Ok i have done all of that and removed the registry cleaner. I have read that thread on registry cleaners before but was undecided on wether i should remove it so thanks for the nudge in the right direction

This laptop is running much better now, thank you very much for helping.
p.s Do you recommend running Malwarebytes' anti-malware along with my other weekly checks?
ComboFix 08-10-08.02 - Student 2008-10-10 2:00:47.2 - NTFSx86
Running from: C:\Documents and Settings\Student\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Student\Desktop\CFScript.txt
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
C:\WINDOWS\System32\vOSn2ebS.exe
C:\WINDOWS\System32\Y0JdM5Kt.exe
C:\WINDOWS\Tasks\At1.job
C:\WINDOWS\Tasks\At10.job
C:\WINDOWS\Tasks\At11.job
C:\WINDOWS\Tasks\At12.job
C:\WINDOWS\Tasks\At13.job
C:\WINDOWS\Tasks\At14.job
C:\WINDOWS\Tasks\At15.job
C:\WINDOWS\Tasks\At16.job
C:\WINDOWS\Tasks\At17.job
C:\WINDOWS\Tasks\At18.job
C:\WINDOWS\Tasks\At19.job
C:\WINDOWS\Tasks\At2.job
C:\WINDOWS\Tasks\At20.job
C:\WINDOWS\Tasks\At21.job
C:\WINDOWS\Tasks\At22.job
C:\WINDOWS\Tasks\At23.job
C:\WINDOWS\Tasks\At3.job
C:\WINDOWS\Tasks\At4.job
C:\WINDOWS\Tasks\At5.job
C:\WINDOWS\Tasks\At6.job
C:\WINDOWS\Tasks\At7.job
C:\WINDOWS\Tasks\At73.job
C:\WINDOWS\Tasks\At74.job
C:\WINDOWS\Tasks\At75.job
C:\WINDOWS\Tasks\At76.job
C:\WINDOWS\Tasks\At77.job
C:\WINDOWS\Tasks\At78.job
C:\WINDOWS\Tasks\At79.job
C:\WINDOWS\Tasks\At8.job
C:\WINDOWS\Tasks\At80.job
C:\WINDOWS\Tasks\At81.job
C:\WINDOWS\Tasks\At82.job
C:\WINDOWS\Tasks\At83.job
C:\WINDOWS\Tasks\At84.job
C:\WINDOWS\Tasks\At85.job
C:\WINDOWS\Tasks\At86.job
C:\WINDOWS\Tasks\At87.job
C:\WINDOWS\Tasks\At88.job
C:\WINDOWS\Tasks\At89.job
C:\WINDOWS\Tasks\At9.job
C:\WINDOWS\Tasks\At90.job
C:\WINDOWS\Tasks\At91.job
C:\WINDOWS\Tasks\At92.job
C:\WINDOWS\Tasks\At93.job
C:\WINDOWS\Tasks\At94.job
C:\WINDOWS\Tasks\At95.job
C:\WINDOWS\Tasks\At96.job
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\Tasks\At1.job
C:\WINDOWS\Tasks\At10.job
C:\WINDOWS\Tasks\At11.job
C:\WINDOWS\Tasks\At12.job
C:\WINDOWS\Tasks\At13.job
C:\WINDOWS\Tasks\At14.job
C:\WINDOWS\Tasks\At15.job
C:\WINDOWS\Tasks\At16.job
C:\WINDOWS\Tasks\At17.job
C:\WINDOWS\Tasks\At18.job
C:\WINDOWS\Tasks\At19.job
C:\WINDOWS\Tasks\At2.job
C:\WINDOWS\Tasks\At20.job
C:\WINDOWS\Tasks\At21.job
C:\WINDOWS\Tasks\At22.job
C:\WINDOWS\Tasks\At23.job
C:\WINDOWS\Tasks\At3.job
C:\WINDOWS\Tasks\At4.job
C:\WINDOWS\Tasks\At5.job
C:\WINDOWS\Tasks\At6.job
C:\WINDOWS\Tasks\At7.job
C:\WINDOWS\Tasks\At73.job
C:\WINDOWS\Tasks\At74.job
C:\WINDOWS\Tasks\At75.job
C:\WINDOWS\Tasks\At76.job
C:\WINDOWS\Tasks\At77.job
C:\WINDOWS\Tasks\At78.job
C:\WINDOWS\Tasks\At79.job
C:\WINDOWS\Tasks\At8.job
C:\WINDOWS\Tasks\At80.job
C:\WINDOWS\Tasks\At81.job
C:\WINDOWS\Tasks\At82.job
C:\WINDOWS\Tasks\At83.job
C:\WINDOWS\Tasks\At84.job
C:\WINDOWS\Tasks\At85.job
C:\WINDOWS\Tasks\At86.job
C:\WINDOWS\Tasks\At87.job
C:\WINDOWS\Tasks\At88.job
C:\WINDOWS\Tasks\At89.job
C:\WINDOWS\Tasks\At9.job
C:\WINDOWS\Tasks\At90.job
C:\WINDOWS\Tasks\At91.job
C:\WINDOWS\Tasks\At92.job
C:\WINDOWS\Tasks\At93.job
C:\WINDOWS\Tasks\At94.job
C:\WINDOWS\Tasks\At95.job
C:\WINDOWS\Tasks\At96.job
.
((((((((((((((((((((((((( Files Created from 2008-09-10 to 2008-10-10 )))))))))))))))))))))))))))))))
.
2008-10-09 20:51 . 2008-10-09 20:51 <DIR> d-------- C:\Program Files\SpywareBlaster
2008-10-09 20:51 . 2008-10-09 20:58 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-10-06 15:49 . 2008-10-06 15:49 <DIR> d-------- C:\Program Files\Trend Micro
2008-10-06 07:39 . 2008-10-06 07:39 <DIR> d-------- C:\Program Files\Windows Live Safety Center
2008-10-04 21:23 . 2008-10-05 08:52 253 --a------ C:\WINDOWS\wininit.ini
2008-10-04 06:09 . 2008-10-04 06:09 <DIR> d-------- C:\Program Files\directx
2008-10-03 13:27 . 2008-10-03 13:58 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-10-01 22:43 . 2008-10-01 22:43 4,096 --a------ C:\WINDOWS\d3dx.dat
2008-10-01 19:53 . 2008-10-03 07:15 2,508 --a------ C:\Gens.cfg
2008-10-01 19:52 . 2008-10-01 19:52 40 --a------ C:\language.dat
2008-10-01 19:51 . 2008-10-01 19:51 882,400 --a------ C:\Streets of Rage 2 (U) [!].7z
2008-10-01 19:48 . 2006-05-21 03:25 1,875,968 --a------ C:\gens.exe
2008-10-01 19:48 . 2005-01-30 22:04 83,132 --a------ C:\GENS.hlp
2008-10-01 19:48 . 2005-01-29 01:21 32,256 --a------ C:\kailleraclient.dll
2008-10-01 19:39 . 2008-10-01 19:44 426,330 --a------ C:\gens-win32-bin-2[1].14.7z
2008-09-27 02:42 . 2008-09-27 02:42 <DIR> d-------- C:\Program Files\Total War
2008-09-15 19:02 . 2008-10-10 01:25 <DIR> d-------- C:\Program Files\Eusing Free Registry Cleaner
2008-09-15 12:50 . 2008-05-01 15:33 331,776 -----c--- C:\WINDOWS\system32\dllcache\msadce.dll
2008-09-15 12:49 . 2008-04-11 20:04 691,712 -----c--- C:\WINDOWS\system32\dllcache\inetcomm.dll
2008-09-15 12:47 . 2008-06-13 12:05 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-09-15 12:46 . 2008-05-08 15:02 203,136 -----c--- C:\WINDOWS\system32\dllcache\rmcast.sys
2008-09-14 16:08 . 2008-09-14 16:08 <DIR> dr-h----- C:\AHCache
2008-09-13 08:12 . 2008-09-13 08:12 <DIR> d-------- C:\WINDOWS\system32\scripting
2008-09-13 08:12 . 2008-09-13 08:12 <DIR> d-------- C:\WINDOWS\system32\en
2008-09-13 08:12 . 2008-09-13 08:12 <DIR> d-------- C:\WINDOWS\l2schemas
2008-09-13 07:11 . 2008-04-14 01:12 1,001,472 -----c--- C:\WINDOWS\system32\dllcache\wmvdmoe2.dll
2008-09-13 07:11 . 2008-04-14 01:12 809,984 -----c--- C:\WINDOWS\system32\dllcache\wmvdmod.dll
2008-09-13 07:11 . 2008-04-14 01:12 258,048 -----c--- C:\WINDOWS\system32\dllcache\wmvds32.ax
2008-09-13 07:09 . 2008-04-14 01:12 774,144 -----c--- C:\WINDOWS\system32\dllcache\setup_wm.exe
2008-09-13 07:08 . 2008-04-14 01:12 1,306,624 --a------ C:\WINDOWS\system32\msxml6.dll
2008-09-13 07:07 . 2008-04-14 01:12 786,432 -----c--- C:\WINDOWS\system32\dllcache\migrate.exe
2008-09-13 07:06 . 2008-04-14 01:10 102,912 -----c--- C:\WINDOWS\system32\dllcache\dpcdll.dll
2008-09-13 07:06 . 2008-04-14 01:09 24,064 -----c--- C:\WINDOWS\system32\dllcache\pidgen.dll
2008-09-13 07:06 . 2008-04-14 01:09 6,144 --a------ C:\WINDOWS\system32\kbdnepr.dll
2008-09-13 07:06 . 2008-04-14 01:09 6,144 --a------ C:\WINDOWS\system32\kbdiultn.dll
2008-09-13 07:06 . 2008-04-14 01:09 6,144 --a------ C:\WINDOWS\system32\kbdbhc.dll
2008-09-13 07:06 . 2007-06-21 06:52 974 --a------ C:\WINDOWS\system32\pid.inf
2008-09-13 07:04 . 2008-04-14 01:11 286,720 -----c--- C:\WINDOWS\system32\dllcache\blackbox.dll
2008-09-13 07:04 . 2008-04-14 01:11 233,472 --a------ C:\WINDOWS\system32\azroles.dll
2008-09-13 07:04 . 2008-04-14 01:11 136,192 --a------ C:\WINDOWS\system32\aaclient.dll
2008-09-13 07:04 . 2008-04-13 18:23 8,192 -----c--- C:\WINDOWS\system32\dllcache\asferror.dll
2008-09-13 07:04 . 2008-04-14 01:11 7,168 --a------ C:\WINDOWS\system32\bitsprx4.dll
2008-09-13 07:04 . 2001-08-23 13:00 999 -----c--- C:\WINDOWS\system32\dllcache\bktrh.gif
2008-09-12 17:15 . 2008-09-12 17:15 <DIR> d-------- C:\WINDOWS\provisioning
2008-09-12 16:05 . 2008-04-14 05:42 11,264 --a------ C:\WINDOWS\system32\spnpinst.exe
2008-09-12 16:05 . 2004-08-02 14:20 7,208 --a------ C:\WINDOWS\system32\secupd.sig
2008-09-12 16:05 . 2004-08-02 14:20 4,569 --a------ C:\WINDOWS\system32\secupd.dat
2008-09-12 13:14 . 2008-09-15 13:15 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2008-09-12 13:14 . 2007-08-10 20:46 26,488 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-09-12 13:03 . 2008-09-13 08:12 <DIR> d-------- C:\WINDOWS\system32\bits
2008-09-12 12:57 . 2008-04-13 18:39 438,784 --a------ C:\WINDOWS\system32\xpob2res.dll
2008-09-12 12:57 . 2008-04-14 01:12 354,304 --a------ C:\WINDOWS\system32\winhttp.dll
2008-09-12 12:57 . 2008-04-14 01:12 18,944 --a------ C:\WINDOWS\system32\qmgrprxy.dll
2008-09-12 12:57 . 2008-04-14 01:11 8,192 --a------ C:\WINDOWS\system32\bitsprx2.dll
2008-09-12 12:57 . 2008-04-14 01:11 7,168 --a------ C:\WINDOWS\system32\bitsprx3.dll
2008-09-12 12:51 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-09-12 12:51 . 2007-07-30 19:19 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-09-12 12:46 . 2007-07-30 19:19 43,352 --a------ C:\WINDOWS\system32\wups2.dll
2008-09-12 12:46 . 2007-07-30 19:18 34,136 --a------ C:\WINDOWS\system32\wucltui.dll.mui
2008-09-12 12:46 . 2007-07-30 19:18 33,624 --a------ C:\WINDOWS\system32\wups.dll
2008-09-12 12:45 . 2007-07-30 19:19 549,720 --a------ C:\WINDOWS\system32\wuapi.dll
2008-09-12 12:45 . 2007-07-30 19:19 325,976 --a------ C:\WINDOWS\system32\wucltui.dll
2008-09-12 12:45 . 2007-07-30 19:19 216,408 --a------ C:\WINDOWS\system32\wuaucpl.cpl
2008-09-12 12:45 . 2007-07-30 19:19 25,944 --a------ C:\WINDOWS\system32\wuaucpl.cpl.mui
2008-09-12 12:45 . 2007-07-30 19:19 25,944 --a------ C:\WINDOWS\system32\wuapi.dll.mui
2008-09-12 12:45 . 2007-07-30 19:18 20,312 --a------ C:\WINDOWS\system32\wuaueng.dll.mui
2008-09-12 12:36 . 2008-09-12 12:35 98,968 --a------ C:\Overview of Windows XP Service Pack 3.docx
2008-09-12 11:59 . 2003-01-07 17:37 1,338,880 --a------ C:\WINDOWS\system32\IEBAK000.TMP
2008-09-12 11:59 . 2002-08-29 11:41 401,920 --a------ C:\WINDOWS\system32\IEBAK001.TMP
2008-09-12 11:59 . 2008-09-12 11:59 98,304 --a------ C:\WINDOWS\system32\IEBAK002.TMP
2008-09-10 20:39 . 2003-03-18 21:20 1,060,864 --a------ C:\WINDOWS\system32\MFC71.dll
2008-09-10 12:14 . 2008-09-10 12:14 <DIR> d-------- C:\Program Files\Alwil Software
2008-09-10 12:12 . 2007-01-18 13:00 3,968 --a------ C:\WINDOWS\system32\drivers\AvgArCln.sys
2008-09-10 12:11 . 2008-09-10 12:11 423,736 --a------ C:\antirootkit.exe
2008-09-10 11:57 . 2008-10-03 16:37 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-10 10:34 . 2008-09-10 10:34 <DIR> d-------- C:\Documents and Settings\Student\Application Data\Leadertech
2008-09-10 10:13 . 2008-09-10 10:13 <DIR> d-------- C:\Program Files\Lavasoft
2008-09-10 02:24 . 2008-09-10 02:24 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\IBPlugin
2008-09-10 00:52 . 2004-07-26 10:34 139,264 --a------ C:\WINDOWS\system32\OPDSL.DLL
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-04 01:39 --------- d-----w C:\Program Files\Common Files\Adobe
2008-10-03 18:05 2,864 ----a-w C:\WINDOWS\system32\winsock.dll
2008-10-02 06:38 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-09-05 12:31 --------- d-----w C:\Documents and Settings\Student\Application Data\IBPlugin
2008-07-31 09:41 68,616 ----a-w C:\WINDOWS\system32\XAPOFX1_1.dll
2008-07-31 09:41 238,088 ----a-w C:\WINDOWS\system32\xactengine3_2.dll
2008-07-31 09:40 509,448 ----a-w C:\WINDOWS\system32\XAudio2_2.dll
2008-07-12 07:18 467,984 ----a-w C:\WINDOWS\system32\d3dx10_39.dll
2008-07-12 07:18 3,851,784 ----a-w C:\WINDOWS\system32\D3DX9_39.dll
2008-07-12 07:18 1,493,528 ----a-w C:\WINDOWS\system32\D3DCompiler_39.dll
2003-09-08 15:15 6,391 ----a-w C:\WINDOWS\inf\INF2.tmp
1998-12-09 01:53 99,840 ----a-w C:\Program Files\Common Files\IRAABOUT.DLL
1998-12-09 01:53 70,144 ----a-w C:\Program Files\Common Files\IRAMDMTR.DLL
1998-12-09 01:53 48,640 ----a-w C:\Program Files\Common Files\IRALPTTR.DLL
1998-12-09 01:53 31,744 ----a-w C:\Program Files\Common Files\IRAWEBTR.DLL
1998-12-09 01:53 186,368 ----a-w C:\Program Files\Common Files\IRAREG.DLL
1998-12-09 01:53 17,920 ----a-w C:\Program Files\Common Files\IRASRIAL.DLL
.
((((((((((((((((((((((((((((( snapshot@2008-10-09_ 4.19.41.13 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-10-09 03:44:17 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_44c.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk.disabled [2003-02-17 1725]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\awtsTLBq]
[BU]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.iv41"= IR41_32.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"KernelFaultCheck"=%systemroot%\system32\dumprep 0 -k
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R3 CBEN5;Xircom CardBus Ethernet 10/100 Adapter family;C:\WINDOWS\system32\DRIVERS\cben5.sys [2002-02-26 50498]
R3 maestro;ESS Maestro Audio Driver (WDM);C:\WINDOWS\system32\drivers\es198xdl.sys [2002-06-20 414400]
.
Contents of the 'Scheduled Tasks' folder
2008-10-07 C:\WINDOWS\Tasks\At24.job
- C:\WINDOWS\System32\vOSn2ebS.exe []
.
- - - - ORPHANS REMOVED - - - -
BHO-REGEDIT4 - (no file)
BHO-[HKEY_CURRENT_USER\software\microsoft\internet explorer\urlsearchhooks] - (no file)
BHO-{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"=" - (no file)
Notify-urqQiHyW - (no file)
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-10-10 02:06:45
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-10-10 2:12:42
ComboFix-quarantined-files.txt 2008-10-10 01:12:36
ComboFix2.txt 2008-10-09 03:22:03
Pre-Run: 2,789,986,304 bytes free
Post-Run: 2,784,694,272 bytes free
261 --- E O F --- 2008-09-12 12:38:08
Malwarebytes' Anti-Malware 1.28
Database version: 1248
Windows 5.1.2600 Service Pack 3
10/10/2008 03:54:10
mbam-log-2008-10-10 (03-54-10).txt
Scan type: Full Scan (C:\|)
Objects scanned: 83510
Time elapsed: 41 minute(s), 55 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 21
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 12
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\bho_myjavacore.mjcore (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\bho_myjavacore.mjcore.1 (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ipb.band (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ipb.band.1 (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{17e44256-51e0-4d46-a0c8-44e80ab4ba5b} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{cf54be1c-9359-4395-8533-1657cf209cfe} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{e0f01490-dcf3-4357-95aa-169a8c2b2190} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{d518921a-4a03-425e-9873-b9a71756821e} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{80ef304a-b1c4-425c-8535-95ab6f1eefb8} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\BHO_MyJavaCore.DLL (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWay) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\xpre (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\dkwqgnbe.bvas (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\dkwqgnbe.toolbar.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
C:\WINDOWS\system32\wTR19 (Trojan.Agent) -> Quarantined and deleted successfully.
Files Infected:
C:\QooBox\Quarantine\C\WINDOWS\system32\evsevswi.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\lafcuqma.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\ljJBsRLD.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\syswdhek.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\urqQiHyW.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\vdglncwj.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2A1BC780-7E63-401C-97DD-05800C2AB9EA}\RP2\A0000009.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2A1BC780-7E63-401C-97DD-05800C2AB9EA}\RP2\A0000013.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2A1BC780-7E63-401C-97DD-05800C2AB9EA}\RP2\A0000014.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2A1BC780-7E63-401C-97DD-05800C2AB9EA}\RP2\A0000017.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2A1BC780-7E63-401C-97DD-05800C2AB9EA}\RP2\A0000020.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2A1BC780-7E63-401C-97DD-05800C2AB9EA}\RP2\A0000019.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 03:56:37, on 10/10/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\atievxx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\HijackThis\HJT.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: (no name) - {12CEC643-277F-4D9C-8E33-B7C9FEEB18FE} - (no file)
O2 - BHO: (no name) - {20989C00-4042-491C-8E4D-79BF8AAE5FBD} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {B09E0F0B-28FE-4A7E-90F6-6D09E4234852} - (no file)
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Microsoft Office.lnk.disabled
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) -
http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5036.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.microsoft.com/win...ls/en/x86/client/wuweb_site.cab?1221219879240
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.microsoft.com/mic...ls/en/x86/client/muweb_site.cab?1221220180553
O20 - Winlogon Notify: awtsTLBq - C:\WINDOWS\
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: UStorage Server Service - Unknown owner - C:\WINDOWS\system32\UStorSrv.exe (file missing)
--
End of file - 3632 bytes