Here are the logs as requested. As for the computer, it is running pretty much the same way it did before the infection (slow to begin with since the desktop is pretty old but my grandpa doesn't seem to mind =D ).
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 下午 03:09:19, on 2009/9/7
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Linksys\WMP11 Config Utility\WMP11CFG.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Mozilla Firefox\firefox.exe
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DT LGE] C:\Program Files\Portrait Displays\forteManager\DTHtml.exe -startup_folder
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Portrait Displays Display Tune Service (DTSRVC) - Unknown owner - C:\Program Files\Portrait Displays\forteManager\dtsrvc.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O24 - Desktop Component 1: (no name) - http://www.diyzone.net/images2/room2441ui5.jpg
O24 - Desktop Component 2: (no name) - http://www.diyzone.net/images2/room2464cl0.jpg
O24 - Desktop Component 3: (no name) - http://www.audioreview.com/channels/audioreview/images/products/product_126027.jpg
O24 - Desktop Component 4: (no name) - http://pics1.blog.yam.com/2/userfile/h/hifihivi/album/1499a5d1135e85.jpg
O24 - Desktop Component 5: (no name) - http://www.diyzone.net/images2/room2462av1.jpg
O24 - Desktop Component 6: (no name) - http://g.udn.com/community/img/style142/bg.jpg
--
End of file - 4722 bytes
SystemLook v1.0 by jpshortstuff (29.08.09)
Log created at 15:08 on 07/09/2009 by Administrator (Administrator - Elevation successful)
========== dir ==========
C:\_OTM - Parameters: "(none)"
---Files---
None found.
---Folders---
MovedFiles d----- [15:57 04/09/2009]
C:\Documents and Settings\All Users\Application Data\{F14A989E-0102-460B-ADB5-BC208314A307} - Parameters: "(none)"
---Files---
None found.
---Folders---
OFFLINE d----c [17:01 19/08/2009]
C:\WINDOWS\system32\images - Parameters: "(none)"
---Files---
i1.gif --a--- 1744 bytes [06:26 21/08/2009] [09:17 21/11/2008]
i2.gif --a--- 1663 bytes [06:26 21/08/2009] [09:17 21/11/2008]
i3.gif --a--- 1689 bytes [06:26 21/08/2009] [09:17 21/11/2008]
j1.gif --a--- 3957 bytes [06:26 21/08/2009] [09:12 21/11/2008]
j2.gif --a--- 47 bytes [06:26 21/08/2009] [09:12 21/11/2008]
j3.gif --a--- 3857 bytes [06:26 21/08/2009] [10:33 27/11/2008]
jj1.gif --a--- 114 bytes [06:26 21/08/2009] [09:14 21/11/2008]
jj2.gif --a--- 48 bytes [06:26 21/08/2009] [09:14 21/11/2008]
jj3.gif --a--- 105 bytes [06:26 21/08/2009] [09:40 21/11/2008]
l1.gif --a--- 3749 bytes [06:26 21/08/2009] [08:39 21/11/2008]
l2.gif --a--- 92 bytes [06:26 21/08/2009] [08:39 21/11/2008]
l3.gif --a--- 468 bytes [06:26 21/08/2009] [08:40 21/11/2008]
pix.gif --a--- 70 bytes [06:26 21/08/2009] [09:44 21/11/2008]
t1.gif --a--- 621 bytes [06:26 21/08/2009] [08:47 21/11/2008]
t2.gif --a--- 1015 bytes [06:26 21/08/2009] [09:17 21/11/2008]
up1.gif --a--- 5568 bytes [06:26 21/08/2009] [08:28 21/11/2008]
up2.gif --a--- 696 bytes [06:26 21/08/2009] [08:29 21/11/2008]
w1.gif --a--- 3028 bytes [06:26 21/08/2009] [08:56 21/11/2008]
w11.gif --a--- 3431 bytes [06:26 21/08/2009] [09:08 21/11/2008]
w2.gif --a--- 47 bytes [06:26 21/08/2009] [08:56 21/11/2008]
w3.gif --a--- 3430 bytes [06:26 21/08/2009] [10:30 27/11/2008]
w3.jpg --a--- 1912 bytes [06:26 21/08/2009] [10:34 27/11/2008]
wt1.gif --a--- 176 bytes [06:26 21/08/2009] [08:57 21/11/2008]
wt2.gif --a--- 51 bytes [06:26 21/08/2009] [08:57 21/11/2008]
wt3.gif --a--- 119 bytes [06:26 21/08/2009] [08:57 21/11/2008]
---Folders---
None found.
-=End Of File=-
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 下午 03:09:19, on 2009/9/7
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Linksys\WMP11 Config Utility\WMP11CFG.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Mozilla Firefox\firefox.exe
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DT LGE] C:\Program Files\Portrait Displays\forteManager\DTHtml.exe -startup_folder
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Portrait Displays Display Tune Service (DTSRVC) - Unknown owner - C:\Program Files\Portrait Displays\forteManager\dtsrvc.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O24 - Desktop Component 1: (no name) - http://www.diyzone.net/images2/room2441ui5.jpg
O24 - Desktop Component 2: (no name) - http://www.diyzone.net/images2/room2464cl0.jpg
O24 - Desktop Component 3: (no name) - http://www.audioreview.com/channels/audioreview/images/products/product_126027.jpg
O24 - Desktop Component 4: (no name) - http://pics1.blog.yam.com/2/userfile/h/hifihivi/album/1499a5d1135e85.jpg
O24 - Desktop Component 5: (no name) - http://www.diyzone.net/images2/room2462av1.jpg
O24 - Desktop Component 6: (no name) - http://g.udn.com/community/img/style142/bg.jpg
--
End of file - 4722 bytes
SystemLook v1.0 by jpshortstuff (29.08.09)
Log created at 15:08 on 07/09/2009 by Administrator (Administrator - Elevation successful)
========== dir ==========
C:\_OTM - Parameters: "(none)"
---Files---
None found.
---Folders---
MovedFiles d----- [15:57 04/09/2009]
C:\Documents and Settings\All Users\Application Data\{F14A989E-0102-460B-ADB5-BC208314A307} - Parameters: "(none)"
---Files---
None found.
---Folders---
OFFLINE d----c [17:01 19/08/2009]
C:\WINDOWS\system32\images - Parameters: "(none)"
---Files---
i1.gif --a--- 1744 bytes [06:26 21/08/2009] [09:17 21/11/2008]
i2.gif --a--- 1663 bytes [06:26 21/08/2009] [09:17 21/11/2008]
i3.gif --a--- 1689 bytes [06:26 21/08/2009] [09:17 21/11/2008]
j1.gif --a--- 3957 bytes [06:26 21/08/2009] [09:12 21/11/2008]
j2.gif --a--- 47 bytes [06:26 21/08/2009] [09:12 21/11/2008]
j3.gif --a--- 3857 bytes [06:26 21/08/2009] [10:33 27/11/2008]
jj1.gif --a--- 114 bytes [06:26 21/08/2009] [09:14 21/11/2008]
jj2.gif --a--- 48 bytes [06:26 21/08/2009] [09:14 21/11/2008]
jj3.gif --a--- 105 bytes [06:26 21/08/2009] [09:40 21/11/2008]
l1.gif --a--- 3749 bytes [06:26 21/08/2009] [08:39 21/11/2008]
l2.gif --a--- 92 bytes [06:26 21/08/2009] [08:39 21/11/2008]
l3.gif --a--- 468 bytes [06:26 21/08/2009] [08:40 21/11/2008]
pix.gif --a--- 70 bytes [06:26 21/08/2009] [09:44 21/11/2008]
t1.gif --a--- 621 bytes [06:26 21/08/2009] [08:47 21/11/2008]
t2.gif --a--- 1015 bytes [06:26 21/08/2009] [09:17 21/11/2008]
up1.gif --a--- 5568 bytes [06:26 21/08/2009] [08:28 21/11/2008]
up2.gif --a--- 696 bytes [06:26 21/08/2009] [08:29 21/11/2008]
w1.gif --a--- 3028 bytes [06:26 21/08/2009] [08:56 21/11/2008]
w11.gif --a--- 3431 bytes [06:26 21/08/2009] [09:08 21/11/2008]
w2.gif --a--- 47 bytes [06:26 21/08/2009] [08:56 21/11/2008]
w3.gif --a--- 3430 bytes [06:26 21/08/2009] [10:30 27/11/2008]
w3.jpg --a--- 1912 bytes [06:26 21/08/2009] [10:34 27/11/2008]
wt1.gif --a--- 176 bytes [06:26 21/08/2009] [08:57 21/11/2008]
wt2.gif --a--- 51 bytes [06:26 21/08/2009] [08:57 21/11/2008]
wt3.gif --a--- 119 bytes [06:26 21/08/2009] [08:57 21/11/2008]
---Folders---
None found.
-=End Of File=-



