Hi and thanks for your reply.
As requested here is the results of the combofix and also the log of uninstall_list.text and hijackthis log.
Many Thanks again
birani
combofix txtMum - 06-12-06 16:40:04.46 Service Pack 2
ComboFix 06.11.27W - Running from: "C:\Documents and Settings\Mum\Desktop"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\Program Files\Common Files\Yazzle1122OinUninstaller.exe
C:\WINDOWS\uninstall_nmon.vbs
C:\Documents and Settings\LocalService\Application Data\NetMon
C:\Program Files\Common Files\{305E394B-0725-2057-0301-04102703002c}
C:\Program Files\Common Files\{305E394B-0726-2057-0301-04102703002c}
C:\Program Files\Common Files\{C05E394B-0725-2057-0301-04102703002c}
C:\Program Files\Common Files\{C05E394B-0726-2057-0301-04102703002c}
C:\WINDOWS\Sm9hbm5l
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\QooBox\Purity\WINDOWS\PPATCH~1
C:\QooBox\Purity\WINDOWS\PPPATC~1
C:\QooBox\Purity\WINDOWS\PPATCH~1\à?pPatch
((((((((((((((((((((((((((((((( Files Created from 2006-11-06 to 2006-12-06 ))))))))))))))))))))))))))))))))))
2006-12-06 15:50 3,542 --a------ C:\WINDOWS\system32\tmp.reg
2006-12-05 17:11 <DIR> d-------- C:\Program Files\RegistryFix
2006-12-05 13:52 <DIR> d--h----- C:\WINDOWS\system32\GroupPolicy
2006-12-04 23:22 <DIR> d-------- C:\Program Files\CCleaner
2006-12-04 22:11 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2006-12-04 22:11 <DIR> d-------- C:\Program Files\Grisoft
2006-12-04 19:34 <DIR> d-------- C:\Program Files\Symantec Technical Support
2006-12-04 11:39 51,788 --a------ C:\WINDOWS\system32\csnow.exe
2006-12-04 11:35 29,696 --a------ C:\WINDOWS\system32\rpcc.dll
2006-12-04 11:35 15,927 --a------ C:\WINDOWS\system32\w.exe
2006-12-04 11:34 9,291 --a------ C:\WINDOWS\system32\z1973.exe
2006-12-04 11:34 8,609 --a------ C:\WINDOWS\system32\z2712.exe
2006-12-04 11:34 6,199 --a------ C:\WINDOWS\system32\z2240.exe
2006-12-04 11:34 6,199 --a------ C:\WINDOWS\system32\se.exe.exe
2006-12-04 11:34 54,327 --a------ C:\WINDOWS\system32\google.png.exe
2006-12-04 11:34 20,480 --a------ C:\WINDOWS\system32\z3658.dll
2006-12-04 11:34 15,927 --a------ C:\WINDOWS\system32\w.exe.exe
2006-12-04 11:34 15,927 ---h----- C:\WINDOWS\system32\nordsys.exe
2006-12-04 11:34 128,567 --a------ C:\WINDOWS\system32\ss.exe.exe
2006-12-04 10:45 <DIR> d-------- C:\WINDOWS\system32\bak
2006-12-01 23:15 30,844 --a------ C:\WINDOWS\system32\gsetup.exe
2006-12-01 22:55 8,570 --a------ C:\WINDOWS\system32\telebos.exe
2006-11-21 21:56 <DIR> d-------- C:\Documents and Settings\Mum\Application Data\ICAClient
2006-11-21 21:55 <DIR> d-------- C:\Program Files\Citrix
2006-11-15 17:49 <DIR> d-------- C:\Program Files\Azureus
2006-11-15 17:49 <DIR> d-------- C:\Documents and Settings\Mum\Application Data\Azureus
2006-11-13 12:18 <DIR> d-------- C:\Documents and Settings\Mum\Application Data\uTorrent
2006-11-13 11:06 <DIR> d-------- C:\Documents and Settings\Mum\Application Data\DivX
2006-11-13 10:52 20,640 --------- C:\WINDOWS\system32\drivers\PxHelp20.sys
2006-11-13 10:52 109,568 --------- C:\WINDOWS\system32\pxinsi64.exe
2006-11-13 10:52 108,544 --------- C:\WINDOWS\system32\pxcpyi64.exe
2006-11-13 10:51 <DIR> d-------- C:\Program Files\DivX
2006-11-12 19:42 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Bluetooth
2006-11-12 19:38 <DIR> d-------- C:\Program Files\IVT Corporation
2006-11-08 23:11 <DIR> d-------- C:\Documents and Settings\Mum\Application Data\ConvertTemp
2006-11-08 23:07 <DIR> d-------- C:\Documents and Settings\Mum\Application Data\Samsung
2006-11-08 22:57 <DIR> d-------- C:\WINDOWS\system32\Samsung PC Studio Codecs
2006-11-08 22:56 77,824 --a------ C:\WINDOWS\system32\fun_mp4_dec.dll
2006-11-08 22:56 684,032 --a------ C:\WINDOWS\system32\fun_mp4_enc.dll
2006-11-08 22:56 2,729,472 --a------ C:\WINDOWS\system32\fun_avcodec.dll
2006-11-08 22:55 94,000 --a------ C:\WINDOWS\system32\drivers\ssm_mdm.sys
2006-11-08 22:55 8,336 --a------ C:\WINDOWS\system32\drivers\ssm_mdfl.sys
2006-11-08 22:55 6,176 --a------ C:\WINDOWS\system32\drivers\ssm_cmnt.sys
2006-11-08 22:55 6,176 --a------ C:\WINDOWS\system32\drivers\ssm_cm.sys
2006-11-08 22:55 58,320 --a------ C:\WINDOWS\system32\drivers\ssm_bus.sys
2006-11-08 22:55 5,840 --a------ C:\WINDOWS\system32\drivers\ssm_whnt.sys
2006-11-08 22:55 5,840 --a------ C:\WINDOWS\system32\drivers\ssm_wh.sys
2006-11-08 22:54 <DIR> d-------- C:\WINDOWS\system32\Samsung_USB_Drivers
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-12-06 16:40 -------- d-------- C:\Program Files\Common Files
2006-12-05 14:34 -------- d-------- C:\Program Files\Norton AntiVirus
2006-12-05 14:34 -------- d-------- C:\Program Files\Common Files\Symantec Shared
2006-12-04 10:45 -------- d-------- C:\Program Files\SymNetDrv
2006-12-04 10:45 -------- d-------- C:\Program Files\QuickTime
2006-12-04 10:45 -------- d-------- C:\Program Files\iTunes
2006-12-04 10:44 35787 --a------ C:\WINDOWS\system32\taskswitch.exe
2006-12-04 10:44 35787 --a------ C:\WINDOWS\system32\NeroCheck.exe
2006-12-04 10:44 35787 --a------ C:\WINDOWS\system32\fast.exe
2006-11-30 16:54 -------- d-------- C:\Documents and Settings\Mum\Application Data\Adobe
2006-11-26 19:33 -------- d-------- C:\Program Files\MSN Messenger
2006-11-26 19:33 -------- d-------- C:\Program Files\Internet Explorer
2006-11-17 11:30 -------- d-------- C:\Documents and Settings\Mum\Application Data\MSN6
2006-11-13 09:15 -------- d-------- C:\Documents and Settings\Mum\Application Data\BitTorrent
2006-11-12 19:38 -------- d--h----- C:\Program Files\InstallShield Installation Information
2006-11-08 22:54 -------- d-------- C:\Program Files\Samsung
2006-11-05 09:59 379 --a------ C:\Documents and Settings\Mum\Application Data\internaldb1942.dat
2006-11-05 09:59 173056 --a------ C:\Documents and Settings\Mum\Application Data\internaldb7098.dat
2006-11-05 09:59 151 --a------ C:\Documents and Settings\Mum\Application Data\internaldb2116.dat
2006-11-05 09:59 13046 --a------ C:\Documents and Settings\Mum\Application Data\internaldb6613.dat
2006-11-05 09:59 0 --a------ C:\Documents and Settings\Mum\Application Data\internaldb6312.dat
2006-11-05 09:43 6144 --a------ C:\Documents and Settings\Mum\Application Data\internaldb7173.dat
2006-11-05 09:43 0 --a------ C:\Documents and Settings\Mum\Application Data\internaldb5737.dat
2006-11-05 09:43 0 --a------ C:\Documents and Settings\Mum\Application Data\internaldb5124.dat
2006-11-05 09:42 0 --a------ C:\Documents and Settings\Mum\Application Data\internaldb562.dat
2006-11-05 09:42 0 --a------ C:\Documents and Settings\Mum\Application Data\internaldb1201.dat
2006-10-26 10:10 1743 --a------ C:\Documents and Settings\Mum\Application Data\AdobeDLM.log
2006-10-17 20:34 -------- d-------- C:\Program Files\Google
2006-10-15 15:59 -------- d-------- C:\Documents and Settings\Mum\Application Data\AdobeUM
2006-10-10 20:31 -------- d-------- C:\Program Files\Common Files\Adobe
2006-10-10 20:30 -------- d-------- C:\Program Files\Adobe
2006-10-10 20:11 -------- d-------- C:\Program Files\Amic Utilities
2006-10-09 21:53 -------- d-------- C:\Program Files\Symantec
2006-09-15 21:52 91904 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NVMCTRAY.DLL,NvTaskbarInit"
"MoneyAgent"="\"C:\\Program Files\\Microsoft Money\\System\\mnyexpr.exe\""
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"Nord"="C:\\WINDOWS\\system32\\nordsys.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"Share-to-Web Namespace Daemon"="C:\\Program Files\\Hewlett-Packard\\HP Share-to-Web\\hpgs2wnd.exe"
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"Adobe Photo Downloader"="\"C:\\Program Files\\Adobe\\Photoshop Album Starter Edition\\3.0\\Apps\\apdproxy.exe\""
"CoolSwitch"="C:\\WINDOWS\\system32\\taskswitch.exe"
"FastUser"="C:\\WINDOWS\\system32\\fast.exe"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"HPDJ Taskbar Utility"="C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\hpztsb07.exe"
"pdfw"="C:\\Program Files\\Amic Utilities\\PDF Writer Pro\\pdfwload.exe"
"Nord"="C:\\WINDOWS\\system32\\nordsys.exe"
"!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
"MSConfig"="C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\MSConfig.exe /auto"
"UserFaultCheck"=hex(2):25,73,79,73,74,65,6d,72,6f,6f,74,25,5c,73,79,73,74,65,\
6d,33,32,5c,64,75,6d,70,72,65,70,20,30,20,2d,75,00
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices]
"Windows Recylinder Check"="pozlyzyzfa.exe"
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000004
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
"ALUAlert"="C:\\Program Files\\Symantec\\LiveUpdate\\ALUNotify.exe"
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.908.5008\\GoogleToolbarNotifier.exe"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
"ALUAlert"="C:\\Program Files\\Symantec\\LiveUpdate\\ALUNotify.exe"
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.908.5008\\GoogleToolbarNotifier.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableLockWorkstation"=dword:00000000
"DisableChangePassword"=dword:00000000
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
"NoLogoff"=dword:00000000
"NoClose"=dword:00000000
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\WinZip Quick Pick.lnk"
"backup"="C:\\WINDOWS\\pss\\WinZip Quick Pick.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\WinZip\\WZQKPICK.EXE "
"item"="WinZip Quick Pick"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="rundll32"
"hkey"="HKLM"
"command"="rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ctfmon"
"hkey"="HKCU"
"command"="C:\\WINDOWS\\system32\\ctfmon.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\drive mp3 comp extra]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Heck Gram"
"hkey"="HKLM"
"command"="C:\\Documents and Settings\\All Users\\Application Data\\AUDIOBINDDRIVEMP3\\Heck Gram.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IpWins]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ipwins"
"hkey"="HKLM"
"command"="C:\\Program Files\\ipwins\\ipwins.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\kdx]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="KHost"
"hkey"="HKCU"
"command"="C:\\WINDOWS\\kdx\\KHost.exe -all"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NvCpl"
"hkey"="HKLM"
"command"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NvCpl.dll,NvStartup"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="nwiz"
"hkey"="HKLM"
"command"="nwiz.exe /install"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\software heart]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ManagerInsideProc"
"hkey"="HKCU"
"command"="C:\\DOCUME~1\\Mum\\APPLIC~1\\ARMYLO~1\\ManagerInsideProc.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SOUNDMAN"
"hkey"="HKLM"
"command"="SOUNDMAN.EXE"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="jusched"
"hkey"="HKLM"
"command"="C:\\Program Files\\Java\\jre1.5.0_01\\bin\\jusched.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec NetDriver Monitor]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SNDMon"
"hkey"="HKLM"
"command"="C:\\PROGRA~1\\SYMNET~1\\SNDMon.exe /Consumer"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Recylinder Check]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="pozlyzyzfa"
"hkey"="HKLM"
"command"="pozlyzyzfa.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"cmdService"=dword:00000002
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\rpcc
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Symantec NetDetect.job
Completion time: 06-12-06 16:40:37.29
C:\ComboFix.txt ... 06-12-06 16:40
uninstall_list.text Ad-Aware SE Personal
Adobe Acrobat 6.0 Professional - English, Français, Deutsch
Adobe Download Manager 2.0 (Remove Only)
Adobe Photoshop CS
Adobe Reader 7.0.5 Language Support
Adobe Reader 7.0.8
Adobe Shockwave Player
Adobe® Photoshop® Album Starter Edition 3.0
AVG Anti-Spyware 7.5
BitTorrent 4.22.1
BlueSoleil
CCleaner (remove only)
CDex extraction audio
Citrix ICA Web Client
Digimax L60 /Kenox X60
Digimax Master
Garmin City Navigator Europe NT+ v8.02
Garmin POI Loader
Google Toolbar for Internet Explorer
HijackThis 1.99.1
hp deskjet 3820 series (Remove only)
HP Photo Printing Software
hp psc 700 series
HP Share-to-Web
igLoader 2,0,0,2
Intel® PRO Network Adapters and Drivers
iPod for Windows 2005-09-23
iPod for Windows 2006-01-10
iPod Updater 2004-11-15
iTunes
J2SE Runtime Environment 5.0 Update 1
LimeWire 4.12.6
LiveUpdate 1.90 (Symantec Corporation)
Macromedia Flash Player 8
MediaTickets by OIN
Messenger Plus! 3 & Sponsor
Messenger Plus! Live & Sponsor
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB886903)
Microsoft Money
Microsoft Money System Pack
Microsoft Office XP Professional
Nero 6 Enterprise Edition
NVIDIA Audio Driver
NVIDIA Windows 2000/XP Display Drivers
PDF Writer Pro v1.2
Powertoys For Windows XP
QuickTime
RegistryFix v5.5
SAMSUNG CDMA Modem Driver Set
SAMSUNG Mobile USB Modem ^^
SAMSUNG Mobile USB Modem 1.0 Software
SAMSUNG Mobile USB Modem Software
Samsung PC Studio
Samsung PC Studio 3 USB Driver Installer
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 9 (KB911565)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893066)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899589)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911280)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Spybot - Search & Destroy 1.3
SUGAR Virtual Makeover
Symantec Technical Support Web Controls
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB910437)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Windows Installer 3.1 (KB893803)
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Media Format Runtime
Windows Media Player 10
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB885884
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Service Pack 2
WinRAR archiver
WinZip
XTNDConnect Blue Manager 2.1
Logfile of HijackThis v1.99.1
Scan saved at 16:53:27, on 06/12/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Program Files\KService\KService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\System32\svchost.exe
c:\program files\internet explorer\iexplore.exe
C:\WINDOWS\system32\nordsys.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Hewlett-Packard\AiO\hp psc 700 series\Bin\hpobrt07.exe
C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Mum\Desktop\Mum N Brian\Brians MP3 player\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.co.uk/O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {17E35919-92F3-E773-D1FA-C66931DC8DC3} - C:\WINDOWS\system32\jcnbspki.dll (file missing)
O2 - BHO: (no name) - {17EC0111-93F3-E726-8AFA-C66931DC8EC7} - C:\WINDOWS\system32\jsrtsw.dll (file missing)
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: (no name) - {E6967341-F6A3-1508-A513-3C42BECF9365} - C:\DOCUME~1\Mum\APPLIC~1\RDRERR~1\Bodymemo.exe (file missing)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe
O4 - HKLM\..\Run: [FastUser] C:\WINDOWS\system32\fast.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [pdfw] C:\Program Files\Amic Utilities\PDF Writer Pro\pdfwload.exe
O4 - HKLM\..\Run: [Nord] C:\WINDOWS\system32\nordsys.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\RunServices: [Windows Recylinder Check] pozlyzyzfa.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Nord] C:\WINDOWS\system32\nordsys.exe
O4 - Global Startup: HPAiODevice(hp psc 700 series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp psc 700 series\Bin\hpobrt07.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Search -
http://edits.mywebse...?p=ZJxdm037YYGBO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Money Viewer - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) -
http://messenger.zon...kr.cab31267.cabO16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) -
http://messenger.zon...nt.cab31267.cabO16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) -
http://messenger.zon...er.cab31267.cabO16 - DPF: {2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6} -
http://www.driveclea...leanerstart.cabO16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://by103fd.bay10...es/MsnPUpld.cabO16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
http://messenger.zon...nt.cab31267.cabO16 - DPF: {9B17FE0E-51F2-4692-8B32-8EFB805FC0E7} (HPObjectInstaller Class) -
http://h30155.www3.h...edsolutions.cabO16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn...pDownloader.cabO16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) -
http://messenger.zon...ro.cab47946.cabO16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) -
http://messenger.zon...ot.cab31267.cabO16 - DPF: {E055C02E-6258-40FF-80A7-3BDA52FACAD7} -
http://activex.matca.../speedtest2.dllO16 - DPF: {FF3F0F03-0F01-131A-A3F9-08F02B23E0CC} -
http://207.226.177.98/gbn2650.exeO17 - HKLM\System\CCS\Services\Tcpip\..\{1CA2ADB7-3337-408E-934A-517706EF454D}: NameServer = 85.255.114.101,85.255.112.73
O17 - HKLM\System\CCS\Services\Tcpip\..\{46843123-250C-4184-BEDC-A257090B90F1}: NameServer = 85.255.114.101,85.255.112.73
O17 - HKLM\System\CCS\Services\Tcpip\..\{752ABCE8-AFFD-4EB1-ADB0-4097A3956AFD}: NameServer = 85.255.114.101,85.255.112.73
O17 - HKLM\System\CCS\Services\Tcpip\..\{76F0FAF3-09F3-4F3B-93DC-5D41FB7A8657}: NameServer = 85.255.114.101,85.255.112.73
O17 - HKLM\System\CCS\Services\Tcpip\..\{AB81FCED-A5F3-4FF0-85C4-AF0FE2549950}: NameServer = 85.255.114.101,85.255.112.73
O17 - HKLM\System\CCS\Services\Tcpip\..\{C40F2F4E-0DA3-46F2-9228-CDB01F0F2AAF}: NameServer = 85.255.114.101,85.255.112.73
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.114.101 85.255.112.73
O17 - HKLM\System\CS1\Services\Tcpip\..\{1CA2ADB7-3337-408E-934A-517706EF454D}: NameServer = 85.255.114.101,85.255.112.73
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.114.101 85.255.112.73
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs:
O20 - Winlogon Notify: rpcc - C:\WINDOWS\system32\rpcc.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InteractiveLogon - Unknown owner - C:\WINDOWS\system32\Fast.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\KService\KService.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Unknown owner - C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe