Thank you OCD for your fast response.
1. I have uninstalled AVG8 for now. I am using ClamWin. After all of this is done I am going to look for a new Anti-Virus program.
2. Here is the ComboFix log:
ComboFix 09-05-15.01 - Owner 05/15/2009 16:42.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1790.1152 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt
FW: ZoneAlarm Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
* Created a new restore point
FILE ::
c:\documents and settings\user\Start Menu\Programs\Startup\PowerReg Scheduler.exe
c:\windows\system32\9EF64877CE.dll
c:\windows\system32\drivers\fsbts.sys
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\Owner\LOCALS~1\Temp\764ACEBF.nbp
c:\docume~1\Owner\LOCALS~1\Temp\764ACEC0.nbp
c:\documents and settings\Owner\Local Settings\temp\764ACEBF.nbp
c:\documents and settings\Owner\Local Settings\temp\764ACEC0.nbp
c:\windows\system32\9EF64877CE.dll
c:\windows\system32\drivers\fsbts.sys
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_FSBTS
——-\Service_fsbts
((((((((((((((((((((((((( Files Created from 2009-04-15 to 2009-05-15 )))))))))))))))))))))))))))))))
.
2009-05-15 20:38 . 2009-05-15 20:38 ——– d—–w C:\Combo-Fix
2009-05-12 02:57 . 2009-05-12 03:00 ——– d—–w c:\program files\Executive Software
2009-05-11 01:46 . 2009-05-11 01:46 ——– d—–w c:\program files\ERUNT
2009-05-10 06:13 . 2001-04-05 21:21 29272 —-a-w c:\windows\system32\OOD2KBS.exe
2009-05-10 06:13 . 2000-11-01 18:12 16384 —-a-w c:\windows\system32\ood2kmsg.dll
2009-05-10 06:13 . 2001-04-06 17:57 238080 —-a-w c:\windows\system32\OOD2000.exe
2009-05-10 06:13 . 2001-04-05 21:40 598016 —-a-w c:\windows\system32\OOD2KCRS.dll
2009-05-10 06:13 . 2000-11-09 23:31 24576 —-a-w c:\windows\system32\OODCSPRO.dll
2009-05-10 06:13 . 2009-05-10 06:13 ——– d—–w c:\program files\OOD2KFRE
2009-05-09 02:09 . 2009-05-11 00:51 ——– d—–w c:\program files\Advanced Spyware Remover
2009-05-08 23:11 . 2009-05-08 23:11 18680 —-a-w c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-08 22:59 . 2009-05-09 00:40 ——– d—–w c:\documents and settings\Administrator\Application Data\.clamwin
2009-05-08 22:58 . 2009-05-08 22:58 664 —-a-w c:\windows\system32\d3d9caps.dat
2009-05-08 18:22 . 2009-05-08 18:22 ——– d—–w c:\documents and settings\Owner\Application Data\.clamwin
2009-05-08 18:21 . 2009-05-08 18:21 ——– d—–w c:\program files\ClamWin
2009-05-08 18:21 . 2009-05-08 18:21 ——– d—–w c:\documents and settings\All Users\.clamwin
2009-05-08 18:15 . 2009-05-09 00:14 ——– d—–w c:\documents and settings\Owner\Application Data\QuickScan
2009-05-07 15:41 . 2009-05-07 15:41 ——– d—–w c:\program files\HDQuality
2009-05-06 15:46 . 2009-05-06 15:46 ——– d—–w c:\windows\Cache
2009-05-06 15:46 . 2009-05-06 16:07 ——– d—–w c:\program files\Coupons
2009-04-28 06:05 . 2009-04-28 06:05 ——– d—–w c:\program files\Cablenut
2009-04-28 05:43 . 2009-04-28 05:43 ——– d—–w c:\documents and settings\Owner\Application Data\wsInspector
2009-04-28 05:37 . 2009-04-28 06:12 ——– d—–w c:\program files\Startup Inspector for Windows
2009-04-27 05:58 . 2009-05-09 03:37 ——– d—–w c:\program files\Defraggler
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-15 20:46 . 2008-07-25 06:34 ——– d—–w c:\program files\SpeedBit Video Accelerator
2009-05-10 06:13 . 2008-07-25 15:41 ——– d–h–w c:\program files\InstallShield Installation Information
2009-04-28 05:45 . 2008-08-23 03:34 ——– d—–w c:\program files\Microsoft Silverlight
2009-04-27 22:12 . 2009-02-17 00:08 15688 —-a-w c:\windows\system32\lsdelete.exe
2009-04-27 22:12 . 2009-02-16 23:12 64160 —-a-w c:\windows\system32\drivers\Lbd.sys
2009-04-15 12:18 . 2008-07-25 15:41 ——– d—–w c:\program files\Crystalize
2009-04-09 15:37 . 2008-11-07 23:24 ——– d—–w c:\program files\LimeWire
2009-04-08 21:30 . 2008-09-04 02:43 ——– d—–w c:\program files\ZipItFree
2009-04-08 15:45 . 2008-07-25 14:53 ——– d—–w c:\program files\Spybot - Search & Destroy
2009-04-01 14:51 . 2009-04-01 14:51 410984 —-a-w c:\windows\system32\deploytk.dll
2009-04-01 14:51 . 2008-07-25 18:00 ——– d—–w c:\program files\Java
2009-04-01 14:41 . 2009-04-01 14:41 ——– d—–w c:\program files\Secunia
2009-04-01 05:39 . 2009-04-01 05:39 4212 —ha-w c:\windows\system32\zllictbl.dat
2009-04-01 05:38 . 2009-04-01 05:38 ——– d—–w c:\program files\Zone Labs
2009-04-01 05:24 . 2009-04-01 05:22 ——– d—–w c:\program files\TmNationsForever
2009-04-01 05:10 . 2008-08-12 05:45 ——– d—–w c:\program files\Google
2009-03-30 00:55 . 2008-07-25 06:34 ——– d—–w c:\program files\DAP
2009-03-29 01:32 . 2008-07-31 06:21 18680 —-a-w c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-03-29 01:16 . 2009-03-26 19:06 ——– d—–w c:\program files\Yahoo!
2009-03-24 11:03 . 2009-03-24 11:03 7808 —-a-w c:\windows\system32\drivers\psi_mf.sys
2009-03-17 18:04 . 2008-07-25 06:32 ——– d—–w c:\program files\Common Files\Adobe
2009-03-06 14:22 . 2006-02-28 12:00 284160 —-a-w c:\windows\system32\pdh.dll
2009-03-03 00:18 . 2006-02-28 12:00 826368 —-a-w c:\windows\system32\wininet.dll
2009-02-20 18:09 . 2006-02-28 12:00 78336 —-a-w c:\windows\system32\ieencode.dll
2009-02-16 04:10 . 2009-04-01 05:38 1221512 —-a-w c:\windows\system32\zpeng25.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-05-13_19.30.18 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-05-15 20:46 . 2009-05-15 20:46 16384 c:\windows\Temp\Perflib_Perfdata_204.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FF6C3CF0-4B15-11D1-ABED-709549C10000}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-12-23 143360]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"Vidalia"="c:\program files\Vidalia Bundle\Vidalia\vidalia.exe" [2007-08-26 11852288]
"DownloadAccelerator"="c:\program files\DAP\DAP.EXE" [2009-03-30 2811392]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpeedBitVideoAccelerator"="c:\program files\SpeedBit Video Accelerator\VideoAccelerator.exe" [2008-09-16 2705008]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-15 49152]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-04-27 516440]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2009-02-16 981384]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-01 148888]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"ClamWin"="c:\program files\ClamWin\bin\ClamTray.exe" [2009-04-14 86016]
"VTTimer"="VTTimer.exe" - c:\windows\system32\VTTimer.exe [2006-09-21 53248]
"S3Trayp"="S3trayp.exe" - c:\windows\system32\S3Trayp.exe [2007-09-30 200704]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\soundman.exe [2006-11-17 577536]
c:\documents and settings\Owner\Start Menu\Programs\Startup\
Instant Memory Cleaner.lnk - c:\program files\Vasilios Applications\Instant Memory Cleaner\Instant Memory Cleaner.exe [2008-7-25 1373409]
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2008-12-15 384000]
PowerReg Scheduler.exe [2008-7-25 256000]
Secunia PSI.lnk - c:\program files\Secunia\PSI\psi.exe [2009-3-24 748840]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
Privoxy.lnk - c:\program files\Vidalia Bundle\Privoxy\privoxy.exe [2006-11-20 250368]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-27 304128]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ lsdelete\
0autocheck autochk /k:C *
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\DAP\\DAP.exe"=
"c:\\Program Files\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"=
"c:\\Program Files\\Cartoon Network\\Ben 10 Bounty Hunters\\RT_Multiplayer.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\SpeedBit Video Accelerator\\VideoAccelerator.exe"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2/16/2009 7:12 PM 64160]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [1/18/2009 5:34 PM 953168]
R2 sbbotdi;sbbotdi;c:\progra~1\SPEEDB~1\sbbotdi.sys [7/25/2008 2:34 AM 35584]
R2 VideoAcceleratorService;VideoAcceleratorService;c:\progra~1\SPEEDB~1\VideoAcceleratorService.exe -start -scm –> c:\progra~1\SPEEDB~1\VideoAcceleratorService.exe -start -scm [?]
R3 S3GIGP;S3GIGP;c:\windows\system32\drivers\S3gIGPm.sys [6/23/2006 2:23 AM 603648]
S2 gupdate1c9859fab90042a;Google Update Service (gupdate1c9859fab90042a);c:\program files\Google\Update\GoogleUpdate.exe [2/2/2009 9:35 PM 133104]
S3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [3/24/2009 7:03 AM 7808]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{aa0ff379-cd9a-11dd-a9ac-0015586d5dac}]
\Shell\AutoRun\command - F:\podcastready.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{aa0ff37a-cd9a-11dd-a9ac-0015586d5dac}]
\Shell\AutoRun\command - E:\podcastready.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{aa0ff56c-cd9a-11dd-a9ac-0015586d5dac}]
\Shell\AutoRun\command - E:\podcastready.exe
.
Contents of the 'Scheduled Tasks' folder
2009-05-11 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 22:12]
2009-05-14 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
2009-05-11 c:\windows\Tasks\Defraggler Volume C Task.job
- c:\program files\Defraggler\df.exe [2009-03-13 13:37]
2009-05-15 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-08-12 23:36]
2009-05-15 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-03 01:35]
2009-03-27 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SpybotSD.exe [2009-04-08 19:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.lego.com/en-US/default.aspx
IE: &Clean Traces - c:\program files\DAP\Privacy Package\dapcleanerie.htm
IE: &Download with &DAP - c:\program files\DAP\dapextie.htm
IE: Download &all with DAP - c:\program files\DAP\dapextie2.htm
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\u45cbglo.default\
FF - component: c:\program files\DAP\DAPFireFox\components\DAPFireFox.dll
FF - plugin: c:\program files\Google\Google Earth Plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.145.5\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\Unity\WebPlayer\loader\npUnity3D32.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-05-15 16:47
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'explorer.exe'(3948)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ZoneLabs\vsmon.exe
c:\windows\system32\agrsmsvc.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\progra~1\SPEEDB~1\VideoAcceleratorService.exe
c:\windows\system32\searchindexer.exe
c:\windows\system32\wscntfy.exe
c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
c:\program files\OpenOffice.org 3\program\soffice.exe
c:\program files\OpenOffice.org 3\program\soffice.bin
c:\program files\Vidalia Bundle\Tor\tor.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Common Files\Ahead\Lib\NMIndexingService.exe
c:\progra~1\SPEEDB~1\VideoAcceleratorEngine.exe
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
c:\program files\HP\Digital Imaging\bin\hpqbam08.exe
c:\program files\HP\Digital Imaging\bin\hpqgpc01.exe
.
**************************************************************************
.
Completion time: 2009-05-15 16:50 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-15 20:50
ComboFix2.txt 2009-05-13 19:31
Pre-Run: 24,573,214,720 bytes free
Post-Run: 24,480,501,760 bytes free
229 — E O F — 2009-04-15 05:07
3. Here is the DDS.txt log
DDS (Ver_09-05-14.01) - NTFSx86
Run by [removed] at 17:05:56.82 on Fri 05/15/2009
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1790.1214 [GMT -4:00]
FW: ZoneAlarm Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\agrsmsvc.exe
C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\SpeedBit Video Accelerator\VideoAccelerator.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\system32\S3trayp.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Vidalia Bundle\Vidalia\vidalia.exe
C:\Program Files\DAP\DAP.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\Program Files\Vidalia Bundle\Privoxy\privoxy.exe
C:\Program Files\Vasilios Applications\Instant Memory Cleaner\Instant Memory Cleaner.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\PROGRA~1\SPEEDB~1\VideoAcceleratorService.exe
C:\Program Files\Secunia\PSI\psi.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Vidalia Bundle\Tor\tor.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\PROGRA~1\SPEEDB~1\VideoAcceleratorEngine.exe
C:\Documents and Settings\Owner\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.lego.com/en-US/default.aspx
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: DAPIELoader Class: {ff6c3cf0-4b15-11d1-abed-709549c10000} - c:\progra~1\dap\DAPIEL~1.DLL
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
uRun: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\ahead\lib\NMBgMonitor.exe"
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Vidalia] "c:\program files\vidalia bundle\vidalia\vidalia.exe"
uRun: [DownloadAccelerator] "c:\program files\dap\DAP.EXE" /STARTUP
mRun: [SpeedBitVideoAccelerator] "c:\program files\speedbit video accelerator\VideoAccelerator.exe"
mRun: [VTTimer] VTTimer.exe
mRun: [S3Trayp] S3trayp.exe
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe
mRun: [Ad-Watch] c:\program files\lavasoft\ad-aware\AAWTray.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [ZoneAlarm Client] "c:\program files\zone labs\zonealarm\zlclient.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [ClamWin] "c:\program files\clamwin\bin\ClamTray.exe" –logon
StartupFolder: c:\docume~1\owner\startm~1\programs\startup\instan~1.lnk - c:\program files\vasilios applications\instant memory cleaner\Instant Memory Cleaner.exe
StartupFolder: c:\docume~1\owner\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe
StartupFolder: c:\documents and settings\owner\start menu\programs\startup\PowerReg Scheduler.exe
StartupFolder: c:\docume~1\owner\startm~1\programs\startup\secuni~1.lnk - c:\program files\secunia\psi\psi.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\privoxy.lnk - c:\program files\vidalia bundle\privoxy\privoxy.exe
IE: &Clean Traces - c:\program files\dap\privacy package\dapcleanerie.htm
IE: &Download with &DAP - c:\program files\dap\dapextie.htm
IE: Download &all with DAP - c:\program files\dap\dapextie2.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://pcpitstop.com/betapit/PCPitStop.CAB
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1216966337453
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E001C731-5E37-4538-A5CB-8168736A2360} - hxxp://quickscan.bitdefender.com/cab/ActiveQscan.cab
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\owner\applic~1\mozilla\firefox\profiles\u45cbglo.default\
FF - component: c:\program files\dap\dapfirefox\components\DAPFireFox.dll
FF - plugin: c:\program files\google\google earth plugin\npgeplugin.dll
FF - plugin: c:\program files\google\google updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\google\update\1.2.145.5\npGoogleOneClick8.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\unity\webplayer\loader\npUnity3D32.dll
============= SERVICES / DRIVERS ===============
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-2-16 64160]
R1 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2009-4-1 353672]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-1-18 953168]
R2 sbbotdi;sbbotdi;c:\progra~1\speedb~1\sbbotdi.sys [2008-7-25 35584]
R2 VideoAcceleratorService;VideoAcceleratorService;c:\progra~1\speedb~1\videoacceleratorservice.exe -start -scm –> c:\progra~1\speedb~1\VideoAcceleratorService.exe -start -scm [?]
R3 S3GIGP;S3GIGP;c:\windows\system32\drivers\S3gIGPm.sys [2006-6-23 603648]
S2 gupdate1c9859fab90042a;Google Update Service (gupdate1c9859fab90042a);c:\program files\google\update\GoogleUpdate.exe [2009-2-2 133104]
S2 vsmon;TrueVector Internet Monitor;c:\windows\system32\zonelabs\vsmon.exe -service –> c:\windows\system32\zonelabs\vsmon.exe -service [?]
S3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [2009-3-24 7808]
=============== Created Last 30 ================
2009-05-15 16:38 –d—– C:\Combo-Fix
2009-05-13 15:20 a-dshr– C:\cmdcons
2009-05-13 15:19 161,792 a——- c:\windows\SWREG.exe
2009-05-13 15:19 98,816 a——- c:\windows\sed.exe
2009-05-11 22:57 –d—– c:\program files\Executive Software
2009-05-10 02:13 598,016 a——- c:\windows\system32\OOD2KCRS.dll
2009-05-10 02:13 238,080 a——- c:\windows\system32\OOD2000.exe
2009-05-10 02:13 29,272 a——- c:\windows\system32\OOD2KBS.exe
2009-05-10 02:13 24,576 a——- c:\windows\system32\OODCSPRO.dll
2009-05-10 02:13 16,384 a——- c:\windows\system32\ood2kmsg.dll
2009-05-10 02:13 –d—– c:\program files\OOD2KFRE
2009-05-08 22:09 –d—– c:\program files\Advanced Spyware Remover
2009-05-08 18:58 664 a——- c:\windows\system32\d3d9caps.dat
2009-05-08 14:22 –d—– c:\docume~1\owner\applic~1\.clamwin
2009-05-08 14:21 –d—– c:\program files\ClamWin
2009-05-08 14:21 –d—– c:\documents and settings\all users\.clamwin
2009-05-08 14:15 –d—– c:\docume~1\owner\applic~1\QuickScan
2009-05-07 11:41 –d—– c:\program files\HDQuality
2009-05-06 11:47 202,072 a—-r– c:\windows\system32\cpnprt2.cid
2009-05-06 11:46 –d—– c:\windows\Cache
2009-05-06 11:46 –d—– c:\program files\Coupons
2009-04-28 02:05 –d—– c:\program files\Cablenut
2009-04-28 01:43 –d—– c:\docume~1\owner\applic~1\wsInspector
2009-04-28 01:37 –d—– c:\program files\Startup Inspector for Windows
2009-04-27 01:58 –d—– c:\program files\Defraggler
==================== Find3M ====================
2009-04-27 18:12 15,688 a——- c:\windows\system32\lsdelete.exe
2009-04-27 18:12 64,160 a——- c:\windows\system32\drivers\Lbd.sys
2009-04-01 10:51 410,984 a——- c:\windows\system32\deploytk.dll
2009-04-01 01:39 4,212 a—h— c:\windows\system32\zllictbl.dat
2009-03-24 07:03 7,808 a——- c:\windows\system32\drivers\psi_mf.sys
2009-03-06 10:22 284,160 a——- c:\windows\system32\pdh.dll
2009-03-02 20:18 826,368 a——- c:\windows\system32\wininet.dll
2009-02-20 14:09 78,336 a——- c:\windows\system32\ieencode.dll
2009-02-16 00:10 1,221,512 a——- c:\windows\system32\zpeng25.dll
2009-02-05 16:29 34 ac—— c:\documents and settings\owner\jagex_runescape_preferences.dat
2008-10-12 11:46 14,566,424 ac—— c:\docume~1\alluse~1\applic~1\vlc-0.9.4-win32.exe
============= FINISH: 17:06:27.39 ===============
4. I have attached the
Attach.txt.
5. My computer is running better. I am able to do all of my updates. I haven't done any of the important updates, like windows or my anti-virus yet. I am waiting on your blessing to do that. I wasn't sure if it doing any of that would interfer with any thing that you ask me to do.
I do still have one concern, is my ISP still showing as being in the Ukraine?