Thanks for the quick response! Heres the log file from ComboFix: ComboFix 09-03-19.01 - adam 2009-03-20 14:27:22.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.489 [GMT 0:00] Running from: c:\documents and settings\adam\My Documents\Downloads\ComboFix.exe AV: ESET NOD32 Antivirus 3.0 *On-access scanning disabled* (Updated) * Created a new restore point . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\documents and settings\adam\Local Settings\Application Data\aucisqy.dat c:\documents and settings\adam\Local Settings\Application Data\aucisqy.exe c:\documents and settings\adam\Local Settings\Application Data\aucisqy_nav.dat c:\documents and settings\adam\Local Settings\Application Data\aucisqy_navps.dat c:\windows\Tasks\rkamfwlk.job . ((((((((((((((((((((((((( Files Created from 2009-02-20 to 2009-03-20 ))))))))))))))))))))))))))))))) . 2009-03-20 14:02 . 2009-03-20 14:14 <DIR> d-------- c:\program files\Galaxy Online 2009-03-18 10:23 . 2009-03-20 14:19 <DIR> d-------- c:\program files\Mozilla Firefox 3.1 Beta 3 2009-03-13 10:51 . 2009-03-13 10:45 15,688 --a------ c:\windows\system32\lsdelete.exe 2009-03-13 10:45 . 2009-03-13 10:45 64,160 --a------ c:\windows\system32\drivers\Lbd.sys 2009-03-13 10:44 . 2009-03-13 10:44 <DIR> d--h-c--- c:\documents and settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800} 2009-03-13 10:43 . 2009-03-13 10:43 <DIR> d-------- c:\program files\Lavasoft 2009-03-11 10:43 . 2009-03-11 10:43 <DIR> d-------- c:\program files\Java 2009-03-11 10:43 . 2009-03-11 10:43 73,728 --a------ c:\windows\system32\javacpl.cpl 2009-02-25 16:18 . 2007-03-10 14:22 549,888 --a------ c:\windows\TheMatrix.scr 2009-02-25 16:18 . 2009-02-25 16:21 276 --a------ c:\windows\TheMatrix.ini . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-03-20 14:27 --------- d-----w c:\documents and settings\All Users\Application Data\Kontiki 2009-03-20 13:47 --------- d-----w c:\documents and settings\All Users\Application Data\Google Updater 2009-03-13 10:43 --------- d-----w c:\documents and settings\All Users\Application Data\Lavasoft 2009-03-11 10:43 410,984 ----a-w c:\windows\system32\deploytk.dll 2009-03-09 11:05 --------- d-----w c:\program files\Malwarebytes' Anti-Malware 2009-03-03 10:12 --------- d-----w c:\program files\Common Files\Blizzard Entertainment 2009-02-24 15:28 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP 2009-02-13 09:48 --------- d-----w c:\program files\Google 2009-02-11 10:19 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys 2009-02-11 10:19 15,504 ----a-w c:\windows\system32\drivers\mbam.sys 2009-02-10 17:53 --------- d-----w c:\program files\Dell_HostCD 2009-02-10 10:59 48,657 ----a-w c:\documents and settings\adam\Application Data\upd.exe 2009-02-09 15:16 --------- d-----w c:\documents and settings\adam\Application Data\Windows Search 2009-02-09 14:26 --------- d-----w c:\documents and settings\adam\Application Data\Malwarebytes 2009-02-09 14:26 --------- d-----w c:\documents and settings\adam\Application Data\DivX 2009-02-09 14:26 --------- d-----w c:\documents and settings\adam\Application Data\Apple Computer 2009-02-09 13:04 --------- d-----w c:\documents and settings\All Users\Application Data\2DBoy 2009-02-06 18:52 49,504 ----a-w c:\windows\system32\sirenacm.dll 2009-01-21 17:46 --------- d-----w c:\program files\CCleaner . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360] "MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-02-06 3885408] "kdx"="c:\program files\Kontiki\KHost.exe" [2008-10-21 1032640] "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2004-08-02 4493312] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 39792] "kdx"="c:\program files\Kontiki\KHost.exe" [2008-10-21 1032640] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696] "egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-10-24 1451264] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-11 148888] "Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-03-13 515416] "nwiz"="nwiz.exe" [2004-08-02 c:\windows\system32\nwiz.exe] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-05-26 123904] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=xwhuog.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service] @="Service" [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\drivers\\svchost.exe"= "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-03-13 64160] R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2008-10-24 34824] R2 ekrn;Eset Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2008-10-24 468224] R3 hcw88rc5;Hauppauge WinTV 88x IR Decoder;c:\windows\system32\drivers\hcw88rc5.sys [2007-01-24 11776] R3 HCW88TUNE;Hauppauge WinTV 88x Tuner;c:\windows\system32\drivers\hcw88tun.sys [2007-01-24 149504] R3 hcw88vid;Hauppauge WinTV 88x Video;c:\windows\system32\drivers\hcw88vid.sys [2007-01-24 498176] R3 HCW88XBAR;Hauppauge WinTV 88x Crossbar;c:\windows\system32\drivers\hcw88bar.sys [2007-01-24 23552] S2 gupdate1c98ae18760ccb4;Google Update Service (gupdate1c98ae18760ccb4);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-09 133104] S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-01-18 951632] . Contents of the 'Scheduled Tasks' folder 2009-03-20 c:\windows\Tasks\Ad-Aware Update (Weekly).job - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-13 10:45] 2008-12-04 c:\windows\Tasks\adam backup.job - c:\program files\AMUST\Registry Cleaner\RegCleaner.exe [2006-11-17 17:13] 2008-12-04 c:\windows\Tasks\adam scan and fix.job - c:\program files\AMUST\Registry Cleaner\RegCleaner.exe [2006-11-17 17:13] 2009-03-20 c:\windows\Tasks\Google Software Updater.job - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-02-09 18:08] 2009-03-20 c:\windows\Tasks\GoogleUpdateTaskMachine.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-02-09 18:09] . - - - - ORPHANS REMOVED - - - - HKCU-Run-aucisqy - c:\documents and settings\adam\local settings\application data\aucisqy.exe . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.co.uk/ IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 TCP: {75D3DDF2-0099-428C-9B52-5D1410ABB3A1} = 212.103.224.51,192.168.3.42 DPF: {BDEE1959-AB6B-4745-A29B-F492861102CC} FF - ProfilePath - c:\documents and settings\adam\Application Data\Mozilla\Firefox\Profiles\7nwd0v1e.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk FF - plugin: c:\program files\Google\Google Updater\2.4.1487.6512\npCIDetect13.dll FF - plugin: c:\program files\Google\Update\1.2.141.5\npGoogleOneClick7.dll ---- FIREFOX POLICIES ---- FF - user.js: yahoo.homepage.dontask - truec:\program files\Mozilla Firefox 3.1 Beta 3\greprefs\all.js - pref("media.enforce_same_site_origin", false); c:\program files\Mozilla Firefox 3.1 Beta 3\greprefs\all.js - pref("media.ogg.enabled", true); c:\program files\Mozilla Firefox 3.1 Beta 3\greprefs\all.js - pref("media.wave.enabled", true); c:\program files\Mozilla Firefox 3.1 Beta 3\greprefs\all.js - pref("media.autoplay.enabled", true); c:\program files\Mozilla Firefox 3.1 Beta 3\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true); c:\program files\Mozilla Firefox 3.1 Beta 3\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess"); c:\program files\Mozilla Firefox 3.1 Beta 3\greprefs\all.js - pref("network.http.prompt-temp-redirect", true); c:\program files\Mozilla Firefox 3.1 Beta 3\greprefs\all.js - pref("network.tcp.sendbuffer", 131072); c:\program files\Mozilla Firefox 3.1 Beta 3\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2); c:\program files\Mozilla Firefox 3.1 Beta 3\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~"); c:\program files\Mozilla Firefox 3.1 Beta 3\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0); c:\program files\Mozilla Firefox 3.1 Beta 3\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2); c:\program files\Mozilla Firefox 3.1 Beta 3\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror"); c:\program files\Mozilla Firefox 3.1 Beta 3\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false); c:\program files\Mozilla Firefox 3.1 Beta 3\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false); . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-03-20 14:28:30 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2009-03-20 14:29:51 ComboFix-quarantined-files.txt 2009-03-20 14:29:49 Pre-Run: 18,474,000,384 bytes free Post-Run: 18,674,642,944 bytes free WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect 159 --- E O F --- 2009-01-05 09:49:02 Thanks for your help!