Hi Blade,
Have done everything you said and am now attaching logs. Here's the DDS
DDS (Ver_09-07-30.01) - NTFSx86
Run by Laurence at 18:51:35.14 on 24/09/2009
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_16
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.3007.2289 [GMT 1:00]
AV: AVG 7.5.552 *On-access scanning enabled* (Updated) {41564737-3200-1071-989B-0000E87B4FB1}
FW: ZoneAlarm Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Digidesign\Drivers\MMERefresh.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\Explorer.EXE
C:\Program Files\Mediafour\MacDrive 7\MacDriveD.exe
C:\Program Files\Novation\USB Audio Driver\nvnusbaudiolog.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\iPod\bin\iPodService.exe
E:\Program Files\iTunes\iTunes.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Laurence\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = uk.msn.com/
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\ahead\lib\NMBgMonitor.exe"
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [{FD1C41EC-B9AC-4F08-9BDB-CC8ECC8FC1B3}] "c:\program files\mediafour\macdrive 7\MacDriveD.exe"
mRun: [DigidesignMMERefresh] c:\program files\digidesign\drivers\MMERefresh.exe
mRun: [NvnUsbAudioLogger] "c:\program files\novation\usb audio driver\nvnusbaudiolog.exe"
mRun: [NeroFilterCheck] c:\program files\common files\ahead\lib\NeroCheck.exe
mRun: [ZoneAlarm Client] "c:\program files\zone labs\zonealarm\zlclient.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "e:\program files\itunes\iTunesHelper.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
dRun: [AVG7_Run] c:\progra~1\grisoft\avg7\avgw.exe /RUNONCE
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
Trusted Zone: cnn.com\www
Trusted Zone: reverbnation.com\www
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab
DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - hxxp://lads.myspace.com/upload/MySpaceUploader1006.cab
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1202321923147
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} - hxxp://lads.myspace.com/upload/MySpaceUploader2.cab
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {FF1CD9A3-00CD-45C1-8182-4EEC229A182D} - hxxps://www.plaxo.com/activex/plx_upldr-2k-xp.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: CShellExecuteHookImpl Object: {57b86673-276a-48b2-bae7-c6dbb3020eb8} - c:\program files\grisoft\avg anti-spyware 7.5\shellexecutehook.dll
================= FIREFOX ===================
FF - ProfilePath -
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
============= SERVICES / DRIVERS ===============
R0 DigiFilter;DigiFilter;c:\windows\system32\drivers\DigiFilt.sys [2008-2-2 16384]
R0 MDFSYSNT;MacDrive file system driver;c:\windows\system32\drivers\MDFSYSNT.SYS [2007-4-18 274048]
R0 MDPMGRNT;MDPMGRNT;c:\windows\system32\drivers\MDPMGRNT.sys [2007-2-28 19072]
R0 Si3132r5;Si3132r5;c:\windows\system32\drivers\Si3132r5.sys [2008-1-30 215856]
R0 Si3531;Si3531;c:\windows\system32\drivers\Si3531.sys [2008-1-30 210736]
R0 SiWinAcc;SiWinAcc;c:\windows\system32\drivers\SiWinAcc.sys [2008-1-30 17328]
R1 AVG Anti-Spyware Driver;AVG Anti-Spyware Driver;c:\program files\grisoft\avg anti-spyware 7.5\guard.sys [2007-5-30 11000]
R1 Avg7Core;AVG7 Kernel;c:\windows\system32\drivers\avg7core.sys [2008-2-6 821856]
R1 Avg7RsW;AVG7 Wrap Driver;c:\windows\system32\drivers\avg7rsw.sys [2008-2-6 4224]
R1 Avg7RsXP;AVG7 Resident Driver XP;c:\windows\system32\drivers\avg7rsxp.sys [2008-2-6 27776]
R1 AvgAsCln;AVG Anti-Spyware Clean Driver;c:\windows\system32\drivers\AvgAsCln.sys [2008-2-7 10872]
R1 AvgClean;AVG7 Clean Driver;c:\windows\system32\drivers\avgclean.sys [2008-2-6 10760]
R1 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2008-2-6 353672]
R2 AvgTdi;AVG Network Redirector;c:\windows\system32\drivers\avgtdi.sys [2008-2-6 4960]
R2 DigiNet;Digidesign Ethernet Support;c:\windows\system32\drivers\diginet.sys [2008-2-2 16400]
R2 LANPkt;Realtek LANPkt Protocol;c:\windows\system32\drivers\LANPkt.sys [2008-2-2 8440]
R3 dalwdmservice;dal service;c:\windows\system32\drivers\Dalwdm.sys [2008-2-2 97808]
R3 MBX2DFU;MBX2DFU;c:\windows\system32\drivers\mbx2dfu.sys [2008-2-2 21648]
R3 MBX2MIDK;Digidesign Mbox 2 Midi Driver;c:\windows\system32\drivers\mbx2midk.sys [2008-2-2 21904]
S2 vsmon;TrueVector Internet Monitor;c:\windows\system32\zonelabs\vsmon.exe -service --> c:\windows\system32\zonelabs\vsmon.exe -service [?]
S3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;c:\windows\system32\DNINDIS5.sys [2008-8-19 17149]
S3 getPlusHelper;getPlus® Helper;c:\windows\system32\svchost.exe -k getPlusHelper [2008-1-30 14336]
S3 IKFileSec;File Security Driver;c:\windows\system32\drivers\ikfilesec.sys [2008-12-2 40840]
S3 IKSysFlt;System Filter Driver;c:\windows\system32\drivers\iksysflt.sys [2008-12-2 66952]
S3 IKSysSec;System Security Driver;c:\windows\system32\drivers\iksyssec.sys [2008-12-2 81288]
S3 NvnUsbAudio;NvnUsbAudio;c:\windows\system32\drivers\nvnusbaudio.sys [2008-2-3 25600]
S3 WPN111;Wireless USB 2.0 Adapter with RangeMax Service;c:\windows\system32\drivers\WPN111.sys [2008-8-19 362944]
S4 aawservice;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\aawservice.exe [2008-9-10 611664]
S4 AVG Anti-Spyware Guard;AVG Anti-Spyware Guard;c:\program files\grisoft\avg anti-spyware 7.5\guard.exe [2007-5-30 312880]
S4 Avg7Alrt;AVG7 Alert Manager Server;c:\progra~1\grisoft\avg7\avgamsvr.exe [2008-2-6 418816]
S4 Avg7UpdSvc;AVG7 Update Service;c:\progra~1\grisoft\avg7\avgupsvc.exe [2008-2-6 49664]
S4 AVGEMS;AVG E-mail Scanner;c:\progra~1\grisoft\avg7\avgemc.exe [2008-2-6 406528]
S4 MacDriveServiceD;MacDriveServiceD;c:\program files\mediafour\macdrive 7\MacDriveServiceD.exe [2007-4-18 143360]
S4 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2008-12-2 356920]
S4 sdCoreService;PC Tools Security Service;c:\program files\spyware doctor\pctsSvc.exe [2008-12-2 1079176]
=============== Created Last 30 ================
==================== Find3M ====================
2009-09-14 02:12 229,888 a------- c:\windows\PEV.exe
2009-08-05 10:01 204,800 a------- c:\windows\system32\mswebdvd.dll
2009-08-03 23:17 411,368 a------- c:\windows\system32\deploytk.dll
2009-08-03 22:47 69,632 a------- c:\windows\Alcmtr.exe
2009-08-03 13:36 38,160 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-03 13:36 19,096 a------- c:\windows\system32\drivers\mbam.sys
2009-07-29 05:37 119,808 a------- c:\windows\system32\t2embed.dll
2009-07-29 05:37 81,920 a------- c:\windows\system32\fontsub.dll
2009-07-27 22:01 11,784 a------- c:\windows\unins000.dat
2009-07-27 21:54 684,313 a------- c:\windows\unins000.exe
2009-07-17 20:01 58,880 a------- c:\windows\system32\atl.dll
2009-07-13 23:43 286,208 a------- c:\windows\system32\wmpdxm.dll
2009-07-03 18:09 915,456 -------- c:\windows\system32\wininet.dll
2008-12-01 18:02 47,360 a------- c:\docume~1\laurence\applic~1\pcouffin.sys
2008-02-13 22:31 32 a------- c:\docume~1\alluse~1\applic~1\ezsid.dat
2008-11-06 17:41 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008110620081107\index.dat
============= FINISH: 18:52:11.10 ===============
Here is the combofix:
ComboFix 09-09-23.02 - Laurence 03/08/2009 22:47.3.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.3007.2486 [GMT 1:00]
Running from: c:\documents and settings\Laurence\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Laurence\Desktop\CFScript.txt
AV: AVG 7.5.552 *On-access scanning enabled* (Updated) {41564737-3200-1071-989B-0000E87B4FB1}
FW: ZoneAlarm Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.
((((((((((((((((((((((((( Files Created from 2009-07-03 to 2009-08-03 )))))))))))))))))))))))))))))))
.
2009-08-07 17:26 . 2009-08-07 17:26 -------- d-sh--w- c:\documents and settings\Laurence\IECompatCache
2009-08-07 17:25 . 2009-08-07 17:25 -------- d-sh--w- c:\documents and settings\Laurence\PrivacIE
2009-08-07 17:24 . 2009-08-07 17:24 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2009-08-07 17:24 . 2009-06-25 08:25 54272 -c----w- c:\windows\system32\dllcache\wdigest.dll
2009-08-07 17:24 . 2009-06-25 08:25 301568 -c----w- c:\windows\system32\dllcache\kerberos.dll
2009-08-07 17:24 . 2009-06-25 08:25 136192 -c----w- c:\windows\system32\dllcache\msv1_0.dll
2009-08-07 17:24 . 2009-06-24 11:18 92928 -c----w- c:\windows\system32\dllcache\ksecdd.sys
2009-08-07 17:24 . 2009-08-07 17:24 -------- d-sh--w- c:\documents and settings\Laurence\IETldCache
2009-08-07 17:21 . 2009-08-07 08:48 100352 -c----w- c:\windows\system32\dllcache\iecompat.dll
2009-08-07 17:20 . 2009-08-07 17:21 -------- d-----w- c:\windows\ie8updates
2009-08-07 17:20 . 2009-07-03 17:09 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2009-08-07 17:20 . 2009-07-03 17:09 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2009-08-07 17:19 . 2009-08-07 17:20 -------- dc-h--w- c:\windows\ie8
2009-08-07 17:11 . 2009-08-07 17:12 -------- d-----w- C:\a700265b5282518f945b7aaa09b846d1
2009-08-07 17:11 . 2009-08-07 17:23 -------- d-----w- c:\windows\SxsCaPendDel
2009-08-05 17:27 . 2009-07-10 13:27 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll
2009-08-05 09:01 . 2009-08-05 09:01 204800 -c----w- c:\windows\system32\dllcache\mswebdvd.dll
2009-08-03 21:47 . 2009-08-03 21:47 69632 ----a-w- c:\windows\Alcmtr.exe
2009-07-29 04:37 . 2009-07-29 04:37 81920 -c----w- c:\windows\system32\dllcache\fontsub.dll
2009-07-29 04:37 . 2009-07-29 04:37 119808 -c----w- c:\windows\system32\dllcache\t2embed.dll
2009-07-27 20:54 . 2009-07-27 21:01 11784 ----a-w- c:\windows\unins000.dat
2009-07-27 20:54 . 2009-07-27 20:54 684313 ----a-w- c:\windows\unins000.exe
2009-07-26 18:05 . 2009-07-26 18:05 -------- d-----w- c:\program files\XLN Audio
2009-07-17 19:01 . 2009-07-17 19:01 58880 -c----w- c:\windows\system32\dllcache\atl.dll
2009-07-16 23:33 . 2009-07-16 23:33 -------- d-----w- c:\program files\iPod
2009-07-14 17:12 . 2009-07-14 17:13 -------- d-----w- c:\program files\QuickTime
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-07 17:54 . 2008-02-04 19:27 70224 ----a-w- c:\documents and settings\Laurence\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-05 09:01 . 2008-01-29 23:18 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-05 00:53 . 2008-12-18 02:06 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-04 23:58 . 2008-02-03 01:32 -------- d-----w- c:\documents and settings\Laurence\Application Data\GetRightToGo
2009-08-04 22:43 . 2008-08-26 22:32 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-08-04 22:26 . 2008-02-06 19:51 -------- d-----w- c:\documents and settings\Laurence\Application Data\AVG7
2009-08-04 09:17 . 2008-02-09 13:29 -------- d-----w- c:\documents and settings\Laurence\Application Data\Azureus
2009-08-03 21:53 . 2008-06-01 00:02 -------- d-----w- c:\program files\Windows Live Safety Center
2009-08-03 21:43 . 2008-02-02 16:34 -------- d-----w- c:\documents and settings\Laurence\Application Data\Digidesign
2009-08-03 12:36 . 2008-12-18 02:06 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-03 12:36 . 2008-12-18 02:06 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-07-29 04:37 . 2008-01-29 23:19 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-07-29 04:37 . 2008-01-29 23:18 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-07-17 19:01 . 2008-01-29 23:18 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-16 23:33 . 2008-02-02 15:55 -------- d-----w- c:\program files\Common Files\Apple
2009-07-13 22:43 . 2008-01-29 23:19 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-03 17:09 . 2008-01-29 23:19 915456 ------w- c:\windows\system32\wininet.dll
2009-06-25 08:25 . 2008-01-29 23:19 54272 ----a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2008-01-29 23:19 56832 ----a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2008-01-29 23:19 147456 ----a-w- c:\windows\system32\schannel.dll
2009-06-25 08:25 . 2008-01-29 23:18 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-06-25 08:25 . 2008-01-29 23:18 730112 ----a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:25 . 2008-01-29 23:18 301568 ----a-w- c:\windows\system32\kerberos.dll
2009-06-24 11:18 . 2008-01-29 23:18 92928 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-22 17:14 . 2008-02-13 21:26 -------- d-----w- c:\documents and settings\Laurence\Application Data\Skype
2009-06-22 17:12 . 2008-02-13 21:31 -------- d-----w- c:\documents and settings\Laurence\Application Data\skypePM
2009-06-12 12:31 . 2008-01-29 23:19 76288 ----a-w- c:\windows\system32\telnet.exe
2009-06-10 14:13 . 2008-01-29 23:18 84992 ----a-w- c:\windows\system32\avifil32.dll
2009-06-10 08:19 . 2008-01-29 16:34 2066432 ----a-w- c:\windows\system32\mstscax.dll
2009-06-10 06:14 . 2008-01-29 23:19 132096 ----a-w- c:\windows\system32\wkssvc.dll
2009-06-05 10:42 . 2009-04-21 13:31 2060288 ----a-w- c:\windows\system32\usbaaplrc.dll
2009-06-05 10:42 . 2008-02-02 15:55 39424 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2009-06-03 19:09 . 2008-01-29 23:19 1291264 ----a-w- c:\windows\system32\quartz.dll
2009-05-15 18:07 . 2008-02-06 19:31 4212 ---ha-w- c:\windows\system32\zllictbl.dat
2009-05-07 15:32 . 2008-01-29 23:18 345600 ----a-w- c:\windows\system32\localspl.dll
2009-02-24 19:34 . 2009-02-24 19:34 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-02-24 19:34 . 2009-02-24 19:34 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-08-08_22.14.29 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-01-29 23:19 . 2009-08-03 09:58 67768 c:\windows\system32\perfc009.dat
- 2008-01-29 23:19 . 2009-08-08 18:07 67768 c:\windows\system32\perfc009.dat
+ 2008-01-29 23:19 . 2009-08-03 09:58 433130 c:\windows\system32\perfh009.dat
- 2008-01-29 23:19 . 2009-08-08 18:07 433130 c:\windows\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-01 153136]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"{FD1C41EC-B9AC-4F08-9BDB-CC8ECC8FC1B3}"="c:\program files\Mediafour\MacDrive 7\MacDriveD.exe" [2007-04-18 159744]
"DigidesignMMERefresh"="c:\program files\Digidesign\Drivers\MMERefresh.exe" [2007-10-31 77824]
"NvnUsbAudioLogger"="c:\program files\Novation\USB Audio Driver\nvnusbaudiolog.exe" [2007-05-04 7168]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2009-02-15 981384]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-26 413696]
"iTunesHelper"="e:\program files\iTunes\iTunesHelper.exe" [2009-07-13 292128]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="c:\progra~1\Grisoft\AVG7\avgw.exe" [2008-02-06 219136]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"wave1"=Digi32.dll
"MIDI2"=diomidi.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AVG Anti-Spyware Guard]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^##nospam.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\##nospam.lnk
backup=c:\windows\pss\##nospam.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^NETGEAR WPN111 Smart Wizard.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\NETGEAR WPN111 Smart Wizard.lnk
backup=c:\windows\pss\NETGEAR WPN111 Smart Wizard.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Laurence^Start Menu^Programs^Startup^MagicDisc.lnk]
path=c:\documents and settings\Laurence\Start Menu\Programs\Startup\MagicDisc.lnk
backup=c:\windows\pss\MagicDisc.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3 (0x3)
"WLSetupSvc"=3 (0x3)
"vsmon"=2 (0x2)
"usnjsvc"=3 (0x3)
"NVSvc"=2 (0x2)
"NMIndexingService"=3 (0x3)
"NBService"=3 (0x3)
"MacDriveServiceD"=2 (0x2)
"iPod Service"=3 (0x3)
"idsvc"=3 (0x3)
"digiSPTIService"=3 (0x3)
"Bonjour Service"=2 (0x2)
"Apple Mobile Device"=2 (0x2)
"sdCoreService"=3 (0x3)
"sdAuxService"=3 (0x3)
"aawservice"=2 (0x2)
"AVGEMS"=2 (0x2)
"Avg7UpdSvc"=2 (0x2)
"Avg7Alrt"=2 (0x2)
"AVG Anti-Spyware Guard"=2 (0x2)
"Nero BackItUp Scheduler 3"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"c:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"c:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"c:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\WINDOWS\\system32\\ZoneLabs\\vsmon.exe"=
"c:\\Program Files\\Mediafour\\MacDrive 7\\MacDriveD.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"e:\\Program Files\\iTunes\\iTunes.exe"=
R0 DigiFilter;DigiFilter;c:\windows\system32\drivers\DigiFilt.sys [02/02/2008 15:56 16384]
R0 MDFSYSNT;MacDrive file system driver;c:\windows\system32\drivers\MDFSYSNT.SYS [18/04/2007 17:33 274048]
R0 MDPMGRNT;MDPMGRNT;c:\windows\system32\drivers\MDPMGRNT.sys [28/02/2007 12:15 19072]
R0 Si3531;Si3531;c:\windows\system32\drivers\Si3531.sys [30/01/2008 00:26 210736]
R0 SiWinAcc;SiWinAcc;c:\windows\system32\drivers\SiWinAcc.sys [30/01/2008 00:26 17328]
R2 DigiNet;Digidesign Ethernet Support;c:\windows\system32\drivers\diginet.sys [02/02/2008 15:54 16400]
R2 LANPkt;Realtek LANPkt Protocol;c:\windows\system32\drivers\LANPkt.sys [02/02/2008 15:24 8440]
R3 dalwdmservice;dal service;c:\windows\system32\drivers\Dalwdm.sys [02/02/2008 15:54 97808]
R3 MBX2DFU;MBX2DFU;c:\windows\system32\drivers\mbx2dfu.sys [02/02/2008 15:54 21648]
R3 MBX2MIDK;Digidesign Mbox 2 Midi Driver;c:\windows\system32\drivers\mbx2midk.sys [02/02/2008 15:54 21904]
S3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;c:\windows\system32\DNINDIS5.sys [19/08/2008 17:18 17149]
S3 NvnUsbAudio;NvnUsbAudio;c:\windows\system32\drivers\nvnusbaudio.sys [03/02/2008 20:26 25600]
S3 WPN111;Wireless USB 2.0 Adapter with RangeMax Service;c:\windows\system32\drivers\WPN111.sys [19/08/2008 17:18 362944]
S4 MacDriveServiceD;MacDriveServiceD;c:\program files\Mediafour\MacDrive 7\MacDriveServiceD.exe [18/04/2007 12:58 143360]
S4 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [02/12/2008 15:50 356920]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-08-04 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 11:34]
.
.
------- Supplementary Scan -------
.
uStart Page = uk.msn.com/
uInternet Settings,ProxyOverride = *.local
Trusted Zone: cnn.com\www
Trusted Zone: reverbnation.com\www
DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} - hxxp://lads.myspace.com/upload/MySpaceUploader2.cab
FF - ProfilePath - c:\documents and settings\Laurence\Application Data\Mozilla\Firefox\Profiles\ing4n3g8.default\
FF - plugin: e:\program files\iTunes\Mozilla Plugins\npitunes.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-08-03 22:54
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(2064)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-08-03 22:56
ComboFix-quarantined-files.txt 2009-08-03 21:56
ComboFix2.txt 2009-08-08 22:19
ComboFix3.txt 2008-12-02 17:40
C:\DeQuarantine.txt
Pre-Run: 82,952,540,160 bytes free
Post-Run: 83,113,566,208 bytes free
244 --- E O F --- 2009-08-06 22:41
Here is Kaspersky log (crtical area scan didn't find anything but "my computer" scan did), I have deleted the wma's but not the other stuff as it's programs I use quite a lot, do you think they really contain viruses?:
--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0: scan report
Thursday, September 24, 2009
Operating system: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Saturday, September 26, 2009 00:14:50
Records in database: 2920954
--------------------------------------------------------------------------------
Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes
Scan area - My Computer:
C:\
D:\
E:\
F:\
Scan statistics:
Objects scanned: 187107
Threats found: 7
Infected objects found: 10
Suspicious objects found: 0
Scan duration: 08:54:44
File name / Threat / Threats count
C:\Documents and Settings\Laurence\Application Data\Sun\Java\Deployment\cache\6.0\16\78fcee10-4e7b73c5 Infected: Trojan-Downloader.Java.OpenConnection.at 1
C:\Documents and Settings\Laurence\Application Data\Sun\Java\Deployment\cache\6.0\57\4839f1b9-14d68b2d Infected: Trojan-Downloader.Java.OpenConnection.at 1
C:\Documents and Settings\Laurence\Desktop\Sony.Vegas.With.Plugins\Plugins\NewBlue FX\Motion blends.exe Infected: not-a-virus:AdWare.Win32.EShoper.am 1
C:\Documents and Settings\Laurence\Desktop\Sony.Vegas.With.Plugins.rar Infected: not-a-virus:AdWare.Win32.EShoper.am 1
E:\Program Files\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.631 1
E:\D drive\New Folder\Sony.Vegas.Movie.Studio.Platinum.Edition.V-8.0d.build.139\Sony.Vegas.Movie.Studio.Platinum.Edition.v8.0d.build.139.rar Infected: not-a-virus:AdWare.Win32.Virtumonde.qqz 1
E:\D drive\New Folder\DVD Fab PLATINUM EDITION 4.0.6.0.(NEW-with serial key)\DVDFabPlatinum4060.rar Infected: Trojan.Win32.Delf.bur 1
E:\D drive\New Folder\VASST Ultimate S 3.0.3 !The Ultimate Plug-in For Sony Vegas 6 & 7 Software 3.0.3.rar Infected: not-a-virus:PSWTool.Win32.IEPassView.l 1
E:\D drive\Shared\!! mandolin concerto 11.wma Infected: Trojan-Downloader.WMA.Wimad.d 1
E:\D drive\Shared\dog eat dog no fronts 22.wma Infected: Trojan-Downloader.WMA.Wimad.d 1
Selected area has been scanned.