Thankyou for all of that info. I seem to have got rid of the major problems- Here are the logs as requested.
Your help is greatly appreciated.
Combofix:
"Mick" - 07-02-06 21:01:20 Service Pack 2
ComboFix 07.02.04 - Running from: "G:\"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\keyboard131.dat
C:\Program Files\Ipwindows\ipwins.dll
C:\Program Files\Ipwindows\ipwins.exe
C:\WINDOWS\system32\GroupPolicy\Machine\Scripts\scripts.ini
C:\WINDOWS\system32\svchosts.exe
C:\WINDOWS\system32\unsvchosts.lzma
C:\Program Files\Common Files\{501BD~1
C:\Program Files\Common Files\{501BD~2
C:\DOCUME~1\Mick\Application Data\SearchToolbarCorp
C:\Program Files\Ipwindows
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\qoobox\purity\DOCUME~1
C:\qoobox\purity\DOCUME~1\Mick
C:\qoobox\purity\DOCUME~1\Mick\Application Data
C:\qoobox\purity\DOCUME~1\Mick\Application Data\CROSOF~1
C:\qoobox\purity\DOCUME~1\Mick\Application Data\from.txt
C:\qoobox\purity\WINDOWS\WNSXS~1
C:\qoobox\purity\WINDOWS\system32\ECURIT~1
((((((((((((((((((((((((((((((( Files Created from 2007-01-06 to 2007-02-06 ))))))))))))))))))))))))))))))))))
2007-02-06 17:39 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-02-06 17:39 <DIR> d-------- C:\Program Files\Grisoft
2007-02-06 16:46 <DIR> d-------- C:\VundoFix Backups
2007-02-05 20:40 <DIR> d-------- C:\DOCUME~1\LOCALS~1\Application Data\Adobe
2007-02-04 18:14 <DIR> d-------- C:\Program Files\ewido anti-malware
2007-02-04 17:57 <DIR> d-------- C:\Program Files\tightvnc
2007-02-04 10:58 81,024 --a------ C:\WINDOWS\system32\drivers\msfwdrv.sys
2007-02-04 10:58 105,856 --a------ C:\WINDOWS\system32\drivers\msfwhlpr.sys
2007-02-04 10:57 67,784 --a------ C:\WINDOWS\system32\drivers\MpFilter.sys
2007-02-04 10:57 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-02-04 10:33 <DIR> d-------- C:\Program Files\Microsoft Windows OneCare Live
2007-02-02 21:09 2 --a------ C:\WINDOWS\system32\wnscpsv.exe
2007-02-02 21:08 72,704 --a------ C:\WINDOWS\system32\drvfig.dll
2007-02-02 21:08 19,968 --a------ C:\WINDOWS\system32\winbmf32.dll
2007-02-01 18:17 <DIR> d-------- C:\Program Files\iTunes
2007-02-01 18:17 <DIR> d-------- C:\Program Files\iPod
2007-02-01 17:29 <DIR> d-------- C:\DOCUME~1\Mick\Application Data\Skype
2007-01-31 19:15 <DIR> d-------- C:\DOCUME~1\Mick\Application Data\Apple Computer
2007-01-28 20:56 <DIR> d-------- C:\Program Files\Microsoft Bootvis
2007-01-24 20:02 <DIR> d-------- C:\DOCUME~1\Mick\Application Data\Individual Software
2007-01-23 19:02 <DIR> d-------- C:\Program Files\Common Files\eDrawings2007
2007-01-21 21:13 <DIR> d-------- C:\DOCUME~1\Mick\Application Data\Webroot
2007-01-21 15:35 <DIR> d-------- C:\DOCUME~1\Mick\Application Data\Help
2007-01-21 14:51 <DIR> d-------- C:\Program Files\RFA
2007-01-19 16:54 <DIR> d-------- C:\DOCUME~1\Mick\Application Data\Google
2007-01-17 18:26 <DIR> d-------- C:\DOCUME~1\Mick\Application Data\Sun
2007-01-17 17:43 <DIR> d-------- C:\DOCUME~1\Mick\Application Data\AdobeUM
2007-01-14 14:48 <DIR> d-------- C:\DOCUME~1\Mick\Application Data\Adobe
2007-01-14 14:39 <DIR> d--hs---- C:\WINDOWS\CSC
2007-01-14 14:04 <DIR> d--hs---- C:\USMT.TMP
2007-01-14 13:57 <DIR> d-------- C:\DOCUME~1\Mick\Application Data\Symantec
2007-01-12 21:06 127,208 --a------ C:\WINDOWS\system32\mucltui.dll
2007-01-12 18:19 36,352 --------- C:\WINDOWS\system32\tsgqec.dll
2007-01-12 18:19 288,768 --------- C:\WINDOWS\system32\rhttpaa.dll
2007-01-12 18:19 116,736 --------- C:\WINDOWS\system32\aaclient.dll
2007-01-12 16:45 <DIR> d-------- C:\WINDOWS\ie7updates
2007-01-09 16:51 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2007-01-09 16:48 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2007-01-09 16:48 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2007-01-09 16:41 <DIR> d--h-c--- C:\WINDOWS\ie7
2007-01-09 16:41 <DIR> d-------- C:\WINDOWS\WBEM
2007-01-09 16:41 <DIR> d-------- C:\WINDOWS\system32\en-US
2007-01-09 16:39 121,856 --------- C:\WINDOWS\system32\xmllite.dll
2007-01-09 16:38 <DIR> d-------- C:\WINDOWS\network diagnostic
2007-01-09 16:21 592 --a------ C:\WINDOWS\chgkey.vbs
2007-01-07 14:12 <DIR> d-------- C:\Program Files\Apple Software Update
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-02-04 22:23 -------- d-------- C:\Program Files\norton systemworks
2007-02-04 22:23 -------- d-------- C:\Program Files\Common Files\symantec shared
2007-02-04 11:06 -------- d---s---- C:\DOCUME~1\Mick\Application Data\microsoft
2007-02-04 10:59 262 --a------ C:\DOCUME~1\Mick\Application Data\winsscookie.txt
2007-01-21 21:13 -------- d-------- C:\Program Files\Common Files\webroot shared
2007-01-21 15:18 -------- d-------- C:\Program Files\microsoft activesync
2007-01-21 15:15 -------- d--h----- C:\Program Files\installshield installation information
2007-01-17 18:17 -------- d-------- C:\Program Files\Common Files\adobe
2007-01-14 15:18 -------- d-------- C:\DOCUME~1\Mick\Application Data\macromedia
2007-01-14 14:27 2508 --a------ C:\DOCUME~1\Mick\Application Data\$_hpcst$.hpc
2007-01-14 13:56 -------- d-------- C:\DOCUME~1\Mick\Application Data\identities
2007-01-12 18:06 -------- d-------- C:\Program Files\microsoft works
2007-01-09 16:47 -------- d-------- C:\Program Files\windows media connect
2007-01-07 14:15 -------- d-------- C:\Program Files\quicktime
2006-12-29 18:58 94208 --a------ C:\WINDOWS\ccuninst.exe
2006-12-29 18:57 -------- d-------- C:\Program Files\telstra
2006-12-29 18:18 -------- d-------- C:\Program Files\polar
2006-12-28 16:50 -------- d-------- C:\Program Files\on screen display
2006-12-28 15:08 -------- d-------- C:\Program Files\java
2006-11-27 19:45 60416 --------- C:\WINDOWS\system32\tzchange.exe
2006-11-13 17:02 1866240 --a------ C:\WINDOWS\system32\mstscax.dll
2006-11-08 16:06 679424 --a------ C:\WINDOWS\system32\inetcomm.dll
2006-11-07 21:03 6049280 --------- C:\WINDOWS\system32\ieframe.dll
2006-11-07 21:03 50688 --------- C:\WINDOWS\system32\msfeedsbs.dll
2006-11-07 21:03 458752 --------- C:\WINDOWS\system32\msfeeds.dll
2006-11-07 21:03 413696 --a------ C:\WINDOWS\system32\vbscript.dll
2006-11-07 21:03 231424 --a------ C:\WINDOWS\system32\webcheck.dll
2006-11-07 21:03 180736 --------- C:\WINDOWS\system32\ieui.dll
2006-11-07 21:03 156160 --a------ C:\WINDOWS\system32\msls31.dll
2006-11-07 19:06 600576 --a------ C:\WINDOWS\system32\mstsc.exe
2006-11-07 03:27 382976 --a------ C:\WINDOWS\system32\iedkcs32.dll
2006-11-07 03:27 229376 --a------ C:\WINDOWS\system32\ieaksie.dll
2006-11-07 03:26 71680 --a------ C:\WINDOWS\system32\admparse.dll
2006-11-07 03:26 55296 --a------ C:\WINDOWS\system32\iesetup.dll
2006-11-07 03:26 54784 --a------ C:\WINDOWS\system32\ie4uinit.exe
2006-11-07 03:26 43008 --a------ C:\WINDOWS\system32\iernonce.dll
2006-11-07 03:26 152064 --a------ C:\WINDOWS\system32\ieakeng.dll
2006-11-07 03:26 13312 --a------ C:\WINDOWS\system32\ieudinit.exe
2006-11-07 03:26 123904 --a------ C:\WINDOWS\system32\advpack.dll
2006-11-07 03:25 161792 --a------ C:\WINDOWS\system32\ieakui.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"WMPNSCFG"="C:\\Program Files\\Windows Media Player\\WMPNSCFG.exe"
"Window Washer"="C:\\Program Files\\Webroot\\Washer\\wwDisp.exe"
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"H/PC Connection Agent"="\"C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe\""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"wlwmjsg.dll"="C:\\WINDOWS\\system32\\rundll32.exe \"C:\\Documents and Settings\\Mick\\Local Settings\\Application Data\\wlwmjsg.dll\",zdxkxpb"
"SynTPLpr"="C:\\Program Files\\Synaptics\\SynTP\\SynTPLpr.exe"
"SynTPEnh"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_10\\bin\\jusched.exe\""
"SNPSTD2"="C:\\WINDOWS\\vsnpstd2.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"OneCareUI"="\"C:\\Program Files\\Microsoft Windows OneCare Live\\winssnotify.exe\""
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"Lto Manager"="\"C:\\Program Files\\Quick GPS Connection Data Download Manager\\DesktopLtoManager.exe\""
"KeybdUtility"="\"C:\\Program Files\\On Screen Display\\Hotkey.exe\""
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"iRiver Updater"="\\Updater.exe"
"ecc"="C:\\Program Files\\Telstra\\BigPond Assist\\assist.exe"
"CloneCDTray"="\"C:\\Program Files\\SlySoft\\CloneCD\\CloneCDTray.exe\" /s"
"BluetoothAuthenticationAgent"="rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent"
"batterymiser"="C:\\Program Files\\Battery miser\\batterymiser.exe"
"AGRSMMSG"="AGRSMMSG.exe"
"!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
"IPOperator"="\"C:\\Program Files\\IP Operator\\IPOperator.exe\" -aUtOsTaRtFrOmReG"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acrobat Assistant.lnk]
"backup"="C:\\WINDOWS\\pss\\Acrobat Assistant.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\Adobe\\ACROBA~2.0\\Distillr\\acrotray.exe "
"item"="Acrobat Assistant"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Norton GoBack.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Norton SystemWorks\\Norton GoBack.lnk"
"backup"="C:\\WINDOWS\\pss\\Norton GoBack.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\NORTON~2\\NORTON~4\\GBTray.exe "
"item"="Norton GoBack"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"=""
"hkey"="HKLM"
"command"=""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Norton Ghost 9.0]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="GhostTray"
"hkey"="HKLM"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\System Mechanic Startup Guard]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="StartupGuard"
"hkey"="HKCU"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{26F5978F-6493-4ee3-B114-C0C3ACCF9D4D}"="BatteryMiser Psap Shl Ext"
"{90382AD7-4298-47E0-BC0F-14ACCFF44D2C}"=""
"{54D9498B-CF93-414F-8984-8CE7FDE0D391}"="ewido shell guard"
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"UPnPMonitor"="{e57ce738-33e8-4c51-8354-bb4de9d215d1}"
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMBalloonTip"=dword:00000000
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winbmf32
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\OneCareMP
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
bthsvcs REG_MULTI_SZ BthServ\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0
*newlycreated* - HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\LEGACY_AVGASCLN
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\MP Scheduled Quick Scan.job
C:\WINDOWS\tasks\MP Scheduled Scan.job
C:\WINDOWS\tasks\MP Scheduled Signature Update.job
********************************************************************
catchme 0.1 W2K/XP - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.netscanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
********************************************************************
Vundofix:
VundoFix V6.3.5
Checking Java version...
Java version is 1.5.0.2
Scan started at 4:46:17 PM 6/02/2007
Listing files found while scanning....
C:\Documents and settings\Mick\Application Data\SearchToolbarCorp\Toolbar Vision\PageHistory.txt
C:\Documents and settings\Mick\Application Data\SearchToolbarCorp\Toolbar Vision\WebHistory.txt
C:\WINDOWS\system32\acccf.bak1
C:\WINDOWS\system32\acccf.bak2
C:\WINDOWS\system32\acccf.ini
C:\WINDOWS\system32\acccf.ini2
C:\WINDOWS\system32\acccf.tmp
C:\WINDOWS\system32\fccca.dll
C:\WINDOWS\system32\gbljilap.dll
C:\WINDOWS\system32\khfdbab.dll
C:\WINDOWS\system32\ldvrxmpw.dll
C:\WINDOWS\system32\palijlbg.ini
C:\WINDOWS\system32\rqrqppn.dll
C:\WINDOWS\system32\wdaltjdl.dll
C:\WINDOWS\system32\wpmxrvdl.ini
Beginning removal...
Attempting to delete C:\Documents and settings\Mick\Application Data\SearchToolbarCorp\Toolbar Vision\PageHistory.txt
C:\Documents and settings\Mick\Application Data\SearchToolbarCorp\Toolbar Vision\PageHistory.txt Has been deleted!
Attempting to delete C:\Documents and settings\Mick\Application Data\SearchToolbarCorp\Toolbar Vision\WebHistory.txt
C:\Documents and settings\Mick\Application Data\SearchToolbarCorp\Toolbar Vision\WebHistory.txt Has been deleted!
Attempting to delete C:\WINDOWS\system32\acccf.bak1
C:\WINDOWS\system32\acccf.bak1 Has been deleted!
Attempting to delete C:\WINDOWS\system32\acccf.bak2
C:\WINDOWS\system32\acccf.bak2 Has been deleted!
Attempting to delete C:\WINDOWS\system32\acccf.ini
C:\WINDOWS\system32\acccf.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\acccf.ini2
C:\WINDOWS\system32\acccf.ini2 Has been deleted!
Attempting to delete C:\WINDOWS\system32\acccf.tmp
C:\WINDOWS\system32\acccf.tmp Has been deleted!
Attempting to delete C:\WINDOWS\system32\fccca.dll
C:\WINDOWS\system32\fccca.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\gbljilap.dll
C:\WINDOWS\system32\gbljilap.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\khfdbab.dll
C:\WINDOWS\system32\khfdbab.dll Could not be deleted.
Attempting to delete C:\WINDOWS\system32\ldvrxmpw.dll
C:\WINDOWS\system32\ldvrxmpw.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\palijlbg.ini
C:\WINDOWS\system32\palijlbg.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\rqrqppn.dll
C:\WINDOWS\system32\rqrqppn.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\wdaltjdl.dll
C:\WINDOWS\system32\wdaltjdl.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\wpmxrvdl.ini
C:\WINDOWS\system32\wpmxrvdl.ini Has been deleted!
Performing Repairs to the registry.
Done!
Beginning removal...
Attempting to delete C:\WINDOWS\system32\khfdbab.dll
C:\WINDOWS\system32\khfdbab.dll Has been deleted!
Performing Repairs to the registry.
Done!
AVG Antispyware:
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 10:28:07 PM 6/02/2007
+ Scan result:
C:\System Volume Information\_restore{EFBF68CD-A66A-42C5-93DF-EA07F8E0F366}\RP2\A0000076.dll -> Adware.Maxifiles : Cleaned.
C:\System Volume Information\_restore{EFBF68CD-A66A-42C5-93DF-EA07F8E0F366}\RP2\A0000077.exe -> Adware.Maxifiles : Cleaned.
C:\RECYCLER\S-1-5-18\Dc1\Update.exe -> Adware.Softomate : Cleaned.
C:\RECYCLER\S-1-5-18\Dc1\system.dll -> Adware.Softomate : Cleaned.
C:\System Volume Information\_restore{EFBF68CD-A66A-42C5-93DF-EA07F8E0F366}\RP2\A0000080.dll -> Adware.Softomate : Cleaned.
C:\System Volume Information\_restore{EFBF68CD-A66A-42C5-93DF-EA07F8E0F366}\RP2\A0000081.exe -> Adware.Softomate : Cleaned.
C:\System Volume Information\_restore{EFBF68CD-A66A-42C5-93DF-EA07F8E0F366}\RP2\A0000082.dll -> Adware.Softomate : Cleaned.
C:\System Volume Information\_restore{EFBF68CD-A66A-42C5-93DF-EA07F8E0F366}\RP2\A0000083.exe -> Adware.Softomate : Cleaned.
C:\RECYCLER\S-1-5-21-823518204-1606980848-1060284298-500\Dc36.exe -> Dialer.IDialer.m : Cleaned.
C:\RECYCLER\S-1-5-21-823518204-1606980848-1060284298-500\Dc11.exe -> Dialer.Small : Cleaned.
C:\RECYCLER\S-1-5-21-823518204-1606980848-1060284298-500\Dc35.exe -> Dialer.Small : Cleaned.
C:\WINDOWS\Temp\__delete_on_reboot__w_i_n_2_._t_m_p_._e_x_e_ -> Dialer.Small : Cleaned.
C:\System Volume Information\_restore{EFBF68CD-A66A-42C5-93DF-EA07F8E0F366}\RP2\A0000079.exe -> Downloader.Agent.bca : Cleaned.
C:\System Volume Information\_restore{EFBF68CD-A66A-42C5-93DF-EA07F8E0F366}\RP2\A0000058.exe -> Downloader.Tiny.fk : Cleaned.
C:\WINDOWS\system32\drvfig.dll -> Not-A-Virus.Hoax.Win32.Renos.gi : Cleaned.
C:\WINDOWS\system32\wnscpsv.exe -> Trojan.Small : Cleaned.
::Report end
New Hijackthis! log:
Logfile of HijackThis v1.99.1
Scan saved at 9:23:41 PM, on 6/02/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\WINDOWS\system32\netdde.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Microsoft SQL Server\MSSQL$INVENTORCONTENT\Binn\sqlservr.exe
C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
C:\WINDOWS\System32\RegSrvc.exe
C:\WINDOWS\System32\rsvp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\dllhost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\tlntsvr.exe
C:\WINDOWS\System32\vssvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\TightVNC\WinVNC.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe
C:\Program Files\Microsoft SQL Server\MSSQL$INVENTORCONTENT\Binn\sqlagent.EXE
C:\Program Files\Microsoft Windows OneCare Live\winss.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\WINDOWS\vsnpstd2.exe
C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe
C:\Program Files\Quick GPS Connection Data Download Manager\DesktopLtoManager.exe
C:\Program Files\On Screen Display\Hotkey.exe
C:\Updater.exe
C:\Program Files\Telstra\BigPond Assist\assist.exe
C:\WINDOWS\System32\dllhost.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Battery miser\batterymiser.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\IP Operator\IPOperator.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Webroot\Washer\wwDisp.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Documents and Settings\Mick\Desktop\HJT\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\PCHEALTH\HELPCTR\System\panels\blank.htm
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://go.microsoft....k/?LinkId=74005R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {188BFCE3-671D-46C7-8A5D-1E4F6843AEA7} - C:\WINDOWS\system32\fccca.dll (file missing)
O2 - BHO: (no name) - {68D5CF1D-EC5C-4bdd-A9EF-F0E517565D50} - C:\WINDOWS\system32\wdaltjdl.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: (no name) - {90382AD7-4298-47E0-BC0F-14ACCFF44D2C} - C:\WINDOWS\system32\khfdbab.dll (file missing)
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [SNPSTD2] C:\WINDOWS\vsnpstd2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [OneCareUI] "C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Lto Manager] "C:\Program Files\Quick GPS Connection Data Download Manager\DesktopLtoManager.exe"
O4 - HKLM\..\Run: [KeybdUtility] "C:\Program Files\On Screen Display\Hotkey.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [iRiver Updater] \Updater.exe
O4 - HKLM\..\Run: [ecc] C:\Program Files\Telstra\BigPond Assist\assist.exe
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [batterymiser] C:\Program Files\Battery miser\batterymiser.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [IPOperator] "C:\Program Files\IP Operator\IPOperator.exe" -aUtOsTaRtFrOmReG
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Window Washer] C:\Program Files\Webroot\Washer\wwDisp.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) -
http://h20270.www2.h...staller_gmn.cabO16 - DPF: {2646205B-878C-11D1-B07C-0000C040BCDB} (NSIEMisc Class) - file://C:\Program Files\Telstra\SpeedTouch\BigPondGUI\HTML\nskey.DLL
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.micros...b?1168580886264O16 - DPF: {E36C5562-C4E0-4220-BCB2-1C671E3A5916} -
http://www.seagate.c.../npseatools.cabO16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) -
https://secure.logme...trl.cab?lmi=100O17 - HKLM\System\CCS\Services\Tcpip\..\{248FC7F4-DD81-4971-B2C3-5DE9D4466A48}: NameServer = 144.140.70.30,144.140.71.16
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = nsw.bigpond.net.au
O17 - HKLM\System\CS1\Services\VxD\MSTCP: SearchList = nsw.bigpond.net.au
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = nsw.bigpond.net.au
O17 - HKLM\System\CS2\Services\VxD\MSTCP: SearchList = nsw.bigpond.net.au
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: SearchList = nsw.bigpond.net.au
O17 - HKLM\System\CS3\Services\VxD\MSTCP: SearchList = nsw.bigpond.net.au
O17 - HKLM\System\CCS\Services\VxD\MSTCP: SearchList = nsw.bigpond.net.au
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = nsw.bigpond.net.au
O20 - Winlogon Notify: winbmf32 - C:\WINDOWS\SYSTEM32\winbmf32.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: GoBack Polling Service (GBPoll) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\TightVNC\WinVNC.exe" -service (file missing)