Hi, Thanks for your reply, i have done as you stated & posted below. I've done a Spybot scan & an adaware scan with a full avast virus scan plus i did the virus scan on windows live & tried using the virus scan at Trend micro. The problem at Trend Micro was that i have been unable to fully complete the test because my browser simply shuts down while the virus check is in progress. However during one attempt at doing the test it stated that there were three very bad problems such as "SPYWARE_KEYL_ASTLOG" "TSPY_BIFROSE" & "TSPY_HUBIGON" & that "SPYWARE_KEYL_ASTLOG" is a key logger that looks for passwords that are entered in to boxes that only show aterix's.
Once again thanks for your help
I've just tried attatching it but it was too big so i'll copy & paste it below.
--- Search result list ---
MediaPlex: Tracking cookie (Internet Explorer: Nick) (Cookie, fixed)
Advertising.com: Tracking cookie (Internet Explorer: Nick) (Cookie, fixed)
Avenue A, Inc.: Tracking cookie (Internet Explorer: Nick) (Cookie, fixed)
Bifrose.LA: System file (File, fixed)
C:\WINDOWS\system32\drivers\oreans32.sys
Bifrose.LA: Settings (Registry key, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{9B71D88C-C598-4935-C5D1-43AA4DB90836}
DoubleClick: Tracking cookie (Internet Explorer: Nick) (Cookie, fixed)
Fake.Wget: Settings (Registry key, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Wget
Fake.Wget: Settings (Registry key, fixed)
HKEY_USERS\S-1-5-21-602162358-1957994488-682003330-1004\Software\Wget
Microsoft.WindowsSecurityCenter_disabled: Settings (Registry change, fixed)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wscsvc\Start!=W=2
--- Spybot - Search && Destroy version: 1.3 ---
2006-09-15 Includes\Cookies.sbi
2006-09-15 Includes\Dialer.sbi
2006-09-15 Includes\Hijackers.sbi
2006-09-15 Includes\Keyloggers.sbi
2004-11-29 Includes\LSP.sbi
2006-09-15 Includes\Malware.sbi
2006-09-15 Includes\PUPS.sbi
2006-09-15 Includes\Revision.sbi
2006-09-15 Includes\Security.sbi
2006-09-15 Includes\Spybots.sbi
2005-02-17 Includes\Tracks.uti
2006-09-15 Includes\Trojans.sbi
--- System information ---
Windows XP (Build: 2600) Service Pack 2
/ Windows Media Player 10: Security Update for Windows Media Player 10 (KB911565)
/ Windows Media Player 10: Security Update for Windows Media Player 10 (KB917734)
/ Windows XP / SP3: Windows XP Hotfix - KB834707
/ Windows XP / SP3: Windows XP Hotfix - KB867282
/ Windows XP / SP3: Windows XP Hotfix - KB873333
/ Windows XP / SP3: Windows XP Hotfix - KB873339
/ Windows XP / SP3: Security Update for Windows XP (KB883939)
/ Windows XP / SP3: Windows XP Hotfix - KB885250
/ Windows XP / SP3: Windows XP Hotfix - KB885835
/ Windows XP / SP3: Windows XP Hotfix - KB885836
/ Windows XP / SP3: Windows XP Hotfix - KB886185
/ Windows XP / SP3: Windows XP Hotfix - KB887472
/ Windows XP / SP3: Windows XP Hotfix - KB887742
/ Windows XP / SP3: Windows XP Hotfix - KB887797
/ Windows XP / SP3: Windows XP Hotfix - KB888113
/ Windows XP / SP3: Windows XP Hotfix - KB888302
/ Windows XP / SP3: Security Update for Windows XP (KB890046)
/ Windows XP / SP3: Windows XP Hotfix - KB890047
/ Windows XP / SP3: Windows XP Hotfix - KB890175
/ Windows XP / SP3: Windows XP Hotfix - KB890859
/ Windows XP / SP3: Windows XP Hotfix - KB890923
/ Windows XP / SP3: Windows XP Hotfix - KB891781
/ Windows XP / SP3: Security Update for Windows XP (KB893066)
/ Windows XP / SP3: Windows XP Hotfix - KB893086
/ Windows XP / SP3: Security Update for Windows XP (KB893756)
/ Windows XP / SP3: Windows Installer 3.1 (KB893803)
/ Windows XP / SP3: Windows Installer 3.1 (KB893803)
/ Windows XP / SP3: Update for Windows XP (KB894391)
/ Windows XP / SP3: Security Update for Windows XP (KB896358)
/ Windows XP / SP3: Security Update for Windows XP (KB896422)
/ Windows XP / SP3: Security Update for Windows XP (KB896423)
/ Windows XP / SP3: Security Update for Windows XP (KB896424)
/ Windows XP / SP3: Security Update for Windows XP (KB896428)
/ Windows XP / SP3: Security Update for Windows XP (KB896688)
/ Windows XP / SP3: Update for Windows XP (KB896727)
/ Windows XP / SP3: Update for Windows XP (KB898461)
/ Windows XP / SP3: Security Update for Windows XP (KB899587)
/ Windows XP / SP3: Security Update for Windows XP (KB899588)
/ Windows XP / SP3: Security Update for Windows XP (KB899591)
/ Windows XP / SP3: Update for Windows XP (KB900485)
/ Windows XP / SP3: Security Update for Windows XP (KB900725)
/ Windows XP / SP3: Update for Windows XP (KB900930)
/ Windows XP / SP3: Security Update for Windows XP (KB901017)
/ Windows XP / SP3: Security Update for Windows XP (KB901214)
/ Windows XP / SP3: Security Update for Windows XP (KB902400)
/ Windows XP / SP3: Security Update for Windows XP (KB903235)
/ Windows XP / SP3: Security Update for Windows XP (KB904706)
/ Windows XP / SP3: Security Update for Windows XP (KB905414)
/ Windows XP / SP3: Security Update for Windows XP (KB905749)
/ Windows XP / SP3: Security Update for Windows XP (KB905915)
/ Windows XP / SP3: Security Update for Windows XP (KB908519)
/ Windows XP / SP3: Security Update for Windows XP (KB908531)
/ Windows XP / SP3: Update for Windows XP (KB910437)
/ Windows XP / SP3: Update for Windows XP (KB911280)
/ Windows XP / SP3: Security Update for Windows XP (KB911562)
/ Windows XP / SP3: Security Update for Windows XP (KB911567)
/ Windows XP / SP3: Security Update for Windows XP (KB911927)
/ Windows XP / SP3: Security Update for Windows XP (KB912812)
/ Windows XP / SP3: Security Update for Windows XP (KB912919)
/ Windows XP / SP3: Security Update for Windows XP (KB913446)
/ Windows XP / SP3: Security Update for Windows XP (KB913580)
/ Windows XP / SP3: Security Update for Windows XP (KB914388)
/ Windows XP / SP3: Security Update for Windows XP (KB914389)
/ Windows XP / SP3: Security Update for Windows XP (KB916281)
/ Windows XP / SP3: Update for Windows XP (KB916595)
/ Windows XP / SP3: Security Update for Windows XP (KB917159)
/ Windows XP / SP3: Security Update for Windows XP (KB917344)
/ Windows XP / SP3: Security Update for Windows XP (KB917422)
/ Windows XP / SP3: Security Update for Windows XP (KB917953)
/ Windows XP / SP3: Security Update for Windows XP (KB918439)
/ Windows XP / SP3: Security Update for Windows XP (KB918899)
/ Windows XP / SP3: Security Update for Windows XP (KB919007)
/ Windows XP / SP3: Security Update for Windows XP (KB920214)
/ Windows XP / SP3: Security Update for Windows XP (KB920670)
/ Windows XP / SP3: Security Update for Windows XP (KB920683)
/ Windows XP / SP3: Security Update for Windows XP (KB920685)
/ Windows XP / SP3: Update for Windows XP (KB920872)
/ Windows XP / SP3: Security Update for Windows XP (KB921398)
/ Windows XP / SP3: Security Update for Windows XP (KB921883)
/ Windows XP / SP3: Update for Windows XP (KB922582)
/ Windows XP / SP3: Security Update for Windows XP (KB922616)
--- Startup entries list ---
Located: HK_LM:Run,
command:
Located: HK_LM:Run, avast!
command: C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
file: C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
size: 108160
MD5: e4289180e929bf984bfecefa73322a6a
Located: HK_LM:Run, Logitech Hardware Abstraction Layer
command: KHALMNPR.EXE
file: C:\WINDOWS\KHALMNPR.EXE
size: 94208
MD5: ffde5245589ffa24c5075203d2a9c314
Located: HK_LM:Run, LVCOMS
command: C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE
file: C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE
size: 98304
MD5: dc4cceab220639cff08890065665118c
Located: HK_LM:Run, NvMixerTray
command: C:\Program Files\NVIDIA Corporation\NvMixer\NvMixerTray.exe
file: C:\Program Files\NVIDIA Corporation\NvMixer\NvMixerTray.exe
size: 131072
MD5: ed010795e4e87f0752305b04e68b49ad
Located: HK_LM:Run, SpeedTouch USB Diagnostics
command: "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
file: C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
size: 866816
MD5: d40191aa225638ab20e59524cdd74030
Located: HK_LM:Run, startkey
command: C:\WINDOWS\system32\systemhosts.exe
file: C:\WINDOWS\system32\systemhosts.exe
size: 1194181
MD5: cc1ebcbbb56a0ed4c42835d430757cd6
Located: HK_LM:Run, SunJavaUpdateSched
command: C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
file: C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
size: 36975
MD5: 61a3a9d5d98bf0331df5b716144a8100
Located: HK_CU:Run, CTFMON.EXE
command: C:\WINDOWS\system32\ctfmon.exe
file: C:\WINDOWS\system32\ctfmon.exe
size: 15360
MD5: 24232996a38c0b0cf151c2140ae29fc8
Located: HK_CU:Run, CursorXP
command: C:\Program Files\CursorXP\CursorXP.exe
file: C:\Program Files\CursorXP\CursorXP.exe
size: 128000
MD5: 7b70742882445f1269fc49708ab39751
Located: HK_CU:Run, KeyType
command:
Located: HK_CU:Run, startkey
command: C:\WINDOWS\system32\systemhosts.exe
file: C:\WINDOWS\system32\systemhosts.exe
size: 1194181
MD5: cc1ebcbbb56a0ed4c42835d430757cd6
Located: HK_CU:Run, Steam
command:
Located: Startup (common), Logitech SetPoint.lnk
command: C:\Program Files\Logitech\SetPoint\SetPoint.exe
file: C:\Program Files\Logitech\SetPoint\SetPoint.exe
size: 593920
MD5: bc91cb3da7a58510a39a0ccbb82cd797
Located: Startup (disabled), Adobe Reader Speed Launch (DISABLED)
command: C:\PROGRA~1\Adobe\ACROBA~2.0\Reader\READER~1.EXE
file: C:\PROGRA~1\Adobe\ACROBA~2.0\Reader\READER~1.EXE
size: 29696
MD5: 43362b96870ce8649f4f2ec893da93f0
Located: Startup (disabled), Run Nintendo Wi-Fi USB Connector Registration Tool (DISABLED)
command: C:\PROGRA~1\WIFICO~1\NINTEN~1.EXE
file: C:\PROGRA~1\WIFICO~1\NINTEN~1.EXE
size: 1073152
MD5: af38256899bf8d5f4358ad68a5453bbe
Located: Startup (disabled), Microsoft Find Fast (DISABLED)
command: C:\PROGRA~1\MICROS~3\Office\FINDFAST.EXE
file: C:\PROGRA~1\MICROS~3\Office\FINDFAST.EXE
size: 111376
MD5: 22661527d19c655fd291bf421090b157
Located: Startup (disabled), Office Startup (DISABLED)
command: C:\PROGRA~1\MICROS~3\Office\OSA.EXE -b
file: C:\PROGRA~1\MICROS~3\Office\OSA.EXE
size: 51984
MD5: d06276d4cad46cdceabefdeb1a0d3c0d
Located: Startup (disabled), ²¥°ÔÍøÂçµçÊÓ (DISABLED)
command: C:\PROGRA~1\pcast\PODCAS~1\PODCAS~2.EXE
--- Browser helper object list ---
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
BHO name:
CLSID name: Adobe PDF Reader Link Helper
description: Adobe Acrobat reader
classification: Legitimate
known filename: AcroIEhelper.ocx<br>AcroIEhelper.dll
info link:
http://www.adobe.com/products/acrobat/readstep2.html
info source: TonyKlein
Path: C:\Program Files\Adobe\Acrobat 7.0\ActiveX\
Long name: AcroIEHelper.dll
Short name: ACROIE~1.DLL
Date (created): 24/09/2005 05:12:08
Date (last access): 20/09/2006 17:52:42
Date (last write): 12/01/2006 21:38:22
Filesize: 63128
Attributes: archive
MD5: F17B2B264072B921FC66A0BE16626BAB
CRC32: 5184CFEA
Version: 0.7.0.0
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
BHO name:
CLSID name: SSVHelper Class
Path: C:\Program Files\Java\jre1.5.0_06\bin\
Long name: ssv.dll
Short name:
Date (created): 10/11/2005 14:03:56
Date (last access): 20/09/2006 17:52:42
Date (last write): 10/11/2005 14:22:10
Filesize: 184423
Attributes: archive
MD5: F01726F7CA8538FDD4663C9DB8FEAEDC
CRC32: 0111B892
Version: 0.5.0.0
{9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
BHO name:
CLSID name: Windows Live Sign-in Helper
Path: C:\Program Files\Common Files\Microsoft Shared\Windows Live\
Long name: WindowsLiveLogin.dll
Short name: WINDOW~1.DLL
Date (created): 07/07/2006 12:29:52
Date (last access): 20/09/2006 17:52:42
Date (last write): 07/07/2006 12:29:52
Filesize: 324416
Attributes: archive
MD5: 52A70C80A446FA3BBCDAF59A9AB26AF4
CRC32: B1456034
Version: 0.4.0.0
--- ActiveX list ---
{00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class)
DPF name:
CLSID name: Checkers Class
Path: C:\WINDOWS\Downloaded Program Files\
Long name: msgrchkr.dll
Short name:
Date (created): 29/05/2003 16:00:18
Date (last access): 20/09/2006 18:51:42
Date (last write): 29/05/2003 16:00:18
Filesize: 77408
Attributes: archive
MD5: 42D567DF86B9B7AC4A89664C9651B68B
CRC32: 47FF3D19
Version: 0.7.0.1
{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object)
DPF name:
CLSID name: QuickTime Object
description: Apple Quicktime
classification: Legitimate
known filename: QTPLUGIN.OCX
info link:
info source: Patrick M. Kolla
Path: C:\Program Files\K-Lite Codec Pack\QuickTime\QTSystem\
Long name: QTPlugin.ocx
Short name:
Date (created): 17/03/2006 14:06:44
Date (last access): 20/09/2006 15:19:24
Date (last write): 11/01/2006 00:33:18
Filesize: 409600
Attributes: archive
MD5: F4EC36EB22CFE40551DE3713805FA3F2
CRC32: 634EA6F9
Version: 0.7.0.0
{14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class)
DPF name:
CLSID name: MessengerStatsClient Class
Path: C:\WINDOWS\Downloaded Program Files\
Long name: MessengerStatsPAClient.dll
Short name: MESSEN~2.DLL
Date (created): 06/04/2004 19:03:54
Date (last access): 20/09/2006 18:51:42
Date (last write): 06/04/2004 19:03:54
Filesize: 172072
Attributes: archive
MD5: 94D1773AEAA2197AFEE3A6F8404FE4E9
CRC32: 76C3823D
Version: 0.9.0.2
{166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control)
DPF name:
CLSID name: Shockwave ActiveX Control
description: Macromedia ShockWave Flash Player 7
classification: Unknown
known filename: SWDIR.DLL
info link:
info source: Patrick M. Kolla
Path: C:\WINDOWS\system32\Macromed\Director\
Long name: SwDir.dll
Short name:
Date (created): 30/11/2004 19:36:10
Date (last access): 20/09/2006 12:33:22
Date (last write): 09/09/2004 15:49:12
Filesize: 54488
Attributes: archive
MD5: 943193399C341AC34E842CB07B5F29A0
CRC32: 12DEB8F4
Version: 0.10.0.1
{215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.5)
DPF name:
CLSID name: Trend Micro ActiveX Scan Agent 6.5
Path: C:\WINDOWS\Downloaded Program Files\
Long name: Housecall_ActiveX.dll
Short name: HOUSEC~1.DLL
Date (created): 31/08/2006 14:15:18
Date (last access): 20/09/2006 16:54:46
Date (last write): 31/08/2006 14:15:18
Filesize: 383488
Attributes: archive
MD5: 29FEC1273BD4BCDCF828C8AE73B8A5DC
CRC32: F620880C
Version: 0.6.0.5
{2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object)
DPF name:
CLSID name: CMediaMix Object
Path: C:\WINDOWS\system32\
Long name: MediaLogic.dll
Short name: MEDIAL~1.DLL
Date (created): 20/12/2005 12:00:40
Date (last access): 20/09/2006 12:33:42
Date (last write): 20/12/2005 12:00:40
Filesize: 253128
Attributes: archive
MD5: 0F768B295C27FB1BD9B3376575DD730A
CRC32: D7266458
Version: 0.1.0.0
{2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class)
DPF name:
CLSID name: Minesweeper Flags Class
Path: C:\WINDOWS\Downloaded Program Files\
Long name: minesweeper.dll
Short name: MINESW~1.DLL
Date (created): 29/05/2003 16:00:22
Date (last access): 20/09/2006 18:51:42
Date (last write): 29/05/2003 16:00:22
Filesize: 84064
Attributes: archive
MD5: F951FD0EA383DF2D49CA0359E4A86968
CRC32: 50A69718
Version: 0.7.0.1
{30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class)
DPF name:
CLSID name: YInstStarter Class
Path: C:\WINDOWS\Downloaded Program Files\
Long name: yinsthelper.dll
Short name: YINSTH~1.DLL
Date (created): 26/01/2004 19:40:04
Date (last access): 20/09/2006 18:51:42
Date (last write): 26/01/2004 19:40:04
Filesize: 133120
Attributes: archive
MD5: E1FBF33D995C89583A36F461EC2879FF
CRC32: 1592E04B
Version: 7.212.0.1
{38D63471-E630-4492-A986-B8C48B79F2F8} (CVideoEgg_ActiveXCtl Object)
DPF name:
CLSID name: CVideoEgg_ActiveXCtl Object
Path: C:\Documents and Settings\All Users\Application Data\VideoEgg1\
Long name: npvideoegg-updater.dll
Short name: NPVIDE~1.DLL
Date (created): 27/04/2006 19:08:22
Date (last access): 20/09/2006 16:58:34
Date (last write): 27/04/2006 19:08:22
Filesize: 233472
Attributes: archive
MD5: B9291899B9C9ACDA1AE9420FFAF21BB0
CRC32: 3D29D674
Version: 0.1.0.0
{39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class)
DPF name:
CLSID name: FilePlanet Download Control Class
Path: C:\WINDOWS\Downloaded Program Files\
Long name: FilePlanetDownloadCtrl.dll
Short name: FILEPL~1.DLL
Date (created): 21/06/2004 20:11:18
Date (last access): 20/09/2006 18:51:42
Date (last write): 21/06/2004 20:11:18
Filesize: 294912
Attributes: archive
MD5: E6B0A532DC0404BCB678CB0F6757008D
CRC32: AE97F52E
Version: 0.1.0.0