Okay thanks very much for your help so far. Here are the results of the three scans:
Ewido
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 20:55:49 12/11/2006
+ Scan result:
C:\System Volume Information\_restore{4D4036DA-56F9-4764-B436-5E0655F40C05}\RP128\A0025409.exe -> Adware.180Solutions : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{4D4036DA-56F9-4764-B436-5E0655F40C05}\RP57\A0020376.exe/ACM.dll -> Adware.SaveNow : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{4D4036DA-56F9-4764-B436-5E0655F40C05}\RP57\A0020376.exe/Save.exe -> Adware.SaveNow : Cleaned with backup (quarantined).
C:\Program Files\Common Files\{38E71C59-096B-2057-1019-05060606002c}\MyToolBar.dll -> Adware.Softomate : Cleaned with backup (quarantined).
C:\Program Files\Common Files\{A8E71C59-096B-2057-1019-05060606002c}\Update.exe -> Adware.Softomate : Cleaned with backup (quarantined).
C:\Program Files\Common Files\{A8E71C59-096B-2057-1019-05060606002c}\services.dll -> Adware.Softomate : Cleaned with backup (quarantined).
C:\Program Files\Common Files\Yazzle1162OinAdmin.exe -> Downloader.PurityScan.dc : Cleaned with backup (quarantined).
C:\Program Files\Common Files\Αdobe\wuauclt.exe -> Downloader.PurityScan.dt : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{4D4036DA-56F9-4764-B436-5E0655F40C05}\RP123\A0024219.exe -> Downloader.Zlob.aes : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{4D4036DA-56F9-4764-B436-5E0655F40C05}\RP120\A0022958.exe -> Downloader.Zlob.auw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{4D4036DA-56F9-4764-B436-5E0655F40C05}\RP122\A0023207.exe -> Downloader.Zlob.auw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{4D4036DA-56F9-4764-B436-5E0655F40C05}\RP123\A0024207.exe -> Downloader.Zlob.auw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{4D4036DA-56F9-4764-B436-5E0655F40C05}\RP123\A0024218.exe -> Downloader.Zlob.auw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{4D4036DA-56F9-4764-B436-5E0655F40C05}\RP124\A0024257.exe -> Downloader.Zlob.auw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{4D4036DA-56F9-4764-B436-5E0655F40C05}\RP57\A0020412.exe -> Dropper.Agent.asf : Cleaned with backup (quarantined).
C:\Program Files\Common Files\Yazzle1122OinAdmin.exe -> Dropper.Small : Cleaned with backup (quarantined).
C:\WINDOWS\system32\drvroj.dll -> Not-A-Virus.Hoax.Win32.Renos.ge : Cleaned with backup (quarantined).
C:\Documents and Settings\Steph\Cookies\steph@247realmedia[1].txt -> TrackingCookie.247realmedia : Cleaned.
C:\Documents and Settings\Steph\Cookies\steph@2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Steph\Cookies\steph@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Steph\Cookies\steph@paypal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Steph\Cookies\steph@7search[2].txt -> TrackingCookie.7search : Cleaned.
C:\Documents and Settings\Steph\Cookies\steph@adrevolver[3].txt -> TrackingCookie.Adrevolver : Cleaned.
C:\Documents and Settings\Steph\Cookies\steph@adtech[2].txt -> TrackingCookie.Adtech : Cleaned.
C:\Documents and Settings\Steph\Cookies\steph@advertising[1].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\Steph\Cookies\steph@adviva[2].txt -> TrackingCookie.Adviva : Cleaned.
C:\Documents and Settings\Steph\Cookies\steph@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Steph\Cookies\steph@bluestreak[2].txt -> TrackingCookie.Bluestreak : Cleaned.
C:\Documents and Settings\Steph\Cookies\steph@www.burstnet[1].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Steph\Cookies\steph@casalemedia[2].txt -> TrackingCookie.Casalemedia : Cleaned.
C:\Documents and Settings\Steph\Cookies\steph@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Steph\Cookies\steph@e-2dj6wjlooiazcao.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Steph\Cookies\steph@e-2dj6wjmiogcpsfq.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Steph\Cookies\steph@e-2dj6wjny-1od5kf.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Steph\Cookies\steph@e-2dj6wjnyojcpgap.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Steph\Cookies\steph@e-2dj6wjnyskczclp.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Steph\Cookies\steph@adopt.euroclick[1].txt -> TrackingCookie.Euroclick : Cleaned.
C:\Documents and Settings\Steph\Cookies\steph@as-us.falkag[1].txt -> TrackingCookie.Falkag : Cleaned.
C:\Documents and Settings\Steph\Cookies\steph@fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\Steph\Cookies\steph@findwhat[1].txt -> TrackingCookie.Findwhat : Cleaned.
C:\Documents and Settings\Steph\Cookies\steph@ehg-techtarget.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Steph\Cookies\steph@ehg-thanedirect.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Steph\Cookies\steph@hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Steph\Cookies\steph@hotlog[1].txt -> TrackingCookie.Hotlog : Cleaned.
C:\Documents and Settings\Steph\Cookies\steph@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\Steph\Cookies\steph@data2.perf.overture[2].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Steph\Cookies\steph@overture[2].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Steph\Cookies\steph@perf.overture[1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Steph\Cookies\steph@ads.pointroll[1].txt -> TrackingCookie.Pointroll : Cleaned.
C:\Documents and Settings\Steph\Cookies\steph@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\Steph\Cookies\steph@edge.ru4[2].txt -> TrackingCookie.Ru4 : Cleaned.
C:\Documents and Settings\Steph\Cookies\steph@bs.serving-sys[2].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\Steph\Cookies\steph@serving-sys[2].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\Steph\Cookies\steph@spylog[2].txt -> TrackingCookie.Spylog : Cleaned.
C:\Documents and Settings\Steph\Cookies\steph@statcounter[1].txt -> TrackingCookie.Statcounter : Cleaned.
C:\Documents and Settings\Steph\Cookies\steph@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Steph\Cookies\steph@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : Cleaned.
C:\Documents and Settings\Steph\Cookies\steph@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Documents and Settings\Steph\Cookies\steph@reduxads.valuead[2].txt -> TrackingCookie.Valuead : Cleaned.
C:\Documents and Settings\Steph\Cookies\steph@statse.webtrendslive[1].txt -> TrackingCookie.Webtrendslive : Cleaned.
C:\Documents and Settings\Steph\Cookies\steph@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Steph\Cookies\steph@zedo[1].txt -> TrackingCookie.Zedo : Cleaned.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run\\kernel32.dll -> Trojan.Small : Cleaned with backup (quarantined).
::Report end
Panda
Incident Status Location
Adware:adware/savenow Not disinfected Windows Registry
Adware:adware/pornmagpass Not disinfected Windows Registry
Adware:adware/systemdoctor Not disinfected Windows Registry
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Steph\Cookies\steph@adrevolver[1].txt
Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\Steph\Cookies\steph@apmebf[1].txt
Spyware:Cookie/Humanclick Not disinfected C:\Documents and Settings\Steph\Cookies\steph@hc2.humanclick[1].txt
Spyware:Cookie/Malwarewipe Not disinfected C:\Documents and Settings\Steph\Cookies\steph@malwarewipe[1].txt
Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\Steph\Cookies\steph@maxserving[1].txt
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Steph\Cookies\steph@realmedia[1].txt
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Steph\Cookies\steph@statcounter[1].txt
Spyware:Cookie/Virusbursters Not disinfected C:\Documents and Settings\Steph\Cookies\steph@www.virusbursters[2].txt
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Steph\Desktop\SmitfraudFix\Process.exe
Possible Virus. Not disinfected C:\Documents and Settings\Steph\Desktop\SmitfraudFix\swsc.exe
Adware:Adware/YazzleSudoku Not disinfected C:\Program Files\Common Files\Yazzle1122OinUninstaller.exe
Adware:Adware/Yazzle Not disinfected C:\Program Files\Common Files\Yazzle1162OinUninstaller.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\WINDOWS\system32\Process.exe
Possible Virus. Not disinfected C:\WINDOWS\system32\swsc.exe
hijackthis
Logfile of HijackThis v1.99.1
Scan saved at 21:24:44, on 12/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\Program Files\VDOTool\TBPanel.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\iTunes\iTunes.exe
C:\Program Files\Last.fm\LastFM.exe
C:\Program Files\BSHOOTER.com\BubbleSD\bshooter.exe
C:\Program Files\BSHOOTER.com\BubbleSD\bshooter.exe
C:\Program Files\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.co.uk/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.co.uk
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {39f25b12-74ff-4079-a51f-1d70f5b08b84} - C:\WINDOWS\system32\ixt0.dll (file missing)
O2 - BHO: (no name) - {582ACF8E-599C-A59F-51ED-022A4C625B92} - C:\WINDOWS\system32\cebhyyc.dll
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [RemHelp] remhelp.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [Gainward] C:\Program Files\VDOTool\TBPanel.exe /A
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00000000-0000-0000-0000-100005000004} -
http://code.trasferimento.biz/l/d682873cb760d5ecc3c21b0562ac534d_2065.exe
O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) -
https://signup.msn.com/pages/MsnInstC.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {DBA8E419-0D5F-439B-A3CC-D01C768D9B51} (DVCDownloaderControl Object) -
http://www.sonypictures.com/games/thedavincicode/DVCDownloaderControl.cab
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetup Control) -
https://www.myweatherford.com/dana-cached/setup/JuniperSetup.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winzzd32 - C:\WINDOWS\SYSTEM32\winzzd32.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe