[color=\"#ff0000\"]

http://images.thetechguide.com/forum/public/style_emoticons/<#EMO_DIR#>/rolleyes.gif\' class=\'bbc_emoticon\' alt=\':rolleyes:\' />
Thanks very much for getting back to me. I removed the spyware terminator
heres the logs you asked for
1:[/color]
Logfile of HijackThis v1.99.1
Scan saved at 12:31:19, on 01/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
C:\Program Files\VideoCompressionCodec\pmsngr.exe
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\VideoCompressionCodec\pmmon.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\ZONELA~1\ZONEAL~1\MAILFR~1\mantispm.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\paddy\Desktop\hijackthis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.co.uk/O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7b4d79df-9ef0-429d-a0e9-d9b138c6a53b} - blank (file missing)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RegMech.exe /QS
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: 32Red Poker - {437F7F6F-FFCC-47e1-8A4B-C992493CF6C3} - C:\Program Files\32RedMPP\MPPoker.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://by111fd.bay111.Email Removed.msn.com/resources/MsnPUpld.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cabO16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn.com/download/MsnMesse...pDownloader.cabO18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\WINDOWS\system32\ZoneLabs\isafe.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: spkrmon - Unknown owner - C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
[color=\"#ff00ff\"]
[color=\"#ff0000\"]2:[/color][/color]SmitFraudFix v2.117
Scan done at 12:36:53.57, 01/11/2006
Run from C:\Documents and Settings\paddy\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix run in normal mode
»»»»»»»»»»»»»»»»»»»»»»»» C:\
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
C:\WINDOWS\system32\a.exe FOUND !
C:\WINDOWS\system32\ot.ico FOUND !
C:\WINDOWS\system32\ts.ico FOUND !
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\paddy
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\paddy\Application Data
»»»»»»»»»»»»»»»»»»»»»»»» Start Menu
C:\DOCUME~1\ALLUSE~1\STARTM~1\Online Security Guide.url FOUND !
C:\DOCUME~1\ALLUSE~1\STARTM~1\Security Troubleshooting.url FOUND !
»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\paddy\FAVORI~1
C:\DOCUME~1\paddy\FAVORI~1\Antivirus Test Online.url FOUND !
»»»»»»»»»»»»»»»»»»»»»»»» Desktop
C:\DOCUME~1\ALLUSE~1\Desktop\Online Security Guide.url FOUND !
C:\DOCUME~1\ALLUSE~1\Desktop\Security Troubleshooting.url FOUND !
»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
C:\Program Files\VideoCompressionCodec\ FOUND !
»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys
»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components]
"Source"="
http://newsimg.bbc.co.uk/media/images/4103...le-getty416.jpg"
"SubscribedURL"="
http://newsimg.bbc.co.uk/media/images/4103...le-getty416.jpg"
"FriendlyName"=""
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\1]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{dfa61db1-388e-4c87-8d56-540fa229bcb4}"="contrabandists"
»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""
»»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32
»»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection
»»»»»»»»»»»»»»»»»»»»»»»» End
[color=\"#ff0000\"]3:[/color]paddy - 06-11-01 12:22:24.46 Service Pack 2
ComboFix 06.10.19 - Running from: "C:\Documents and Settings\paddy\Desktop"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\uninstall_nmon.vbs
C:\Documents and Settings\LocalService\Application Data\NetMon
C:\Program Files\Inetget2
C:\Program Files\msmovies
C:\Program Files\network monitor
C:\Program Files\Common Files\{E86EFAA3-0AE9-1033-0721-03062403002c}
((((((((((((((((((((((((((((((( Files Created from 2006-10-01 to 2006-11-01 ))))))))))))))))))))))))))))))))))
2006-10-24 09:50 77,824 --a------ C:\WINDOWS\system32\driverif.dll
2006-10-24 09:50 75,776 --a------ C:\WINDOWS\zllsputility.exe
2006-10-24 09:50 733,236 --a------ C:\WINDOWS\system32\vete.dll
2006-10-24 09:50 541,733 --a------ C:\WINDOWS\system32\drivers\vetmonnt.sys
2006-10-24 09:50 21,605 --a------ C:\WINDOWS\system32\drivers\vet-filt.sys
2006-10-24 09:50 15,668 --a------ C:\WINDOWS\system32\drivers\vet-rec.sys
2006-10-24 09:50 12,288 --a------ C:\WINDOWS\system32\vetntmsg.dll
2006-10-24 09:50 108,453 --a------ C:\WINDOWS\system32\drivers\vetfddnt.sys
2006-10-24 09:42 76,560 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2006-10-13 10:01 3,968 --a------ C:\WINDOWS\system32\drivers\avgclean.sys
2006-10-01 22:23 706,048 --a------ C:\WINDOWS\system32\libmcl-3.1.1.dll
2006-10-01 22:23 3,423,744 --a------ C:\WINDOWS\system32\libfilefmt-1.1.0.dll
2006-10-01 22:23 20,480 --a------ C:\WINDOWS\system32\libavi-dd-1.2.0.dll
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-11-01 12:23 -------- d-------- C:\Program Files\Common Files
2006-11-01 11:19 -------- d-------- C:\Documents and Settings\paddy\Application Data\AVG7
2006-10-30 14:29 -------- d-------- C:\Program Files\32RedMPP
2006-10-30 14:08 -------- d-------- C:\Documents and Settings\paddy\Application Data\Microgaming
2006-10-29 23:11 -------- d-------- C:\Program Files\Roxio Easy Media Creator 7.5 ENG Trial
2006-10-29 21:11 -------- d-------- C:\Program Files\Spyware Terminator
2006-10-29 16:17 -------- d-------- C:\Program Files\eMule
2006-10-29 14:31 -------- d-------- C:\Program Files\QuickTime
2006-10-25 10:17 -------- d-------- C:\Program Files\VideoCompressionCodec
2006-10-24 09:58 -------- d-------- C:\Documents and Settings\paddy\Application Data\MailFrontier
2006-10-24 09:50 -------- d-------- C:\Program Files\Zone Labs
2006-10-24 09:42 -------- d-------- C:\Program Files\Internet Explorer
2006-10-22 14:48 -------- d-------- C:\Program Files\Registry Mechanic
2006-10-22 14:45 -------- d-------- C:\Program Files\Common Files\Download Manager
2006-10-18 17:35 -------- d-------- C:\Program Files\Boilsoft AVI Converter
2006-10-18 17:15 -------- d-------- C:\Program Files\Common Files\AVSMedia
2006-10-18 17:14 -------- d-------- C:\Program Files\AVSMedia
2006-10-18 17:14 -------- d-------- C:\Program Files\Allok AVI MPEG Converter
2006-10-18 13:16 -------- d-------- C:\Program Files\Nero
2006-10-18 13:16 -------- d-------- C:\Program Files\Common Files\Ahead
2006-10-18 08:26 -------- d-------- C:\Program Files\Ahead
2006-10-15 15:18 -------- d-------- C:\Documents and Settings\paddy\Application Data\Free Download Manager
2006-10-14 19:58 -------- d-------- C:\Program Files\MSXML 4.0
2006-10-13 17:31 8464 --a------ C:\WINDOWS\system32\sporder.dll
2006-10-13 10:00 816288 --a------ C:\WINDOWS\system32\drivers\avg7core.sys
2006-10-09 12:52 -------- d-------- C:\Documents and Settings\paddy\Application Data\uTorrent
2006-10-09 00:11 -------- d-------- C:\Documents and Settings\paddy\Application Data\Sun
2006-10-06 23:37 -------- d-------- C:\Program Files\Java
2006-10-02 21:12 -------- d-------- C:\Program Files\Paddy Power Poker
2006-09-25 15:01 -------- d-------- C:\Documents and Settings\paddy\Application Data\deighan1
2006-09-25 13:00 -------- d-------- C:\Program Files\MSN Messenger
2006-09-23 10:39 -------- d-------- C:\Documents and Settings\paddy\Application Data\Rocky2t6
2006-09-20 00:12 2368 --a------ C:\WINDOWS\system32\SVKP.sys
2006-09-19 23:37 -------- d-------- C:\Documents and Settings\paddy\Application Data\Vso
2006-09-19 01:11 -------- d-------- C:\Documents and Settings\paddy\Application Data\Nero
2006-09-18 10:32 34 --a------ C:\Documents and Settings\paddy\Application Data\pcouffin.log
2006-09-18 10:31 81920 --a------ C:\Documents and Settings\paddy\Application Data\ezpinst.exe
2006-09-18 10:31 7176 --a------ C:\Documents and Settings\paddy\Application Data\pcouffin.cat
2006-09-18 10:31 47360 --a------ C:\WINDOWS\system32\drivers\pcouffin.sys
2006-09-18 10:31 47360 --a------ C:\Documents and Settings\paddy\Application Data\pcouffin.sys
2006-09-18 10:31 1144 --a------ C:\Documents and Settings\paddy\Application Data\pcouffin.inf
2006-09-18 10:31 -------- d-------- C:\Program Files\vso
2006-09-16 19:45 -------- d-------- C:\Program Files\Cucusoft
2006-09-16 17:43 -------- d-------- C:\Documents and Settings\paddy\Application Data\deighan
2006-09-15 11:01 -------- d-------- C:\Documents and Settings\paddy\Application Data\Roxio
2006-09-13 05:01 1084416 --a------ C:\WINDOWS\system32\msxml3.dll
2006-09-12 19:04 -------- d--h----- C:\Program Files\InstallShield Installation Information
2006-09-12 19:02 -------- d-------- C:\Documents and Settings\paddy\Application Data\Samsung
2006-09-12 17:58 -------- d-------- C:\Program Files\Samsung
2006-09-12 17:58 -------- d-------- C:\Program Files\Common Files\InstallShield
2006-09-12 16:51 1245184 --a------ C:\WINDOWS\system32\msxml4.dll
2006-09-11 23:27 -------- d-------- C:\Program Files\WinRAR
2006-09-11 22:22 -------- d-------- C:\Documents and Settings\paddy\Application Data\.ABC
2006-09-08 17:26 4222516 --a------ C:\ABC-win32-v3.1.exe
2006-09-08 15:47 -------- d-------- C:\Program Files\MP3 Rocket
2006-09-08 15:47 -------- d-------- C:\Program Files\Common Files\Scanner
2006-09-06 11:15 28416 --a------ C:\WINDOWS\system32\drivers\avg7rsxp.sys
2006-09-06 01:25 -------- d-------- C:\Program Files\MP3 Player Utilities 1.51
2006-09-06 00:43 4960 --a------ C:\WINDOWS\system32\drivers\avgtdi.sys
2006-09-06 00:42 4224 --a------ C:\WINDOWS\system32\drivers\avg7rsw.sys
2006-09-05 23:06 -------- d-------- C:\Program Files\CleanUp!
2006-09-05 20:31 448593 --ahs---- C:\WINDOWS\system32\yycdd.bak1
2006-09-04 21:00 -------- d-------- C:\Documents and Settings\paddy\Application Data\Seven Zip
2006-09-01 15:41 -------- d-------- C:\Documents and Settings\paddy\Application Data\Ahead
2006-08-25 15:45 617472 --a------ C:\WINDOWS\system32\comctl32.dll
2006-08-21 12:21 16896 --a------ C:\WINDOWS\system32\fltlib.dll
2006-08-21 09:14 23040 --a------ C:\WINDOWS\system32\fltmc.exe
2006-08-16 11:58 100352 --a------ C:\WINDOWS\system32\6to4svc.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NvCpl.dll,NvStartup"
"SpeedTouch USB Diagnostics"="\"C:\\Program Files\\Thomson\\SpeedTouch USB\\Dragdiag.exe\" /icon"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"SpywareTerminator"="\"C:\\Program Files\\Spyware Terminator\\SpywareTerminatorShield.exe\""
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgcc.exe /STARTUP"
"NeroFilterCheck"="C:\\Program Files\\Common Files\\Ahead\\Lib\\NeroCheck.exe"
"RegistryMechanic"="C:\\Program Files\\Registry Mechanic\\RegMech.exe /QS"
"Zone Labs Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"Source"="
http://newsimg.bbc.co.uk/media/images/4103...le-getty416.jpg"
"SubscribedURL"="
http://newsimg.bbc.co.uk/media/images/4103...le-getty416.jpg"
"FriendlyName"=""
"Flags"=dword:00001001
"Position"=hex:2c,00,00,00,a2,01,00,00,23,00,00,00,a4,00,00,00,9a,00,00,00,e8,\
03,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:01,00,00,00
"OriginalStateInfo"=hex:18,00,00,00,d2,03,00,00,6d,01,00,00,a0,01,00,00,2c,01,\
00,00,01,00,00,40
"RestoredStateInfo"=hex:14,6d,ae,06,41,c0,b4,74,a8,6f,7a,01,68,de,ae,06,20,6d,\
ae,06,08,09,00,00
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\1]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,00,01,00,00,00,00,00,00,00,04,00,00,de,03,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,6a,02,00,00,23,00,00,00,a4,00,00,00,9a,00,\
00,00,01,00,00,00
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgw.exe /RUNONCE"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgw.exe /RUNONCE"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
"{dfa61db1-388e-4c87-8d56-540fa229bcb4}"="contrabandists"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
"pmsngr.exe"="C:\\Program Files\\VideoCompressionCodec\\pmsngr.exe"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
"CDRAutoRun"=dword:00000000
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
"CDRAutoRun"=dword:00000000
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Symantec NetDetect.job
Completion time: 06-11-01 12:23:50.64
C:\ComboFix.txt ... 06-11-01 12:23
Thats all the logs hope you can help
Thanks guestolo