Ok, here is the ComboFix log ~
ComboFix 10-05-09.06 - gemz 10/05/2010 12:27:36.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.510.108 [GMT 1:00]
Running from: c:\documents and settings\gemz\Desktop\Combo-Fix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: ZoneAlarm Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\TEMP\logishrd\LVPrcInj01.dll
.
((((((((((((((((((((((((( Files Created from 2010-04-10 to 2010-05-10 )))))))))))))))))))))))))))))))
.
2010-05-09 21:51 . 2010-05-09 21:51 -------- d-----w- c:\documents and settings\gemz\Application Data\AVG9
2010-05-04 21:49 . 2007-09-06 07:14 822400 ----a-w- c:\windows\system32\drivers\wn311b.sys
2010-04-28 12:11 . 2010-04-28 12:11 15944 ----a-w- c:\windows\system32\drivers\hitmanpro35.sys
2010-04-28 12:10 . 2010-04-28 12:10 -------- d-----w- c:\documents and settings\All Users\Application Data\Hitman Pro
2010-04-28 12:10 . 2010-04-28 12:10 -------- d-----w- c:\program files\Hitman Pro 3.5
2010-04-27 22:21 . 2010-04-27 22:21 -------- d-----w- c:\program files\Trend Micro
2010-04-27 16:04 . 2010-04-28 15:53 -------- d-----w- c:\program files\Mozilla Developer Preview 3.7 Alpha 4
2010-04-10 18:29 . 2010-04-10 18:29 -------- d-----w- c:\program files\BBC iPlayer Desktop
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-10 11:36 . 2008-10-13 19:27 0 ----a-w- c:\windows\system32\drivers\lvuvc.hs
2010-05-10 11:36 . 2008-10-13 19:26 0 ----a-w- c:\windows\system32\drivers\logiflt.iad
2010-05-09 21:55 . 2007-10-15 21:24 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-05-09 15:06 . 2006-09-17 14:54 -------- d-----w- c:\program files\Messenger Plus! Live
2010-05-04 21:49 . 2005-11-28 22:23 -------- d-----w- c:\program files\NETGEAR
2010-05-04 21:49 . 2005-11-11 18:58 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-04-30 09:15 . 2007-08-10 19:54 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-04-28 12:28 . 2006-02-12 16:16 -------- d-----w- c:\program files\Lavasoft
2010-04-28 11:52 . 2010-03-03 23:28 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2010-04-28 11:50 . 2006-02-12 16:17 -------- d-----w- c:\documents and settings\gemz\Application Data\Lavasoft
2010-04-27 20:06 . 2007-11-24 13:33 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-04-20 20:55 . 2010-04-20 20:55 242696 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgtdix.sys
2010-04-20 20:53 . 2009-03-07 22:34 242896 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-04-20 20:44 . 2010-04-20 20:44 1689952 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgupd.dll
2010-04-09 19:02 . 2010-04-09 19:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2010-04-05 20:09 . 2008-12-01 23:59 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-04-01 23:04 . 2005-12-11 14:11 -------- d-----w- c:\program files\Google
2010-04-01 22:48 . 2005-11-11 19:03 -------- d-----w- c:\program files\Jasc Software Inc
2010-03-21 16:47 . 2010-03-21 16:47 -------- d-----w- c:\documents and settings\gemz\Application Data\Office Genuine Advantage
2010-03-13 11:07 . 2010-03-13 11:07 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2010-03-13 11:07 . 2007-02-18 22:34 29512 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-03-13 10:58 . 2008-07-03 19:53 216200 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-03-11 20:37 . 2005-11-11 18:54 -------- d-----w- c:\program files\Common Files\Java
2010-03-11 20:37 . 2010-03-11 20:37 503808 ----a-w- c:\documents and settings\gemz\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-77272cfd-n\msvcp71.dll
2010-03-11 20:37 . 2010-03-11 20:37 499712 ----a-w- c:\documents and settings\gemz\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-77272cfd-n\jmc.dll
2010-03-11 20:37 . 2010-03-11 20:37 348160 ----a-w- c:\documents and settings\gemz\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-77272cfd-n\msvcr71.dll
2010-03-11 20:36 . 2010-03-11 20:36 61440 ----a-w- c:\documents and settings\gemz\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-54cdfadf-n\decora-sse.dll
2010-03-11 20:36 . 2010-03-11 20:36 12800 ----a-w- c:\documents and settings\gemz\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-54cdfadf-n\decora-d3d.dll
2010-03-11 20:33 . 2005-11-11 18:54 -------- d-----w- c:\program files\Java
2010-03-10 08:02 . 2004-08-11 17:00 417792 ----a-w- c:\windows\system32\vbscript.dll
2010-03-03 23:37 . 2010-03-03 23:37 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-02-26 06:05 . 2004-08-11 17:00 668672 ----a-w- c:\windows\system32\wininet.dll
2010-02-26 06:05 . 2004-08-11 17:00 81920 ----a-w- c:\windows\system32\ieencode.dll
2010-02-24 12:31 . 2005-11-11 18:38 454016 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-21 21:06 . 2009-06-28 14:27 38784 ----a-w- c:\documents and settings\gemz\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-02-16 13:17 . 2004-08-11 17:00 2137088 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-02-16 12:39 . 2004-08-03 22:59 2016768 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-12 10:03 . 2010-03-01 19:04 293376 ------w- c:\windows\system32\browserchoice.exe
2010-02-12 04:47 . 2004-08-11 17:00 100864 ----a-w- c:\windows\system32\6to4svc.dll
2010-02-11 12:01 . 2004-08-11 17:00 226880 ----a-w- c:\windows\system32\drivers\tcpip6.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-07-26 3883856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SigmatelSysTrayApp"="stsystra.exe" [2005-03-23 339968]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-05 344064]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 53248]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"AS00_Netgear"="c:\program files\NETGEAR\Wireless Smart Configuration\Utility\NetgearAG.exe" [2003-05-16 389120]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 241664]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb10.exe" [2004-03-04 172032]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2008-02-13 564496]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-02-13 2196240]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2009-02-16 981384]
"SunJavaUpdateSched"="c:\program files\Java\j2re1.4.2_03\bin\jusched.exe" [2003-11-19 32881]
"AS00_WN311B"="c:\program files\NETGEAR\WN311B\Utility\WN311B.exe" [2008-09-17 3002368]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
c:\documents and settings\gemz\Start Menu\Programs\Startup\
BBC iPlayer Desktop.lnk - c:\program files\BBC iPlayer Desktop\BBC iPlayer Desktop.exe [2010-4-10 95232]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2006-12-28 528384]
MediaChecker.lnk - c:\program files\HOTALBUMMyBOX\MediaChecker.exe [2007-11-30 915096]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 14:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-03-13 11:07 12464 ----a-w- c:\windows\system32\avgrsstx.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Photosmart Premier Fast Start.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Photosmart Premier Fast Start.lnk
backup=c:\windows\pss\HP Photosmart Premier Fast Start.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2005-02-16 23:11 49152 ----a-w- c:\program files\Hewlett-Packard\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2005-11-11 19:01 98304 ----a-w- c:\program files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
2005-11-11 19:00 26112 ----a-w- c:\program files\Real\RealPlayer\realplay.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
2005-10-26 15:17 159744 ----a-r- c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
2010-04-30 09:15 2020592 ----a-w- c:\program files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
R0 PzWDM;PzWDM;c:\windows\system32\drivers\PzWDM.sys [06/10/2008 20:27 15172]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [03/07/2008 20:53 216200]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [07/03/2009 23:34 242896]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [17/02/2010 11:25 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [17/02/2010 11:15 61440]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [13/03/2010 12:07 308064]
R3 AWINDIS5;AWINDIS5 Protocol Driver;c:\windows\system32\AWINDIS5.SYS [28/11/2005 23:23 16194]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [07/01/2010 23:02 135664]
S3 NETGEAR_WG311_SERVICE;NETGEAR WG311 Wireless PCI Adapter Service;c:\windows\system32\drivers\wg311nd5.sys [28/11/2005 23:23 307904]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [17/02/2010 11:15 12872]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contents of the 'Scheduled Tasks' folder
2010-05-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-07 22:02]
2010-05-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-07 22:02]
2010-05-10 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 15:07]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.google.co.uk/uSearchMigratedDefaultURL =
hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext =
https://loginnet.passport.com/ppsecure/ ... rf?lc=1033uSearchURL,(Default) =
hxxp://www.google.com/keyword/%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000
DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} -
hxxps://secure.gopetslive.com/dev/GoPetsWeb.cabFF - ProfilePath - c:\documents and settings\gemz\Application Data\Mozilla\Firefox\Profiles\yleriqnk.default\
FF - prefs.js: browser.startup.homepage -
hxxp://www.facebook.com/login.phpFF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-05-10 12:38
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(684)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
- - - - - - - > 'explorer.exe'(6080)
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\windows\system32\HPZipm12.exe
c:\windows\stsystra.exe
c:\program files\Common Files\Logitech\KHAL\KHALMNPR.EXE
c:\program files\Common Files\Logishrd\LQCVFX\COCIManager.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
.
**************************************************************************
.
Completion time: 2010-05-10 12:48:37 - machine was rebooted
ComboFix-quarantined-files.txt 2010-05-10 11:48
ComboFix2.txt 2010-05-09 22:32
Pre-Run: 37,920,116,736 bytes free
Post-Run: 37,866,352,640 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - A57E9BF269FCB3E11A848E2210793C73
~~~~~~~~~~~~~~~~
Thanks for all your help

! The RUNDLL dialogue has now stopped and it's also resolved another two problems concerning a dial-up connection request and a really annoying browser re-directer

.
Unfortunately, she's still getting the other dialogue box, "Error - Information file not found". This seems to be linked to some mediachecker program which she messed up uninstalling called HOTALBUM (I think she couldn't find the uninstall and just deleted the folders). It came with her camera. It's not malicious. We ran HijackThis and ticked the box to remove it but it still re-appears in Startup. We can stop the dialogue box popping up by unticking it from Startup but we'd prefer to remove it if we can.
Edit: Duh! Spoke too soon. The dialler has returned. On boot the Dial Up Connection box comes up requesting dial up connection to MSN. She uses MSN but we're on cable. I may re-post this as a new topic as it's probably completely separate to these problems.