Hi, sorry i took so long. I restarted Window xp in safe mode and ran Malwarebytes. Here is the log.
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.orgDatabase version: 4897
Windows 5.1.2600 Service Pack 3 (Safe Mode)
Internet Explorer 8.0.6001.18702
20/10/2010 9:01:57 PM
mbam-log-2010-10-20 (21-01-57).txt
Scan type: Full scan (C:\|)
Objects scanned: 251258
Time elapsed: 43 minute(s), 34 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 2
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 10
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{9f44453e-1e46-4d5c-b57c-112ff2edae82} (Spyware.OnlineGames) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\qvodplayer (Adware.Agent) -> No action taken.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\{0651900a-e0d7-82f7-c0cb-aee22db5dfa1} (Trojan.ZbotR.Gen) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\registrymonitor2 (Malware.Trace) -> No action taken.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -> Data: c:\program files\microsoft\desktoplayer.exe -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.UserInit) -> Bad: (c:\windows\system32\userinit.exe,,c:\program files\microsoft\desktoplayer.exe) Good: (userinit.exe) -> No action taken.
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Program Files\QvodPlayer\QvodBand.dll (Spyware.OnlineGames) -> No action taken.
C:\Program Files\QvodPlayer\QvodUninst.exe (Adware.Agent) -> No action taken.
C:\System Volume Information\_restore{CC029D65-F456-449C-BF6D-EE7CD26572BC}\RP173\A0066021.exe (Adware.Casino) -> No action taken.
C:\System Volume Information\_restore{CC029D65-F456-449C-BF6D-EE7CD26572BC}\RP192\A0075515.exe (Adware.HotBar) -> No action taken.
C:\System Volume Information\_restore{CC029D65-F456-449C-BF6D-EE7CD26572BC}\RP211\A0103857.exe (Patch.NetworkMagic) -> No action taken.
C:\System Volume Information\_restore{CC029D65-F456-449C-BF6D-EE7CD26572BC}\RP211\A0103858.exe (Patch.NetworkMagic) -> No action taken.
C:\System Volume Information\_restore{CC029D65-F456-449C-BF6D-EE7CD26572BC}\RP236\A0144213.exe (Adware.Agent) -> No action taken.
C:\System Volume Information\_restore{CC029D65-F456-449C-BF6D-EE7CD26572BC}\RP236\A0147670.exe (Adware.Agent) -> No action taken.
C:\Program Files\Microsoft\desktoplayer.exe (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\qtplugin.exe (Rootkit.Agent) -> No action taken.