Hi - We're back and no bonefishin but had a great time - now to deal with this pesky computer issue!
So far I have the AVG report and another HJT log:
———————————————————
AVG Anti-Spyware - Scan Report
———————————————————
+ Created at: 7:13:41 AM 11/22/2006
+ Scan result:
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP247\A0054854.EXE -> Adware.Background : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP250\A0058199.dll -> Adware.Comet : Cleaned with backup (quarantined).
C:\RecoveryBin\Volume-525d1f8b-70ea-11da-94b0-806d6172696f\WINDOWS\system32\dmanu(01C6FF180FD50009).exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\RecoveryBin\Volume-525d1f8b-70ea-11da-94b0-806d6172696f\WINDOWS\system32\dmmrh(01C6FF7D31570005).exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\RecoveryBin\Volume-525d1f8b-70ea-11da-94b0-806d6172696f\WINDOWS\system32\dmncq(01C7017180EE0006).exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\RecoveryBin\Volume-525d1f8b-70ea-11da-94b0-806d6172696f\WINDOWS\system32\dmzbq(01C70276A164000B).exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP228\A0051679.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP228\A0051686.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP229\A0051693.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP229\A0051698.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP229\A0051703.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP229\A0051707.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP229\A0051713.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP229\A0051720.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP229\A0051724.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP229\A0051733.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP229\A0051737.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP229\A0051741.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP229\A0051748.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP229\A0051755.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP229\A0051780.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP229\A0051825.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP229\A0051826.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP229\A0051827.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP229\A0051828.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP229\A0051829.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP229\A0051830.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP229\A0051831.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP229\A0051832.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP229\A0051835.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP229\A0051836.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP230\A0051858.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP230\A0051862.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP230\A0051869.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP231\A0052869.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP231\A0052874.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP231\A0053874.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP231\A0053878.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP232\A0053905.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP232\A0053909.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP232\A0053988.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP232\A0053989.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP232\A0053990.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP232\A0053991.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP232\A0053992.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP233\A0054155.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP233\A0054159.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP233\A0054163.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP233\A0054167.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP233\A0054171.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP233\A0054175.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP234\A0054186.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP234\A0054193.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP234\A0054197.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP234\A0054261.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP234\A0054262.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP234\A0054263.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP234\A0054274.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP234\A0054278.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP235\A0054291.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP235\A0054295.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP235\A0054299.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP235\A0054303.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP235\A0054308.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP235\A0054312.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP235\A0054316.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP235\A0054320.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP235\A0054322.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP235\A0054326.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP235\A0054332.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP235\A0054336.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP237\A0054344.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP237\A0054354.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP237\A0054359.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP238\A0054432.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP238\A0054646.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP238\A0054647.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP239\A0054665.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP239\A0054673.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP239\A0054677.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP239\A0054687.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP241\A0054702.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP241\A0054707.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP241\A0054711.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP242\A0054718.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP245\A0054730.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP245\A0054745.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP245\A0054749.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP245\A0054754.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP246\A0054764.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP246\A0054769.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP246\A0054773.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP246\A0054778.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP246\A0054782.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP247\A0054930.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP247\A0054931.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP247\A0054932.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP247\A0054933.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP247\A0054934.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP248\A0054964.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP248\A0054968.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP248\A0054978.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP248\A0054982.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP248\A0054988.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP248\A0055000.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP248\A0055007.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP248\A0055016.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP248\A0055023.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP248\A0056023.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP248\A0056027.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP248\A0057023.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP248\A0057027.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP249\A0057037.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP249\A0057045.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP249\A0057159.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP249\A0057160.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP249\A0057161.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP249\A0057162.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP249\A0057163.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP249\A0057164.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP249\A0057165.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP249\A0057180.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP249\A0057184.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP249\A0058180.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP249\A0058184.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP252\A0058243.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP252\A0058247.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP252\A0058252.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP252\A0058260.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP252\A0058264.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP252\A0058286.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP252\A0058290.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP252\A0058326.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP253\A0058340.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP253\A0059340.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP253\A0059344.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP253\A0059351.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP253\A0059355.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP253\A0059361.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP253\A0059365.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP254\A0059427.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP254\A0059428.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP254\A0059429.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP254\A0059430.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP254\A0059440.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP254\A0059446.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP254\A0059449.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP254\A0059453.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP254\A0059457.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP254\A0059466.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP254\A0059503.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP254\A0059504.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP254\A0059505.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP254\A0059506.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP254\A0059513.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP255\A0059524.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP255\A0059528.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP255\A0059532.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP255\A0059536.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP255\A0059540.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP255\A0059547.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP255\A0059552.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP256\A0059559.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP256\A0059566.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP256\A0059570.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP256\A0059573.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0D573AD-6F9C-4307-9D47-C10892964EEB}\RP256\A0059577.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\WINDOWS\system32\csons.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\WINDOWS\system32\dmdke.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\WINDOWS\system32\dmkov.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\WINDOWS\system32\dmtfq.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
::Report end
Now for the HJT log:
Logfile of HijackThis v1.99.1
Scan saved at 7:24:07 AM, on 11/22/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\ISS\BlackICE\blackd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\pctspk.exe
C:\Program Files\ISS\BlackICE\rapapp.exe
C:\WINDOWS\system32\ScsiAccess.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Executive Software\Undelete\UdServe.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Sunbelt Software\CounterSpy Client\sunasDtServ.exe
C:\Program Files\Sunbelt Software\CounterSpy Client\sunasServ.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\SM1BG.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\ISS\BlackICE\blackice.exe
C:\Program Files\Hewlett-Packard\AiO\hp psc 700 series\Bin\hpobrt07.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\PROGRA~1\Webshots\Webshots.scr
C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Hijack this\HijackThis.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {77701e16-9bfe-4b63-a5b4-7bd156758a37} - (no file)
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: (no name) - {C17590D2-ECB4-4b15-8820-F58798DCC118} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Executive Software\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [sunasDTServ] C:\Program Files\Sunbelt Software\CounterSpy Client\sunasDtServ.exe
O4 - HKLM\..\Run: [sunasServ] C:\Program Files\Sunbelt Software\CounterSpy Client\sunasServ.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SM1BG] C:\WINDOWS\SM1BG.EXE
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [iolo Utility Bar] "C:\Program Files\iolo\System Mechanic 5 Professional\SMUtilityBar.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: BlackICE PC Protection.lnk = C:\Program Files\ISS\BlackICE\blackice.exe
O4 - Global Startup: HPAiODevice(hp psc 700 series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp psc 700 series\Bin\hpobrt07.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O8 - Extra context menu item: &Webshots Photo Search - res://C:\Program Files\Webshots\WSToolbar4IE.dll/MENUSEARCH.HTM
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {2E12FB00-546B-4EE3-9CC2-057BF02E1C17} (Webshots Multiple Media Uploader - Container) - http://community.webshots.com/html/atx/wsaxcontrol.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/windowsupdate/…b?1135072400508
O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - http://community.webshots.com/html/WSPhotoUploader.CAB
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: BlackICE - Internet Security Systems, Inc. - C:\Program Files\ISS\BlackICE\blackd.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: RapApp - Internet Security Systems, Inc. - C:\Program Files\ISS\BlackICE\rapapp.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\system32\ScsiAccess.EXE
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Executive Software Undelete (UndeleteService) - Executive Software International - C:\Program Files\Executive Software\Undelete\UdServe.exe