Hi Blade81,
The forum wouldn't let me put both main.txt and extra.txt in one reply so I have split them
Results of Decard's Scan main.txt follows:
Deckard's System Scanner v20071014.68
Run by Keith on 2008-01-13 18:33:14
Computer is in Normal Mode.
--------------------------------------------------------------------------------
Backed up registry hives.
Performed disk cleanup.
Percentage of Memory in Use: 77% (more than 75%).
Total Physical Memory: 255 MiB (256 MiB recommended).
-- HijackThis (run as Keith.exe) -----------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:33:51, on 13/01/2008
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\WINDOWS\system32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE
C:\WINDOWS\system32\regsvc.exe
C:\WINDOWS\system32\MSTask.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\system32\stisvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\Tablet.exe
C:\WINDOWS\System32\WBEM\WinMgmt.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\TPPALDR.EXE
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Documents and Settings\Keith\Desktop\dss.exe
C:\DOCUME~1\Keith\Desktop\Keith.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://www.netscapeonline.co.uk/search/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://keyword.uk.netscape.com/keyword/%s
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [TPP Auto Loader] C:\WINDOWS\TPPALDR.EXE
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKUS\.DEFAULT\..\Run: [internat.exe] internat.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q (User 'Default user')
O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} -
https://www-secure.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} -
https://www-secure.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) -
http://www.lizardtech.com/download/files/win/djvuplugin/en_US/DjVuControl_en_US.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} -
https://www-secure.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} -
http://download.mcafee.com/molbin/shared/mcinsctl/en-gb/4,0,0,83/mcinsctl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1134682152277
O16 - DPF: {6B4788E2-BAE8-11D2-A1B4-00400512739B} (PWMediaSendControl Class) -
http://216.249.24.143/code/PWActiveXImgCtl.CAB
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1178712875385
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} -
http://bin.mcafee.com/molbin/shared/mcgdmgr/en-gb/1,0,0,20/mcgdmgr.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} -
https://www-secure.symantec.com/techsupp/asa/ctrl/SymAData.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0A7E049B-EBA0-4C74-9D05-B00D80C813E5}: NameServer = 194.168.4.100 194.168.8.100
O17 - HKLM\System\CS1\Services\Tcpip\..\{0A7E049B-EBA0-4C74-9D05-B00D80C813E5}: NameServer = 194.168.4.100 194.168.8.100
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINDOWS\System32\dmadmin.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\System32\Tablet.exe
--
End of file - 6948 bytes
-- HijackThis Fixed Entries (C:\DOCUME~1\Keith\Desktop\backups\) ---------------
backup-20080113-111421-192 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
backup-20080113-111421-230 O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
backup-20080113-111421-451 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
backup-20080113-111421-715 O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
-- File Associations -----------------------------------------------------------
.bat - batfile - DefaultIcon - C:\WINDOWS\system32\SHELL32.DLL,-153
.com - comfile - DefaultIcon - C:\WINDOWS\system32\SHELL32.DLL,2
.hlp - hlpfile - DefaultIcon - unable to read value
.ini - inifile - DefaultIcon - shell32.dll,-151
.js - JSFile - DefaultIcon - C:\Program Files\Macromedia\Dreamweaver MX\Dreamweaver.exe,2
.reg - regfile - DefaultIcon - unable to read value
.txt - txtfile - DefaultIcon - shell32.dll,-152
.vbs - VBSFile - DefaultIcon - unable to read value
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R0 iomdisk (Iomega Devices Disk Filter Services) - c:\windows\system32\drivers\iomdisk.sys <Not Verified; Iomega Corporation; Iomega Disk Filter Driver>
R0 PenClass (Pen Class) - c:\windows\system32\drivers\penclass.sys <Not Verified; Wacom Technology Corporation; Wacom Pen Class Driver>
R1 BANTExt (Belarc SMBios Access) - c:\windows\system32\drivers\bantext.sys
R3 alcan5wn (SpeedTouch USB ADSL PPP Networking Driver (NDISWAN)) - c:\windows\system32\drivers\alcan5wn.sys <Not Verified; THOMSON; SpeedTouch USB>
S3 3c1807pd (U.S. Robotics 56K Voice Win Int) - c:\windows\system32\drivers\3c1807pd.sys <Not Verified; 3Com Corporation; 3Com modem>
S3 AWINDIS5 (AWINDIS5 Protocol Driver) - c:\windows\system32\awindis5.sys <Not Verified; AMBIT Microsystems Corporation.; AMBIT WinDis32 Protocol Driver for Windows>
S3 Dot4Print (Print Class Driver for IEEE-1284.4 hpoipr07) - c:\windows\system32\drivers\hpoipr07.sys <Not Verified; HP; HP Dot4Print>
S3 hpoid407 (IEEE-1284.4 Driver hpoid407) - c:\windows\system32\drivers\hpoid407.sys <Not Verified; HP; HP Dot4 Windows 2000>
S3 hpoius07 (USB to IEEE-1284.4 Translation Driver hpoius07) - c:\windows\system32\drivers\hpoius07.sys <Not Verified; HP; HP Dot4Usb Windows 2000>
S3 NETGEAR_WG311T_SERVICE (NETGEAR WG311T Wireless Adapter Service) - c:\windows\system32\drivers\wg311tn5.sys (file missing)
S3 NuVision (Hauppauge WinTV USB Pro (PAL I FM)) - c:\windows\system32\drivers\nuvision.sys <Not Verified; Hauppauge Computer Works; WinTV USB>
S3 TPP300 (USB Storage Adapter V3 (TPP)) - c:\windows\system32\drivers\tpp300.sys <Not Verified; In-System Design, Inc.; TPP Storage Adapter>
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 Iomega App Services - "c:\progra~1\iomega\system32\appservices.exe" <Not Verified; Iomega Corporation; Iomega App Services>
R2 TabletService - c:\windows\system32\tablet.exe <Not Verified; Wacom Technology, Corp.; Wacom Win32 Tablet Service>
S4 Iomega Activity Disk2 - ""
-- Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
-- Scheduled Tasks -------------------------------------------------------------
2007-12-30 22:00:03 346 --a------ C:\WINDOWS\Tasks\SmartDefrag.job
2007-12-14 08:04:10 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
-- Files created between 2007-12-13 and 2008-01-13 -----------------------------
2008-01-11 09:40:37 16384 --a-----t C:\WINDOWS\system32\Perflib_Perfdata_204.dat
2008-01-07 10:24:34 0 d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-01-07 07:13:51 0 d-------- C:\WINDOWS\system32\ActiveScan
2007-12-25 20:24:04 16384 --a-----t C:\WINDOWS\system32\Perflib_Perfdata_1fc.dat
2007-12-24 12:41:19 16384 --a-----t C:\WINDOWS\system32\Perflib_Perfdata_210.dat
2007-12-24 06:29:33 16384 --a-----t C:\WINDOWS\system32\Perflib_Perfdata_214.dat
2007-12-21 13:44:27 16384 --a-----t C:\WINDOWS\system32\Perflib_Perfdata_21c.dat
2007-12-20 14:53:45 0 d-------- C:\Program Files\SpywareBlaster
2007-12-20 14:52:33 0 d-------- C:\Program Files\SpywareGuard
2007-12-19 20:29:29 2695168 --a------ C:\Documents and Settings\Keith\NTUSER.DAT
2007-12-14 08:04:07 16384 --a-----t C:\WINDOWS\system32\Perflib_Perfdata_354.dat
-- Find3M Report ---------------------------------------------------------------
2008-01-13 10:04:21 0 d-a------ C:\Program Files\Mozilla Thunderbird
2008-01-13 09:51:57 14304 --a------ C:\WINDOWS\system32\tablet.dat
2008-01-11 19:56:34 1204 --a------ C:\WINDOWS\system32\d3d9caps.dat
2007-12-31 11:12:30 0 d-a------ C:\Program Files\Spyware Doctor
2007-12-19 22:30:43 1285744 ---h----- C:\WINDOWS\ShellIconCache
2007-12-12 06:32:33 16384 --a-----t C:\WINDOWS\system32\Perflib_Perfdata_20c.dat
2007-12-11 09:10:59 16384 --a-----t C:\WINDOWS\system32\Perflib_Perfdata_218.dat
2007-12-03 23:00:01 0 d--h----- C:\Program Files\InstallShield Installation Information
2007-12-03 23:00:00 0 d-a------ C:\Program Files\Logitech
2007-12-03 22:15:54 0 d-------- C:\Documents and Settings\Keith\Application Data\Uniblue
2007-11-30 21:27:35 16384 --a-----t C:\WINDOWS\system32\Perflib_Perfdata_200.dat
2007-11-30 20:36:01 0 d-------- C:\Program Files\NETGEAR
2007-11-30 20:34:13 0 d-------- C:\Program Files\Canon
2007-11-30 17:33:06 0 dra------ C:\Program Files\Common Files
2007-11-30 14:47:46 0 d-------- C:\Program Files\IObit
2007-11-30 13:53:50 0 d-------- C:\Program Files\CCleaner
2007-11-30 08:46:31 16384 --a-----t C:\WINDOWS\system32\Perflib_Perfdata_208.dat
2007-11-29 23:00:01 0 d-------- C:\Program Files\Alwil Software
2007-11-29 22:52:36 0 d-a------ C:\Program Files\Common Files\Symantec Shared
2007-11-26 21:56:12 0 d-------- C:\Program Files\startup help
2007-11-26 21:43:59 0 d-------- C:\Program Files\Common Files\HP
2007-11-25 11:46:53 0 d-------- C:\Program Files\Zortam Mp3 Media Studio
2007-11-25 11:45:31 0 d-------- C:\Program Files\Zortam ID3 Tag Editor
2007-11-23 16:44:04 16384 --a-----t C:\WINDOWS\system32\Perflib_Perfdata_68c.dat
2007-11-23 16:22:23 0 d-------- C:\Documents and Settings\Keith\Application Data\Apple Computer
2007-11-23 14:03:29 0 d-------- C:\Program Files\Samsung
2007-11-20 08:04:07 0 d-------- C:\Program Files\Picasa2
2007-11-18 22:24:34 2746 --a------ C:\WINDOWS\O
2007-11-18 22:24:34 1636 --a------ C:\WINDOWS\?
2007-11-18 22:24:33 550 --a------ C:\WINDOWS\6
2007-11-18 22:24:33 67 --a------ C:\WINDOWS\°
2007-11-17 17:25:09 0 d-------- C:\Program Files\r2 Studios
2007-10-29 11:09:06 2377 --a------ C:\WINDOWS\n
2007-10-29 11:09:06 35 --a------ C:\WINDOWS\m
2007-10-29 11:09:06 4442 --a------ C:\WINDOWS\e
2007-10-29 11:09:06 2105 --a------ C:\WINDOWS\d
2007-10-24 18:58:08 73216 --a------ C:\WINDOWS\ST6UNST.EXE <Not Verified; Microsoft Corporation; Microsoft® Visual Basic for Windows>
2007-10-23 20:40:15 2980 --a------ C:\WINDOWS\0
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SystemTray"="SysTray.Exe" [07/12/99 12:00 C:\WINDOWS\SYSTEM32\systray.exe]
"Synchronization Manager"="mobsync.exe" [19/06/03 19:05 C:\WINDOWS\SYSTEM32\mobsync.exe]
"TPP Auto Loader"="C:\WINDOWS\TPPALDR.EXE" [22/08/01 14:29 ]
"SpeedTouch USB Diagnostics"="C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" [26/01/04 10:38 ]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [04/12/07 13:00 ]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"^SetupICWDesktop"=C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"internat.exe"=internat.exe
"Spyware Doctor"="C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
"Picasa Media Detector"=C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Documents and Settings\Keith\Start Menu\Programs\Startup\
SpywareGuard.lnk - C:\Program Files\SpywareGuard\sgmain.exe [29/08/2003 19:05:35]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoActiveDesktop"=0 (0x0)
"NoActiveDesktopChanges"=0 (0x0)
"NoInternetIcon"=0 (0x0)
"NoDesktop"=0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoActiveDesktop"=0 (0x0)
"NoActiveDesktopChanges"=0 (0x0)
"NoInternetIcon"=0 (0x0)
"NoDesktop"=0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sglfb.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\tga.sys]
@="Driver"
-- Hosts -----------------------------------------------------------------------
127.0.0.1 i.i.com.com
-- End of Deckard's System Scanner: finished at 2008-01-13 18:35:15 ------------