Hi Chris,
Sorry for the late reply, i have done what you have ask me to do. Please see below for the new HJT log and AVGAS report. Thanks.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:32:36 PM, on 4/21/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Intuit\QuickBooks Pro\qbw32.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\PROGRA~1\MICROS~2\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Trend Micro\LousyPic\LousyPic.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://go.compaq.com/1Q00CDT/0409/bl8.aspR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.livescore.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://go.microsoft.com/fwlink/?LinkId=74005O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk.disabled
O4 - Global Startup: QuickBooks Professional Edition 2003.lnk = C:\Program Files\Intuit\QuickBooks Pro\qbw32.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: Shortcut to E-mail.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) -
http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cabO16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) -
http://messenger.zone.msn.com/binary/MineS...er.cab31267.cabO16 - DPF: {47CEF84E-92D8-4C4A-86D7-CB982889DCC0} (Oberon Media Network Optimizer) -
http://mp1.mplay.oberon-media.com/client/flashnet.cabO16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary/Messe...StatsClient.cabO16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) -
http://www.parispourvous.com/paris4you/act...sCamControl.ocxO16 - DPF: {AD08A333-609E-11D3-950C-008098601567} -
http://wordreference.com/Install/defin.cabO16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} (Facebook Photo Uploader 4) -
http://upload.facebook.com/controls/Facebo...Uploader4_5.cabO16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) -
http://messenger.zone.msn.com/binary/Solit...wn.cab30149.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{46730882-F687-4AB1-AAEA-3DE7B2FEB6DA}: NameServer = 203.92.64.194,203.92.84.194
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
--
End of file - 6409 bytes
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 4:00:00 PM 4/21/2008
+ Scan result:
C:\Program Files\iWin Games\sadiWinGamesHookIE.dll -> Adware.BHO : Cleaned with backup (quarantined).
C:\Program Files\Microsoft AntiSpyware\Quarantine\A7B997D6-9539-41ED-A258-E2CD95\6671BC14-1C05-4AA3-B1E7-636F11 -> Adware.Comet : Cleaned with backup (quarantined).
C:\Program Files\Microsoft AntiSpyware\Quarantine\E9E41733-FA91-46F4-AA48-377CBC\E77F5997-8F04-49F6-B477-4BD771 -> Adware.Comet : Cleaned with backup (quarantined).
C:\Program Files\Microsoft AntiSpyware\Quarantine\A7B997D6-9539-41ED-A258-E2CD95\003E110B-30FF-4381-8F8F-118FA2 -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Program Files\Microsoft AntiSpyware\Quarantine\A7B997D6-9539-41ED-A258-E2CD95\0A758478-F082-40B4-AD3E-C670B2 -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Program Files\Microsoft AntiSpyware\Quarantine\A7B997D6-9539-41ED-A258-E2CD95\1D3A7CBD-A404-4D7B-9759-ED4004 -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Program Files\Microsoft AntiSpyware\Quarantine\A7B997D6-9539-41ED-A258-E2CD95\2B76BA95-2272-4968-A2F8-D0FA59 -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Program Files\Microsoft AntiSpyware\Quarantine\A7B997D6-9539-41ED-A258-E2CD95\2DFB6DE1-865A-4A3A-8024-52E49F -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Program Files\Microsoft AntiSpyware\Quarantine\A7B997D6-9539-41ED-A258-E2CD95\338A4E38-0E8F-471B-8A3C-601D12 -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Program Files\Microsoft AntiSpyware\Quarantine\A7B997D6-9539-41ED-A258-E2CD95\3A2C26A6-A0AE-4FFF-9D95-233734 -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Program Files\Microsoft AntiSpyware\Quarantine\A7B997D6-9539-41ED-A258-E2CD95\44D77B16-D3CA-4863-9F24-8ADABB -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Program Files\Microsoft AntiSpyware\Quarantine\A7B997D6-9539-41ED-A258-E2CD95\475A8365-5B72-470A-96F7-F51D68 -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Program Files\Microsoft AntiSpyware\Quarantine\A7B997D6-9539-41ED-A258-E2CD95\4DD2CB2F-7063-4EC6-9FFF-D45A64 -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Program Files\Microsoft AntiSpyware\Quarantine\A7B997D6-9539-41ED-A258-E2CD95\5B2AB787-C938-4410-93CA-0B976C -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Program Files\Microsoft AntiSpyware\Quarantine\A7B997D6-9539-41ED-A258-E2CD95\66706411-4FB2-4526-A2BC-0F7FA5 -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Program Files\Microsoft AntiSpyware\Quarantine\A7B997D6-9539-41ED-A258-E2CD95\85E0C68E-F718-4000-877F-413A03 -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Program Files\Microsoft AntiSpyware\Quarantine\A7B997D6-9539-41ED-A258-E2CD95\97F05109-38FC-4D94-B6DD-0C3440 -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Program Files\Microsoft AntiSpyware\Quarantine\A7B997D6-9539-41ED-A258-E2CD95\98AFEFF7-326A-4F5C-9132-A3FDA8 -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Program Files\Microsoft AntiSpyware\Quarantine\A7B997D6-9539-41ED-A258-E2CD95\A85EBB6E-5B39-4A1F-BB59-3DB67E -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Program Files\Microsoft AntiSpyware\Quarantine\A7B997D6-9539-41ED-A258-E2CD95\A95916F5-40E3-426D-A3D5-1968F8 -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Program Files\Microsoft AntiSpyware\Quarantine\A7B997D6-9539-41ED-A258-E2CD95\AA12AA14-DF94-4946-899B-A88704 -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Program Files\Microsoft AntiSpyware\Quarantine\A7B997D6-9539-41ED-A258-E2CD95\AB91A4B7-DDDA-4039-B759-F14412 -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Program Files\Microsoft AntiSpyware\Quarantine\A7B997D6-9539-41ED-A258-E2CD95\ADBA97B6-E310-4063-8B35-3AFCA4 -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Program Files\Microsoft AntiSpyware\Quarantine\A7B997D6-9539-41ED-A258-E2CD95\AF6FAB8B-A285-4A42-8FAC-15FE55 -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Program Files\Microsoft AntiSpyware\Quarantine\A7B997D6-9539-41ED-A258-E2CD95\B66C4FEA-4790-4570-B26D-27D83B -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Program Files\Microsoft AntiSpyware\Quarantine\A7B997D6-9539-41ED-A258-E2CD95\F8CBEAFC-930E-4A5D-B83E-439336 -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Program Files\Microsoft AntiSpyware\Quarantine\E9E41733-FA91-46F4-AA48-377CBC\5F63E4C5-078E-4B89-8D5D-7568A0 -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Program Files\Microsoft AntiSpyware\Quarantine\E9E41733-FA91-46F4-AA48-377CBC\74A4F9C6-F5DE-451B-857B-DE45B1 -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\Contact.Contacts -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\Contact.Contacts\CLSID -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\Contact.Contacts\CurVer -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Program Files\Microsoft AntiSpyware\Quarantine\A7B997D6-9539-41ED-A258-E2CD95\5B06D6EB-1A0C-47C6-8151-34E841 -> Adware.Shopper : Cleaned with backup (quarantined).
C:\Program Files\Microsoft AntiSpyware\Quarantine\A7B997D6-9539-41ED-A258-E2CD95\C829D04D-2F05-471B-8A2B-70BBF9 -> Adware.Shopper : Cleaned with backup (quarantined).
C:\Program Files\Microsoft AntiSpyware\Quarantine\E9E41733-FA91-46F4-AA48-377CBC\5DDEFEF0-205A-42BF-885C-C4B766 -> Adware.Shopper : Cleaned with backup (quarantined).
C:\Documents and Settings\Jimmy\Cookies\jimmy@2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Jimmy\Cookies\jimmy@dbs.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Jimmy\Cookies\jimmy@premiumtv.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\alan\Cookies\alan@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Jimmy\Cookies\jimmy@adbrite[1].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\alan\Cookies\alan@3.adbrite[2].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\alan\Cookies\alan@adbrite[2].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\Jimmy\Cookies\jimmy@adtech[1].txt -> TrackingCookie.Adtech : Cleaned.
C:\Documents and Settings\alan\Cookies\alan@adtech[2].txt -> TrackingCookie.Adtech : Cleaned.
C:\Documents and Settings\Jimmy\Cookies\jimmy@advertising[1].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\alan\Cookies\alan@advertising[1].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\Jimmy\Cookies\jimmy@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\alan\Cookies\alan@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\chaileng\Cookies\chaileng@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\chaileng\Cookies\chaileng@bluemountain[2].txt -> TrackingCookie.Bluemountain : Cleaned.
C:\Documents and Settings\Jimmy\Cookies\jimmy@www.burstbeacon[2].txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\Jimmy\Cookies\jimmy@www.burstnet[1].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\alan\Cookies\alan@casalemedia[1].txt -> TrackingCookie.Casalemedia : Cleaned.
C:\Documents and Settings\Jimmy\Cookies\jimmy@connextra[5].txt -> TrackingCookie.Connextra : Cleaned.
C:\Documents and Settings\alan\Cookies\alan@connextra[1].txt -> TrackingCookie.Connextra : Cleaned.
C:\Documents and Settings\Jimmy\Cookies\jimmy@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\alan\Cookies\alan@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Jimmy\Cookies\jimmy@fastclick[2].txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\alan\Cookies\alan@fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\alan\Cookies\alan@media.fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\alan\Cookies\alan@ehg-dig.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\alan\Cookies\alan@ehg-vintedge.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\alan\Cookies\alan@hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Jimmy\Cookies\jimmy@searchportal.information[1].txt -> TrackingCookie.Information : Cleaned.
C:\Documents and Settings\Jimmy\Cookies\jimmy@sales.liveperson[2].txt -> TrackingCookie.Liveperson : Cleaned.
C:\Documents and Settings\alan\Cookies\alan@server.iad.liveperson[2].txt -> TrackingCookie.Liveperson : Cleaned.
C:\Documents and Settings\alan\Cookies\alan@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\Jimmy\Cookies\jimmy@stat.onestat[2].txt -> TrackingCookie.Onestat : Cleaned.
C:\Documents and Settings\alan\Cookies\alan@overture[1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Jimmy\Cookies\jimmy@questionmarket[2].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\alan\Cookies\alan@questionmarket[2].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\Jimmy\Cookies\jimmy@revenue[2].txt -> TrackingCookie.Revenue : Cleaned.
C:\Documents and Settings\Jimmy\Cookies\jimmy@revsci[1].txt -> TrackingCookie.Revsci : Cleaned.
C:\Documents and Settings\Jimmy\Cookies\jimmy@bs.serving-sys[2].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\Jimmy\Cookies\jimmy@serving-sys[2].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\alan\Cookies\alan@bs.serving-sys[2].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\alan\Cookies\alan@serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\Jimmy\Cookies\jimmy@statcounter[1].txt -> TrackingCookie.Statcounter : Cleaned.
C:\Documents and Settings\alan\Cookies\alan@statcounter[2].txt -> TrackingCookie.Statcounter : Cleaned.
C:\Documents and Settings\Jimmy\Cookies\jimmy@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : Cleaned.
C:\Documents and Settings\Jimmy\Cookies\jimmy@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Documents and Settings\alan\Cookies\alan@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Documents and Settings\Jimmy\Cookies\jimmy@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\alan\Cookies\alan@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned.
::Report end
Thanks and Regards,
Jimmy