OK! AGREE WITH YOU ON THAT BEING THE FUN PART...ONE SERIOUS CAFFINE OVERDOSE LATER!!!
followed all of the above instructions and already the computer would appear to be running 10x faster plus no annoyin icons in the toolbar bay, here are the reports as asked....thanks again!! buck-eye U JEDI!!
RAPPORT Log:-
SmitFraudFix v2.126
Scan done at 14:06:37.00, 04/12/2006
Run from C:\Documents and Settings\Suzie\Desktop\New Folder (3)\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix run in normal mode
»»»»»»»»»»»»»»»»»»»»»»»» C:\
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Suzie
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Suzie\Application Data
»»»»»»»»»»»»»»»»»»»»»»»» Start Menu
»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Suzie\FAVORI~1
»»»»»»»»»»»»»»»»»»»»»»»» Desktop
»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys
»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components
»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\\PROGRA~1\\Google\\GOOGLE~2\\GOEC62~1.DLL"
»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""
»»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32
»»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection
»»»»»»»»»»»»»»»»»»»»»»»» End
AVG REPORT:-
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 13:50:05 04/12/2006
+ Scan result:
HKU\S-1-5-21-1990455940-458014605-3675420851-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{55BE9F0D-6CAF-4C3E-B125-5A13A8C9D0EC} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1990455940-458014605-3675420851-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C815ACE8-3DBF-4FFD-8231-AB1D21E8B7EE} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1990455940-458014605-3675420851-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{55BE9F0D-6CAF-4C3E-B125-5A13A8C9D0EC} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1990455940-458014605-3675420851-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C815ACE8-3DBF-4FFD-8231-AB1D21E8B7EE} -> Adware.Generic : Cleaned with backup (quarantined).
C:\WINDOWS\eliteunstall.exe -> Adware.MediaMotor : Cleaned with backup (quarantined).
HKU\S-1-5-21-1990455940-458014605-3675420851-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0D2DEF3A-F4F1-42EC-AC4F-132E7BA6E292} -> Adware.MWSearch : Cleaned with backup (quarantined).
HKU\S-1-5-21-1990455940-458014605-3675420851-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A19EF336-01D4-48E6-926A-FE7E1C747AED} -> Adware.MWSearch : Cleaned with backup (quarantined).
HKU\S-1-5-21-1990455940-458014605-3675420851-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0D2DEF3A-F4F1-42EC-AC4F-132E7BA6E292} -> Adware.MWSearch : Cleaned with backup (quarantined).
HKU\S-1-5-21-1990455940-458014605-3675420851-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F65B197F-8260-4D52-909A-F70118E646EB} -> Adware.MWSearch : Cleaned with backup (quarantined).
HKU\S-1-5-21-1990455940-458014605-3675420851-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95C60327-8E17-44D6-98EB-7EB70CC606DD} -> Adware.SafeSurfing : Cleaned with backup (quarantined).
C:\Program Files\DAEMON Tools\SetupDTSB.exe -> Adware.SaveNow : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP287\A0114023.exe -> Adware.SaveNow : Cleaned with backup (quarantined).
C:\Program Files\Common Files\Sandlot Shared\slghex.dll -> Adware.SpywareStorm : Cleaned with backup (quarantined).
HKU\S-1-5-21-1990455940-458014605-3675420851-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{DA7FF3F8-08BE-4CAC-BC00-94D91C6AE7F4} -> Adware.TrustCleaner : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP264\A0097432.exe -> Adware.VirusBurst.b : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP263\A0096412.exe -> Downloader.Zlob.aie : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP264\A0097415.exe -> Downloader.Zlob.aie : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP294\A0136539.dll -> Downloader.Zlob.ako : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP295\A0137531.exe -> Downloader.Zlob.aku : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP264\A0097437.exe -> Downloader.Zlob.awv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP264\A0097439.exe -> Downloader.Zlob.awv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP264\A0097440.exe -> Downloader.Zlob.awv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP264\A0097441.exe -> Downloader.Zlob.awv : Cleaned with backup (quarantined).
C:\Documents and Settings\Suzie\Desktop\freebie spy remover baz\hijackthis\backups\backup-20061129-150927-932.dll -> Downloader.Zlob.bbv : Cleaned with backup (quarantined).
C:\Documents and Settings\Suzie\Desktop\freebie spy remover baz\hijackthis\backups\backup-20061202-121752-859.dll -> Downloader.Zlob.bbv : Cleaned with backup (quarantined).
C:\Documents and Settings\Suzie\Desktop\freebie spy remover baz\hijackthis\backups\backup-20061202-121819-814.dll -> Downloader.Zlob.bbv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP288\A0116005.dll -> Downloader.Zlob.bbv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP288\A0117007.dll -> Downloader.Zlob.bbv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP288\A0117023.dll -> Downloader.Zlob.bbv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP288\A0118023.dll -> Downloader.Zlob.bbv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP288\A0119023.dll -> Downloader.Zlob.bbv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP288\A0120025.dll -> Downloader.Zlob.bbv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP288\A0121024.dll -> Downloader.Zlob.bbv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP288\A0122023.dll -> Downloader.Zlob.bbv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP288\A0123023.dll -> Downloader.Zlob.bbv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP288\A0124023.dll -> Downloader.Zlob.bbv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP288\A0125025.dll -> Downloader.Zlob.bbv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP288\A0126023.dll -> Downloader.Zlob.bbv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP288\A0127023.dll -> Downloader.Zlob.bbv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP288\A0128025.dll -> Downloader.Zlob.bbv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP289\A0128037.dll -> Downloader.Zlob.bbv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP290\A0128100.dll -> Downloader.Zlob.bbv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP291\A0128159.dll -> Downloader.Zlob.bbv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP291\A0128208.dll -> Downloader.Zlob.bbv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP291\A0129208.dll -> Downloader.Zlob.bbv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP291\A0129224.dll -> Downloader.Zlob.bbv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP292\A0129391.dll -> Downloader.Zlob.bbv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP292\A0129444.dll -> Downloader.Zlob.bbv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP292\A0130446.dll -> Downloader.Zlob.bbv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP292\A0131448.dll -> Downloader.Zlob.bbv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP292\A0132446.dll -> Downloader.Zlob.bbv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP292\A0133444.dll -> Downloader.Zlob.bbv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP292\A0134455.dll -> Downloader.Zlob.bbv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP292\A0135455.dll -> Downloader.Zlob.bbv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP292\A0135480.dll -> Downloader.Zlob.bbv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP292\A0136489.dll -> Downloader.Zlob.bbv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP294\A0136521.dll -> Downloader.Zlob.bbv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP295\A0137523.dll -> Downloader.Zlob.bbv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP295\A0137540.dll -> Downloader.Zlob.bbv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP295\A0143558.dll -> Downloader.Zlob.bbv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP295\A0137548.exe -> Downloader.Zlob.ec : Cleaned with backup (quarantined).
HKU\S-1-5-21-1990455940-458014605-3675420851-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2559D0B1-AF60-4BD5-965D-0E51383A6367} -> Hijacker.Generic : Cleaned with backup (quarantined).
C:\Documents and Settings\Suzie\Desktop\Barry\New Folder (4)\New Folder (3)\web.studio.v4.0.patch-icu.zip/patch.exe -> Trojan.Delf.li : Cleaned with backup (quarantined).
C:\WINDOWS\YOINSI.exe -> Trojan.Scapur.k : Cleaned with backup (quarantined).
C:\WINDOWS\system32\wnsinttr.exe -> Trojan.Small : Cleaned with backup (quarantined).
::Report end
NEW HIJACK THIS LOG:-
Logfile of HijackThis v1.99.1
Scan saved at 14:10:52, on 04/12/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Documents and Settings\Suzie\Desktop\freebie spy remover baz\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\slrundll.exe
C:\WINDOWS\Explorer.EXE
C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
C:\Apps\Powercinema\PCMService.exe
C:\apps\ABoard\ABoard.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\apps\ABoard\AOSD.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
C:\Program Files\USB Product Driver 2.25r003\shwicon.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Silicon Prairie Software\MemTurbo\memturbo.exe
C:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\CalCheck.exe
C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Suzie\Desktop\freebie spy remover baz\hijackthis\avg71free_371a669.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.wanadoo.co.ukR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.wanadoo.co.ukR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Wanadoo
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Documents and Settings\Suzie\Desktop\New Folder\BitComet\tools\BitCometBHO.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [ATIPTA] C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [PE2CKFNT SE] C:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\ChkFont.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [UserFaultCheck] C:\WINDOWS\system32\dumprep 0 -u
O4 - HKLM\..\Run: [ShowIcon_Justram_USB Product Driver v2.25r003] "C:\Program Files\USB Product Driver 2.25r003\shwicon.exe" -t"Justram\USB Product Driver v2.25r003"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MSKAgent.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Documents and Settings\Suzie\Desktop\freebie spy remover baz\Spyware Doctor\swdoctor.exe" /Q
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O4 - Global Startup: 20-20 Shortcut Bar.lnk = C:\Documents and Settings\Suzie\Desktop\New Folder\Mswin\60\SCBar.Exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: MemTurbo.lnk = C:\Program Files\Silicon Prairie Software\MemTurbo\memturbo.exe
O4 - Global Startup: Photo Express Calendar Checker SE.lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\CalCheck.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Download all links using BitComet - res://C:\Documents and Settings\Suzie\Desktop\New Folder\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Download all videos using BitComet - res://C:\Documents and Settings\Suzie\Desktop\New Folder\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: Download link using &BitComet - res://C:\Documents and Settings\Suzie\Desktop\New Folder\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: Search with Wanadoo - res://C:\PROGRA~1\Wanadoo\WSBar\WSBar.dll/VSearch.htm
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0527.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0527.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.wanadoo.co.uk
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) -
http://messenger.zon...kr.cab31267.cabO16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) -
http://messenger.zon...nt.cab31267.cabO16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft....k/?linkid=39204O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.micros...b?1131671051140O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
http://messenger.zon...nt.cab31267.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoft...free/asinst.cabO16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) -
http://www.crucial.c.../cpcScanner.cabO16 - DPF: {AEF76437-F960-4EBC-97EA-7BBB4230CF38} (OcarptMain Class) -
https://oca.microsof...cure/ocarpt.CABO16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) -
http://messenger.zon...ro.cab32846.cabO16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) -
http://us.dl1.yimg.c...utocomplete.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{9EF397F5-88A0-449B-B3D7-5E80A378512E}: NameServer = 195.92.195.94 195.92.195.95
O18 - Protocol: asp - {8D32BA61-D15B-11D4-894B-000000000000} - C:\WINDOWS\system32\hsppp.dll
O18 - Protocol: ezpp - {810403FA-E82E-11D5-8AAB-0010A404A3DE} - C:\WINDOWS\system32\EZTOOL~1.DLL
O18 - Protocol: hsp - {8D32BA61-D15B-11D4-894B-000000000000} - C:\WINDOWS\system32\hsppp.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: x-asp - {8D32BA61-D15B-11D4-894B-000000000000} - C:\WINDOWS\system32\hsppp.dll
O18 - Protocol: x-hsp - {8D32BA61-D15B-11D4-894B-000000000000} - C:\WINDOWS\system32\hsppp.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Documents and Settings\Suzie\Desktop\freebie spy remover baz\ewido anti-malware\ewidoctrl.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
SOOOOoo....
hopefully ucan make more sense of that than i can, as mentioned earlier everything appears to be running far more effectivly now but ill wait for your thumbs up before i make any more assumtions! thans again Sam! merry xmas n noo year!