101376 --a------ C:\WINDOWS\system32\occache.dll
2006-10-17 13:03 17408 --a------ C:\WINDOWS\system32\corpol.dll
2006-10-17 13:01 71680 --a------ C:\WINDOWS\system32\admparse.dll
2006-10-17 13:01 55296 --a------ C:\WINDOWS\system32\iesetup.dll
2006-10-17 13:01 382976 --a------ C:\WINDOWS\system32\iedkcs32.dll
2006-10-17 13:01 229376 --a------ C:\WINDOWS\system32\ieaksie.dll
2006-10-17 13:01 152064 --a------ C:\WINDOWS\system32\ieakeng.dll
2006-10-17 13:01 13312 --a------ C:\WINDOWS\system32\ieudinit.exe
2006-10-17 13:00 54784 --a------ C:\WINDOWS\system32\ie4uinit.exe
2006-10-17 13:00 43008 --a------ C:\WINDOWS\system32\iernonce.dll
2006-10-17 13:00 123904 --a------ C:\WINDOWS\system32\advpack.dll
2006-10-17 12:57 36352 --a------ C:\WINDOWS\system32\imgutil.dll
2006-10-17 12:56 45568 --a------ C:\WINDOWS\system32\mshta.exe
2006-10-17 12:28 48128 --a------ C:\WINDOWS\system32\mshtmler.dll
2006-10-17 12:23 161792 --a------ C:\WINDOWS\system32\ieakui.dll
2006-10-16 20:11 -------- d-------- C:\Documents and Settings\Compaq_Owner\Application Data\Template
2006-10-16 20:04 -------- d-------- C:\Program Files\AvailaSoft
2006-10-16 17:56 -------- d-------- C:\Documents and Settings\Compaq_Owner\Application Data\Morpheus
2006-10-16 17:25 -------- d-------- C:\Documents and Settings\Compaq_Owner\Application Data\Morpheus PRO
2006-10-16 17:06 -------- d-------- C:\Program Files\Common Files\Symantec Shared
2006-10-16 14:58 -------- d-------- C:\Documents and Settings\Compaq_Owner\Application Data\iMesh
2006-10-16 01:21 -------- d-------- C:\Documents and Settings\Compaq_Owner\Application Data\Sun
2006-10-14 23:44 -------- d-------- C:\Program Files\Common Files\Microsoft Shared
2006-10-14 11:57 -------- d-------- C:\Program Files\MSXML 4.0
2006-10-13 19:46 -------- d-------- C:\Documents and Settings\Compaq_Owner\Application Data\Adobe
2006-10-12 03:05 -------- d-------- C:\Program Files\Windows Media Player
2006-10-10 08:56 -------- d-------- C:\Program Files\Outlook Express
2006-10-10 08:56 -------- d-------- C:\Program Files\Common Files\System
2006-10-10 06:24 -------- d-------- C:\Program Files\Common Files\Adobe
2006-10-10 06:24 -------- d-------- C:\Program Files\Adobe
2006-10-10 06:09 -------- d-------- C:\Program Files\Yahoo!
2006-10-10 04:53 -------- d-------- C:\Program Files\Quicken
2006-10-10 02:00 -------- d-------- C:\Documents and Settings\Compaq_Owner\Application Data\Macromedia
2006-10-10 01:59 -------- d-------- C:\Program Files\Google
2006-09-12 23:01 1084416 --a------ C:\WINDOWS\system32\msxml3.dll
2006-09-12 17:51 1245184 --a------ C:\WINDOWS\system32\msxml4.dll
2006-09-06 17:43 22752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2006-08-25 09:45 617472 --a------ C:\WINDOWS\system32\comctl32.dll
2006-08-21 06:21 16896 --a------ C:\WINDOWS\system32\fltlib.dll
2006-08-21 03:14 23040 --a------ C:\WINDOWS\system32\fltmc.exe
2006-08-16 05:58 100352 --a------ C:\WINDOWS\system32\6to4svc.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"Yahoo! Pager"="\"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe\" -quiet"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"RTHDCPL"="RTHDCPL.EXE"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"Recguard"="C:\\WINDOWS\\SMINST\\RECGUARD.EXE"
"HPBootOp"="\"C:\\Program Files\\Hewlett-Packard\\HP Boot Optimizer\\HPBootOp.exe\" /run"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"
"!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000000
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoCDBurning"=dword:00000000
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Adobe Gamma Loader.lnk"
"backup"="C:\\WINDOWS\\pss\\Adobe Gamma Loader.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\COMMON~1\\Adobe\\CALIBR~1\\ADOBEG~1.EXE "
"item"="Adobe Gamma Loader"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!AVG Anti-Spyware]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="avgas"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ccApp"
"hkey"="HKLM"
"command"="\"c:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="HPwuSchd2"
"hkey"="HKLM"
"command"="C:\\Program Files\\HP\\HP Software Update\\HPwuSchd2.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark 1200 Series]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="lxczbmgr"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Lexmark 1200 Series\\lxczbmgr.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="msmsgs"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="nwiz"
"hkey"="HKLM"
"command"="nwiz.exe /install"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="realsched"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="YahooMessenger"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe\" -quiet"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SAVScan"=dword:00000003
"navapsvc"=dword:00000002
"ccSetMgr"=dword:00000002
"ccProxy"=dword:00000002
"ccISPwdSvc"=dword:00000003
"ccEvtMgr"=dword:00000002
"AVG Anti-Spyware Guard"=dword:00000002
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
Completion time: 06-11-11 13:55:33.28
C:\ComboFix.txt ... 06-11-11 13:55
Third Report ((((Fresh HiJackThis))))Logfile of HijackThis v1.99.1
Scan saved at 1:56:42 PM, on 11/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://google.com/O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: HpWebHelper - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft....k/?LinkID=39204O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.micros...b?1160492278593O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoft...free/asinst.cabO23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
I hope I did everything right.....Thanks again.