Hi, I'm new at this, so hope I'm in the right place.
have run all the scans as instructed.
logLogfile of HijackThis v1.99.1
Scan saved at 11:21:20 a.m., on 6/01/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAIP.EXE
C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\PBitDefender Online Scanner - Real Time Virus Report
Generated at: Sat, Jan 06, 2007 - 08:41:05
________________________________________
Scan Info
Scanned Files 766295
Infected Files 2
Virus Detected
MemScan:Trojan.Downloader.ConHook.J 1
Trojan.Downloader.Winfixer.O 1
rog
Application Version : 3.4.1000
Core Rules Database Version : 3159
Trace Rules Database Version: 1172
Scan type : Complete Scan
Total Scan Time : 00:33:57
Memory items scanned : 369
Memory threats detected : 2
Registry items scanned : 5851
Registry threats detected : 6
File items scanned : 34703
File threats detected : 141
Trojan.Downloader-AutoAff
C:\WINDOWS\SYSTEM32\FCCDAAW.DLL
C:\WINDOWS\SYSTEM32\FCCDAAW.DLL
Unclassified.Unknown Origin/System
C:\WINDOWS\SYSTEM32\LGBPD.EXE
C:\WINDOWS\SYSTEM32\LGBPD.EXE
[LGBLiveUpdate] C:\WINDOWS\SYSTEM32\LGBPD.EXE
C:\WINDOWS\SYSTEM32\SLIMMXGC.EXE
HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\timerp.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\timerp.exe#Path
C:\SYSTEM VOLUME INFORMATION\_RESTORE{F7B1EC78-8A36-4E24-A337-2D10D7E143F7}\RP249\A0061193.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{F7B1EC78-8A36-4E24-A337-2D10D7E143F7}\RP251\A0061286.EXE
C:\WINDOWS\SYSTEM32\LGB\LGBPD.EXE
C:\WINDOWS\Prefetch\LGBPD.EXE-10CD9875.pf
Adware.BusMaster/SafeSurfing
C:\WINDOWS\SYSTEM32\TCBLGWSG.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\CommA
HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\CommA#Path
C:\SYSTEM VOLUME INFORMATION\_RESTORE{F7B1EC78-8A36-4E24-A337-2D10D7E143F7}\RP249\A0061198.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{F7B1EC78-8A36-4E24-A337-2D10D7E143F7}\RP251\A0061291.DLL
Adware.Tracking Cookie
C:\Documents and Settings\Administrator\Cookies\administrator@i.screensavers[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@atdmt[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@partypoker[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@www.rowise[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@ads.cdfreaks[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@try.screensavers[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@xiti[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@windows.serialz[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@mb[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@ads.searchextreme[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@adbrite[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@serialz[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@data2.perf.overture[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@kanoodle[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@pcbannerhost[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@1071830256[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@dp[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@yadro[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@optimost[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@888[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@downloads.serialz[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@m1.webstats4u[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@43836137[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@cassava[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@warlog[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@cgi-bin[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@creative.paypopup[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@cgi-bin[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@adv.entercasino[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@1067983230[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@ads.xtramsn.co[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@adultmediashop[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@crackserver[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@a.websponsors[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@indextools[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@h.starware[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@burstnet[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@ad[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@screensavers[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@amlocalhost.trymedia[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@ad1.clickhype[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@ads.mininova[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@mt[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@r-kimedia.co[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@mediaonenetwork[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@counter.plugin[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@keywordmax[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@adinterax[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@www.burstnet[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@ad.yieldmanager[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@usenext[3].txt
C:\Documents and Settings\Administrator\Cookies\administrator@mb[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@toplist.bitcomet[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@680784[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@sales.liveperson[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@www.adtrak[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@ads.sharereactor[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@3889204[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@acvs.mediaonenetwork[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@image.checkmystats.com[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@ads.us.e-planning[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@ilead.itrack[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@roiservice[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@adsrevenue[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@1064535546[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@ads.i-am-bored[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@adlog.cdfreaks[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@xxxhotvideos[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@drivecleaner[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@www.webforsex[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@ads.planetactive[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@ad.zanox[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@1068674416[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@1072701528[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@1070176844[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@ads.azbilliards[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@1070748332[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@entrepreneur[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@shop.sex.co[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@stats1.reliablestats[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@atwola[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@www.drivecleaner[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@nextag[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@ads.stileproject[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@1070754780[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@rotator.adjuggler[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@stats.drivecleaner[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@www.belstat[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@1068107619[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@1070563868[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@netmediagroup[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@1071927725[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@mediaplex[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@reference[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@toplist[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@ats[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@intaclick[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@1071226142[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@www.precisioncounter[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@tacoda[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@1069965519[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@1072697200[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@tracker.mediatracker.co[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@www.w3counter[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@ads.gamershell[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@1071930148[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@usenext[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@search.crackserver[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@1071241275[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@1071893604[1].txt
Adware.AdStart
HKLM\Software\Microsoft\Windows\CurrentVersion\Run#adstart [ C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\system32\br_rt.dll" DllVerify ]
Adware.Mirar/NetNucleus
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\TEMP\MITCC.TMP
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\TEMP\MITCC.TMP.CAB
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\TEMP\NNBAR_VCSETUP_876088_LOG.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{F7B1EC78-8A36-4E24-A337-2D10D7E143F7}\RP249\A0061197.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{F7B1EC78-8A36-4E24-A337-2D10D7E143F7}\RP251\A0061290.EXE
C:\WINDOWS\MIRAR_DISTRO_876088.EXE
C:\WINDOWS\Prefetch\MIRAR_DISTRO_876088.EXE-29B9F657.pf
Adware.Toolbar888
C:\PROGRAM FILES\COMMON FILES\{340BADF3-06D5-1033-0722-040614050040}\BAR888.DLL
Trojan.SearchTool
C:\SYSTEM VOLUME INFORMATION\_RESTORE{F7B1EC78-8A36-4E24-A337-2D10D7E143F7}\RP247\A0061096.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{F7B1EC78-8A36-4E24-A337-2D10D7E143F7}\RP247\A0061097.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{F7B1EC78-8A36-4E24-A337-2D10D7E143F7}\RP248\A0061140.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{F7B1EC78-8A36-4E24-A337-2D10D7E143F7}\RP249\A0061179.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{F7B1EC78-8A36-4E24-A337-2D10D7E143F7}\RP249\A0061194.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{F7B1EC78-8A36-4E24-A337-2D10D7E143F7}\RP250\A0061242.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{F7B1EC78-8A36-4E24-A337-2D10D7E143F7}\RP251\A0061272.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{F7B1EC78-8A36-4E24-A337-2D10D7E143F7}\RP251\A0061287.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{F7B1EC78-8A36-4E24-A337-2D10D7E143F7}\RP252\A0061335.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{F7B1EC78-8A36-4E24-A337-2D10D7E143F7}\RP253\A0061365.DLL
C:\WINDOWS\SYSTEM32\SEARCHTOOL\NSEBA.DLL
C:\WINDOWS\SYSTEM32\SMARTSHOPPER\SMARTSHOPPER0.DLL
Worm.Rbot Variant
C:\WINDOWS\SYSTEM32\TASKWIZ.EXEram Files\Symantec\Norton Ghost 2003\GSUPERAntiSpyware Scan Log
Generated 01/06/2007 at 09:36 AM
Application Version : 3.4.1000
Core Rules Database Version : 3159
Trace Rules Database Version: 1172
Scan type : Complete Scan
Total Scan Time : 00:33:57
Memory items scanned : 369
Memory threats detected : 2
Registry items scanned : 5851
Registry threats detected : 6
File items scanned : 34703
File threats detected : 141
Trojan.Downloader-AutoAff
C:\WINDOWS\SYSTEM32\FCCDAAW.DLL
C:\WINDOWS\SYSTEM32\FCCDAAW.DLL
Unclassified.Unknown Origin/System
C:\WINDOWS\SYSTEM32\LGBPD.EXE
C:\WINDOWS\SYSTEM32\LGBPD.EXE
[LGBLiveUpdate] C:\WINDOWS\SYSTEM32\LGBPD.EXE
C:\WINDOWS\SYSTEM32\SLIMMXGC.EXE
HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\timerp.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\timerp.exe#Path
C:\SYSTEM VOLUME INFORMATION\_RESTORE{F7B1EC78-8A36-4E24-A337-2D10D7E143F7}\RP249\A0061193.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{F7B1EC78-8A36-4E24-A337-2D10D7E143F7}\RP251\A0061286.EXE
C:\WINDOWS\SYSTEM32\LGB\LGBPD.EXE
C:\WINDOWS\Prefetch\LGBPD.EXE-10CD9875.pfhostStartService.exes below
Hope this is right and someone can help.
Thanks very much
cheers Phil