Thank you very much for your reply and time, I can wait so no need to apologise ever. I definitely still have something, ad windows pop up in a browser spontaneously trying to get me to download and install more rubbish probably. I am also constantly being warned about file extension changes, since installing the protection, but don't know if this is good or bad? Here are the logs.ComboFix 08-03-01.3 - Phil 2008-03-03 4:59:54.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.191 [GMT 0:00]
Running from: C:\Documents and Settings\Phil\Desktop\ComboFix.exe
[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
.
((((((((((((((((((((((((( Files Created from 2008-02-03 to 2008-03-03 )))))))))))))))))))))))))))))))
.
2008-03-02 07:07 . 2008-03-02 07:07 275 --a------ C:\WINDOWS\wininit.ini
2008-03-01 20:22 . 2008-03-01 20:24 <DIR> d-------- C:\Documents and Settings\Phil\Application Data\EngMaths
2008-03-01 20:20 . 2008-03-01 20:24 <DIR> d-------- E:\Program Files\Engineering Mathematics
2008-03-01 18:49 . 2008-03-01 18:54 <DIR> d-------- E:\Program Files\Windows Live Safety Center
2008-03-01 18:19 . 2008-03-02 09:38 <DIR> d-------- E:\Program Files\RegScrubXP
2008-03-01 18:11 . 2008-03-01 18:11 <DIR> d-------- E:\Program Files\CCleaner
2008-03-01 16:12 . 2008-03-02 15:23 <DIR> d-------- E:\Program Files\WinClamAVShield
2008-03-01 16:07 . 2008-03-01 16:07 138,752 --a------ C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2008-03-01 16:06 . 2008-03-01 16:06 <DIR> d-------- E:\Program Files\SUPERAntiSpyware
2008-03-01 16:06 . 2008-03-02 10:11 <DIR> d-------- E:\Program Files\Spyware Terminator
2008-03-01 16:06 . 2008-03-01 16:06 <DIR> d-------- C:\Documents and Settings\Phil\Application Data\SUPERAntiSpyware.com
2008-03-01 16:06 . 2008-03-02 15:22 <DIR> d-------- C:\Documents and Settings\Phil\Application Data\Spyware Terminator
2008-03-01 16:06 . 2008-03-01 16:06 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-03-01 16:06 . 2008-03-02 10:09 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spyware Terminator
2008-03-01 16:03 . 2008-03-01 16:03 <DIR> d-------- E:\Program Files\Spybot - Search & Destroy
2008-03-01 16:03 . 2008-03-01 16:05 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-03-01 15:59 . 2008-03-02 10:02 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-01 15:58 . 2008-03-02 10:02 <DIR> d-------- E:\Program Files\SpywareBlaster
2008-03-01 14:05 . 2007-12-04 12:54 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr
2008-03-01 14:05 . 2007-12-04 14:55 94,544 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2008-03-01 14:05 . 2007-12-04 14:56 93,264 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2008-03-01 14:05 . 2007-12-04 14:51 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2008-03-01 14:05 . 2007-12-04 14:49 26,624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2008-03-01 14:05 . 2007-12-04 14:53 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2008-03-01 14:04 . 2008-03-01 14:04 <DIR> d-------- E:\Program Files\Alwil Software
2008-03-01 14:04 . 2003-03-18 20:20 1,060,864 --a------ C:\WINDOWS\system32\MFC71.dll
2008-03-01 14:04 . 2007-12-04 13:04 837,496 --a------ C:\WINDOWS\system32\aswBoot.exe
2008-03-01 14:04 . 2004-01-09 09:13 380,928 --a------ C:\WINDOWS\system32\actskin4.ocx
2008-03-01 13:47 . 2008-03-01 13:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avg7
2008-03-01 11:15 . 2004-08-03 23:56 388,608 --a------ C:\CF19599.exe
2008-03-01 10:52 . 2008-03-01 10:52 <DIR> d-------- E:\Program Files\Trend Micro
2008-03-01 08:05 . 2008-03-01 08:05 <DIR> d-------- C:\Documents and Settings\Phil\Temporary Internet Files
2008-02-29 19:21 . 2008-02-29 19:21 <DIR> d-------- E:\Program Files\Lavasoft
2008-02-29 19:21 . 2008-02-29 19:22 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-29 17:21 . 2008-03-01 10:56 2,410 --a------ C:\WINDOWS\system32\tmp.reg
2008-02-29 16:22 . 2008-02-29 16:22 <DIR> d-------- E:\Program Files\Enigma Software Group
2008-02-24 18:21 . 2008-02-24 18:21 <DIR> d-------- C:\Documents and Settings\All Users\CrypKey
2008-02-24 18:07 . 2008-02-25 06:48 4,480 --a------ C:\WINDOWS\system32\esnecil.nlp
2008-02-24 18:07 . 2008-02-25 17:10 4,480 --a------ C:\WINDOWS\system32\esnecil.ind
2008-02-24 18:07 . 2008-02-25 17:10 4 --a------ C:\WINDOWS\vx86036.dat
2008-02-24 10:49 . 2008-02-24 18:23 <DIR> d-------- E:\Program Files\PyroSim 2007
2008-02-24 10:49 . 2008-02-24 10:49 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\PyroSim
2008-02-24 10:48 . 2008-02-25 17:09 <DIR> d-------- E:\Program Files\PyroSim
2008-02-24 10:48 . 1999-06-18 21:49 165,888 --a------ C:\WINDOWS\Ckconfig.exe
2008-02-24 10:48 . 2007-05-23 18:29 122,880 --a------ C:\WINDOWS\system32\Crypserv.exe
2008-02-24 10:48 . 1996-05-03 17:21 27,648 -ra------ C:\WINDOWS\Setup_ck.exe
2008-02-24 10:48 . 1996-05-03 15:36 18,432 --a------ C:\WINDOWS\Setup_ck.dll
2008-02-24 10:48 . 2007-05-01 21:15 16,896 --a------ C:\WINDOWS\system32\Ckldrv.sys
2008-02-24 10:48 . 1995-07-04 18:33 11,776 --a------ C:\WINDOWS\Ckrfresh.exe
2008-02-24 10:48 . 2008-02-24 10:50 78 --a------ C:\WINDOWS\Crypkey.ini
2008-02-14 00:58 . 2008-02-14 00:58 <DIR> d-------- E:\Program Files\CFAST6
2008-02-13 07:06 . 2008-02-13 07:06 <DIR> d-------- E:\Program Files\Microsoft Silverlight
2008-02-10 09:14 . 2008-03-02 09:10 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-02-10 09:14 . 2008-02-10 09:14 1,409 --a------ C:\WINDOWS\QTFont.for
2008-02-10 09:09 . 2008-02-10 09:09 <DIR> d-------- E:\Program Files\Apple Software Update
2008-02-10 09:09 . 2008-02-10 09:09 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-02 09:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-03-02 06:57 --------- d-----w C:\Documents and Settings\Phil\Application Data\EndNote
2008-03-01 17:34 --------- d-----w E:\Program Files\Quicknation
2008-03-01 16:05 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-02-11 18:09 --------- d-----w C:\Program Files\Common Files\Adobe
2008-02-10 09:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-10-09 16:41 952 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0F296CA4-A145-4C7C-B036-1B67F8BFFC93}]
2007-02-17 06:59 868424 --a------ E:\PROGRA~1\QUICKN~1\YOUTUB~1.DLL
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56 15360]
"SUPERAntiSpyware"="E:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-02-29 16:03 1481968]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2003-12-19 09:53 65024 C:\WINDOWS\SOUNDMAN.EXE]
"AGRSMMSG"="AGRSMMSG.exe" [2003-09-23 16:06 88363 C:\WINDOWS\AGRSMMSG.exe]
"ATIModeChange"="Ati2mdxx.exe" [2001-09-04 08:24 28672 C:\WINDOWS\system32\Ati2mdxx.exe]
"KTPWare"="C:\Program Files\Elantech\ktp3.exe" [2003-11-27 10:33 258048]
"Tweak UI"="TWEAKUI.CPL" [2000-06-18 13:03 106544 C:\WINDOWS\system32\TWEAKUI.CPL]
"Windows Defender"="E:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 18:20 866584]
"SunJavaUpdateSched"="E:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"avast!"="E:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 13:00 79224]
"SpywareTerminator"="E:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe" [2008-03-01 16:07 2957824]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Windows Desktop Search.lnk - E:\Program Files\Windows Desktop Search\WindowsSearch.exe [2007-02-05 14:40:46 118784]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= E:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2007-02-05 14:39 294400]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= E:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"AvpSrv"= {f55bb8d4-0538-4ffd-a3b2-e48854f7dffb} - C:\WINDOWS\Installer\{f55bb8d4-0538-4ffd-a3b2-e48854f7dffb}\AvpSrv.dll [2008-02-29 15:08 18706]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
E:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 12:41 294912 E:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"E:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"E:\\Program Files\\PyroSim 2007\\fds\\smpd.exe"=
R0 rmedia;Ricoh MediaCard Driver;C:\WINDOWS\system32\DRIVERS\rmedia.sys [2003-10-20 18:09]
R1 sp_rsdrv2;Spyware Terminator Driver 2;C:\WINDOWS\system32\drivers\sp_rsdrv2.sys [2008-03-01 16:07]
R2 mpich2_smpd;MPICH2 Process Manager, Argonne National Lab;E:\Program Files\PyroSim 2007\fds\smpd.exe [2008-01-23 21:01]
R3 Ktp3;Elantech TouchPad(KTP3);C:\WINDOWS\system32\DRIVERS\Ktp3.sys [2004-03-03 08:20]
S3 sea3bus;Sony Ericsson Device 0A3 driver (WDM);C:\WINDOWS\system32\DRIVERS\sea3bus.sys [2007-01-26 20:05]
S3 sea3mdfl;Sony Ericsson Device 0A3 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\sea3mdfl.sys [2007-01-26 20:06]
S3 sea3mdm;Sony Ericsson Device 0A3 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\sea3mdm.sys [2007-01-26 20:06]
.
Contents of the 'Scheduled Tasks' folder
"2008-03-01 10:44:51 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- E:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-03-03 04:42:16 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- E:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-03 05:00:40
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
folder error: C:\WINDOWS
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\explorer.exe [6.00.2900.3156]
-> C:\WINDOWS\Installer\{f55bb8d4-0538-4ffd-a3b2-e48854f7dffb}\AvpSrv.dll
.
Completion time: 2008-03-03 5:01:52
ComboFix2.txt 2008-03-03 04:57:11
ComboFix3.txt 2008-03-01 11:19:40
.
2008-02-29 17:31:26 --- E O F ---
============================================
SmitFraudFix v2.298
Scan done at 5:03:01.57, 03/03/2008
Run from C:\Documents and Settings\Phil\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode
»»»»»»»»»»»»»»»»»»»»»»»» Process
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
E:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
E:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
E:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\crypserv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
E:\Program Files\PyroSim 2007\fds\smpd.exe
E:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Elantech\ktp3.exe
C:\WINDOWS\system32\SearchIndexer.exe
E:\Program Files\Windows Defender\MSASCui.exe
E:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
E:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
E:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\ctfmon.exe
E:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
E:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
E:\Program Files\Windows Desktop Search\WindowsSearch.exe
E:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
E:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
»»»»»»»»»»»»»»»»»»»»»»»» hosts
»»»»»»»»»»»»»»»»»»»»»»»» C:\
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Phil
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Phil\Application Data
»»»»»»»»»»»»»»»»»»»»»»»» Start Menu
»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Phil\FAVORI~1
»»»»»»»»»»»»»»»»»»»»»»»» Desktop
»»»»»»»»»»»»»»»»»»»»»»»» E:\Program Files
»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys
»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
»»»»»»»»»»»»»»»»»»»»»»»» IEDFix
!!!Attention, following keys are not inevitably infected!!!
IEDFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» VACFix
!!!Attention, following keys are not inevitably infected!!!
VACFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
----------------------+
[!] Suspicious: AvpSrv.dll
SSODL: AvpSrv - {f55bb8d4-0538-4ffd-a3b2-e48854f7dffb}
»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""
»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""
»»»»»»»»»»»»»»»»»»»»»»»» Rustock
»»»»»»»»»»»»»»»»»»»»»»»» DNS
Description: Intel(R) PRO/Wireless 2200BG Network Connection - Packet Scheduler Miniport
DNS Server Search Order: 192.168.2.1
HKLM\SYSTEM\CCS\Services\Tcpip\..\{9CEBBDD8-F316-45D4-B13E-D67ABA6087DC}: DhcpNameServer=192.168.2.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{9CEBBDD8-F316-45D4-B13E-D67ABA6087DC}: DhcpNameServer=192.168.2.1
HKLM\SYSTEM\CS3\Services\Tcpip\..\{9CEBBDD8-F316-45D4-B13E-D67ABA6087DC}: DhcpNameServer=192.168.2.1
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1
»»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection
»»»»»»»»»»»»»»»»»»»»»»»» End