Here's the ComboFix log. I was unable to totally disable Virgin PC Guard, but I turned off all of its protection options individually.
My PC seems to be running normally now. Do you think it's fixed?
ComboFix 10-05-10.02 - Andy 11/05/2010 3:36.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.2046.880 [GMT 1:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: PCguard Anti-Virus *On-access scanning enabled* (Updated) {5B5A3BD7-8573-4672-AEA8-C9BB713B6755}
FW: PCguard Firewall *enabled* {80593BF4-D969-4EC5-ADAE-A22F2DFC7A22}
SP: PCguard Anti-Spyware *enabled* (Updated) {307352C6-1CBD-11DB-8AF6-B622A1EF5492}
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\programdata\hpe5032.dll
c:\windows\system32\system
c:\windows\winhelp.ini
.
((((((((((((((((((((((((( Files Created from 2010-04-11 to 2010-05-11 )))))))))))))))))))))))))))))))
.
2010-05-11 02:49 . 2010-05-11 02:53 ——– d—–w- c:\users\Andy\AppData\Local\temp
2010-05-11 02:49 . 2010-05-11 02:49 ——– d—–w- c:\users\Erica.Andy-PC\AppData\Local\temp
2010-05-11 02:49 . 2010-05-11 02:49 ——– d—–w- c:\users\Default\AppData\Local\temp
2010-05-11 01:57 . 2010-05-11 01:57 ——– d—–w- c:\program files\ERUNT
2010-05-11 01:22 . 2010-05-11 01:22 ——– d—–w- c:\users\Andy\AppData\Roaming\Malwarebytes
2010-05-11 01:22 . 2010-04-29 14:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-05-11 01:22 . 2010-05-11 01:22 ——– d—–w- c:\programdata\Malwarebytes
2010-05-11 01:22 . 2010-05-11 01:22 ——– d—–w- c:\program files\MALWAREBYTES ANTI-MALWARE
2010-05-11 01:22 . 2010-05-11 01:42 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-05-11 01:22 . 2010-04-29 14:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-05-10 11:58 . 2010-05-10 11:58 ——– d—–w- c:\program files\Enigma Software Group
2010-05-10 11:56 . 2010-05-10 15:19 ——– d—–w- c:\windows\61D3AAE1D5214CD7939B37813DE8F955.TMP
2010-05-10 03:59 . 2010-05-10 10:45 120 —-a-w- c:\users\Andy\AppData\Local\Vjubanahifureqi.dat
2010-05-10 03:59 . 2010-05-10 03:59 0 —-a-w- c:\users\Andy\AppData\Local\Wsopaxacodene.bin
2010-05-10 03:59 . 2010-05-10 03:59 ——– d—–w- c:\users\Andy\AppData\Local\{D4246A22-534D-4C71-B6CC-E94525464D8B}
2010-04-14 08:55 . 2010-02-23 11:10 79360 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys
2010-04-14 08:55 . 2010-02-23 11:10 212992 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-04-14 08:55 . 2010-02-23 11:10 106496 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-04-14 08:54 . 2010-02-18 14:07 3600776 —-a-w- c:\windows\system32\ntkrnlpa.exe
2010-04-14 08:54 . 2010-02-18 14:07 3548040 —-a-w- c:\windows\system32\ntoskrnl.exe
2010-04-14 08:54 . 2010-03-04 17:33 430080 —-a-w- c:\windows\system32\vbscript.dll
2010-04-14 08:54 . 2010-02-18 14:07 904576 —-a-w- c:\windows\system32\drivers\tcpip.sys
2010-04-14 08:54 . 2010-02-18 13:30 200704 —-a-w- c:\windows\system32\iphlpsvc.dll
2010-04-14 08:54 . 2010-02-18 11:28 25088 —-a-w- c:\windows\system32\drivers\tunnel.sys
2010-04-14 08:54 . 2009-12-23 11:33 172032 —-a-w- c:\windows\system32\wintrust.dll
2010-04-14 08:53 . 2010-01-13 17:34 98304 —-a-w- c:\windows\system32\cabview.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-11 02:53 . 2009-10-06 00:27 90189600 –sha-w- c:\windows\system32\drivers\fidbox.dat
2010-05-11 02:04 . 2007-07-27 10:12 ——– d—–w- c:\programdata\NVIDIA
2010-05-11 02:02 . 2009-10-06 00:27 1208132 –sha-w- c:\windows\system32\drivers\fidbox.idx
2010-05-10 12:05 . 2010-02-06 05:41 ——– d—–w- c:\users\Andy\AppData\Roaming\GetRightToGo
2010-05-10 11:56 . 2009-09-03 10:19 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2010-05-10 03:58 . 2010-05-10 03:57 20 —-a-w- c:\users\Andy\AppData\Roaming\qvjsge.dat
2010-05-07 21:57 . 2010-03-26 23:05 ——– d—–w- c:\users\Andy\AppData\Roaming\vlc
2010-05-06 09:36 . 2009-10-02 17:24 221568 ——w- c:\windows\system32\MpSigStub.exe
2010-04-15 04:09 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2010-04-15 03:00 . 2009-12-20 16:12 ——– d—–w- c:\programdata\Microsoft Help
2010-04-09 17:44 . 2010-04-09 17:24 ——– d—–w- c:\users\Andy\AppData\Roaming\Spotify
2010-04-09 17:24 . 2010-04-09 17:24 ——– d—–w- c:\program files\Spotify
2010-04-09 14:24 . 2009-04-13 00:05 ——– d—–w- c:\program files\HMRC
2010-03-09 16:25 . 2010-03-31 18:07 78336 —-a-w- c:\windows\system32\ieencode.dll
2010-03-09 15:42 . 2010-03-31 18:07 834048 —-a-w- c:\windows\system32\wininet.dll
2010-02-25 04:21 . 2007-07-17 17:59 79304 —-a-w- c:\users\Andy\AppData\Local\GDIPFONTCACHEV1.DAT
2010-02-24 19:26 . 2009-08-13 03:04 38784 —-a-w- c:\users\Default\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-02-24 19:26 . 2009-06-12 18:40 38784 —-a-w- c:\users\Andy\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-02-23 14:15 . 2010-02-23 14:15 16 —-a-w- c:\windows\popcinfo.dat
2010-02-20 23:06 . 2010-03-11 03:01 24064 —-a-w- c:\windows\system32\nshhttp.dll
2010-02-20 23:05 . 2010-03-11 03:01 30720 —-a-w- c:\windows\system32\httpapi.dll
2010-02-20 20:53 . 2010-03-11 03:01 411648 —-a-w- c:\windows\system32\drivers\http.sys
2010-02-16 08:24 . 2007-07-17 17:59 680 —-a-w- c:\users\Andy\AppData\Local\d3d9caps.dat
2010-02-12 10:32 . 2010-03-20 03:00 293376 —-a-w- c:\windows\system32\browserchoice.exe
2002-04-16 10:27 . 2002-04-16 10:27 5 –sha-w- c:\windows\System32\CdI5T.drv
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" [2009-09-24 434176]
"Google Update"="c:\users\Andy\AppData\Local\Google\Update\GoogleUpdate.exe" [2010-02-07 135664]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"WorksFUD"="c:\program files\Microsoft Works\wkfud.exe" [2001-08-24 24576]
"Microsoft Works Portfolio"="c:\program files\Microsoft Works\WksSb.exe" [2001-08-23 331830]
"Microsoft Works Update Detection"="c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2001-08-17 28738]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"SPIRunE"="SPIRunE.dll" [2009-03-05 18432]
"Broadbandadvisor.exe"="c:\program files\Virgin Broadband\advisor\Broadbandadvisor.exe" [2009-05-27 2303216]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2008-01-10 92704]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-01-10 8530464]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-01-10 88608]
"Nikon Transfer Monitor"="c:\program files\Common Files\Nikon\Monitor\NkMonitor.exe" [2009-09-15 479232]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-04-29 1090952]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Microsoft Works Calendar Reminders.lnk - c:\program files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe [2001-8-8 24633]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 14:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ PDBoot.exe\0autocheck autochk *
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(

:fd,aa,04,92,8c,f3,c9,01
R2 OMSI download service;Sony Ericsson OMSI download service;c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [2009-04-30 90112]
R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2009-06-18 79360]
R3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys [2009-10-25 13224]
R3 HSFHWCD2;HSFHWCD2;c:\windows\system32\DRIVERS\HSFHWCD2.sys [x]
R3 HSXHWCD2;HSXHWCD2;c:\windows\system32\DRIVERS\HSXHWCD2.sys [x]
R3 PD91Engine;PD91Engine;c:\program files\Raxco\PerfectDisk2008\PD91Engine.exe [2008-09-22 910600]
R3 Radialpoint Security Services;Virgin Broadband PCguard;c:\program files\Virgin Broadband\PCguard\RpsSecurityAwareR.exe [2009-10-06 175184]
R3 s0017bus;Sony Ericsson Device 0017 driver (WDM);c:\windows\system32\DRIVERS\s0017bus.sys [2008-05-27 90536]
R3 s0017mdfl;Sony Ericsson Device 0017 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s0017mdfl.sys [2008-05-27 15016]
R3 s0017mdm;Sony Ericsson Device 0017 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s0017mdm.sys [2008-05-27 122152]
R3 s0017mgmt;Sony Ericsson Device 0017 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s0017mgmt.sys [2008-05-27 115496]
R3 s0017nd5;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (NDIS);c:\windows\system32\DRIVERS\s0017nd5.sys [2008-05-27 25768]
R3 s0017obex;Sony Ericsson Device 0017 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s0017obex.sys [2008-05-27 111912]
R3 s0017unic;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (WDM);c:\windows\system32\DRIVERS\s0017unic.sys [2008-05-27 117672]
R3 s115mdfl;Sony Ericsson Device 115 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s115mdfl.sys [2007-04-23 15112]
R3 s115mdm;Sony Ericsson Device 115 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s115mdm.sys [2007-04-23 108680]
R3 s115mgmt;Sony Ericsson Device 115 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s115mgmt.sys [2007-04-23 100488]
R3 s115obex;Sony Ericsson Device 115 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s115obex.sys [2007-04-23 98568]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-09-15 7408]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2009-09-15 9968]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2009-09-15 74480]
S2 PD91Agent;PD91Agent;c:\program files\Raxco\PerfectDisk2008\PD91Agent.exe [2008-09-22 693512]
S2 RadialpointSafeConnectAgent;Virgin Broadband PCguard SafeConnectAgent;c:\program files\Virgin Broadband\PCguard\SafeConnect\Bin\SanaAgent.exe RadialpointSafeConnectAgent [x]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2009-08-17 239648]
S3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller;c:\windows\system32\DRIVERS\l160x86.sys [2009-04-27 47104]
S3 RadialpointSafeConnectDriver;RadialpointSafeConnectDriver;c:\program files\Virgin Broadband\PCguard\SafeConnect\Driver\platform_VISTA\SafeConnectDriver.sys [2008-11-14 161304]
S3 RadialpointSafeConnectFilter;RadialpointSafeConnectFilter;c:\program files\Virgin Broadband\PCguard\SafeConnect\Driver\platform_VISTA\SafeConnectFilter.sys [2008-11-14 29720]
S3 RadialpointSafeConnectShim;RadialpointSafeConnectShim;c:\program files\Virgin Broadband\PCguard\SafeConnect\Driver\platform_VISTA\SafeConnectShim.sys [2008-11-14 29248]
S3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\DRIVERS\seehcri.sys [2008-01-09 27632]
S3 t3;Sound Blaster X-Fi Xtreme Audio;c:\windows\system32\drivers\t3.sys [2009-05-06 413208]
S3 TotRec7;Total Recorder WDM audio driver;c:\windows\system32\drivers\TotRec7.sys [2008-11-18 126984]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
2010-05-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3273408307-3295208567-3124459625-1000Core.job
- c:\users\Andy\AppData\Local\Google\Update\GoogleUpdate.exe [2010-02-07 23:01]
2010-05-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3273408307-3295208567-3124459625-1000UA.job
- c:\users\Andy\AppData\Local\Google\Update\GoogleUpdate.exe [2010-02-07 23:01]
2010-05-11 c:\windows\Tasks\User_Feed_Synchronization-{CE5DE530-D1DA-40BB-B585-A2C5297CCE8E}.job
- c:\windows\system32\msfeedssync.exe [2008-06-09 07:33]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.co.uk/
uInternet Settings,ProxyServer = http=localhost:59812
uInternet Settings,ProxyOverride = *.local
IE: &Download; All with FlashGet - c:\users\Andy\Program files\FlashGet\jc_all.htm
IE: &Download; with FlashGet - c:\users\Andy\Program files\FlashGet\jc_link.htm
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
DPF: {8FD07749-EFFA-48C6-947C-45A8D7BF422F} - hxxp://www.cyberlink.com/vista/prog/CLVistaGenie.cab
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-updateMgr - c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
HKCU-Run-DriverUpdaterPro - c:\program files\iXi Tools\Driver Updater Pro\DriverUpdaterPro.exe
HKCU-Run-Microsoft Works Update Detection - c:\program files\Microsoft Works\WkDetect.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-05-11 03:53
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\S-1-5-21-3273408307-3295208567-3124459625-1000\Software\SecuROM\License information*]
"datasecu"=hex:28,ee,67,4c,15,a6,2a,9d,85,f1,2d,13,ff,55,84,61,36,82,6f,f1,1d,
9b,5f,72,6b,f4,3e,ad,1b,f9,cb,86,30,16,aa,4d,cd,c5,17,ba,4a,c2,58,69,17,ca,\
"rkeysecu"=hex:cb,bd,f2,61,5a,4e,c6,95,f2,29,8b,82,ba,6b,3d,44
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b4
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2010-05-11 03:57:21
ComboFix-quarantined-files.txt 2010-05-11 02:57
Pre-Run: 333,092,827,136 bytes free
Post-Run: 332,137,639,936 bytes free
- - End Of File - - 0292F00E80A823E05F2DECD7418922EE