The Sd log wasn't comlete, did you miss some, or was that it? You seeing any improvement yet?
Let's see if we can get some more.
Go to add/remove programs and uninstall, if present, the following
Microsoft Security Adviser
AntiVirusProOpen HJT, run a system scan only, check mark these lines if present
O2 - BHO: (no name) - {2F02D978-0FF6-80F7-60BB-0426224AB7B3} - C:\Program Files\toawbhfc\shtbfwba.dll (file missing)
O2 - BHO: (no name) - {F767A1F8-6BBC-4531-AEDD-DE9553D57000} - C:\WINDOWS\System32\credu.dll
O4 - HKLM\..\Run: [msctrl.exe] C:\Program Files\Microsoft Security Adviser\msctrl.exe
O4 - HKLM\..\Run: [msavsc.exe] C:\Program Files\Microsoft Security Adviser\msavsc.exe
O4 - HKLM\..\Run: [msscan.exe] C:\Program Files\Microsoft Security Adviser\msscan.exe
O4 - HKLM\..\Run: [msiemon.exe] C:\Program Files\Microsoft Security Adviser\msiemon.exe
O4 - HKLM\..\Run: [msfw.exe] C:\Program Files\Microsoft Security Adviser\msfw.exe
O4 - HKCU\..\Run: [msctrl.exe] C:\Program Files\Microsoft Security Adviser\msctrl.exe
O4 - HKCU\..\Run: [msavsc.exe] C:\Program Files\Microsoft Security Adviser\msavsc.exe
O4 - HKCU\..\Run: [msscan.exe] C:\Program Files\Microsoft Security Adviser\msscan.exe
O4 - HKCU\..\Run: [msiemon.exe] C:\Program Files\Microsoft Security Adviser\msiemon.exe
O4 - HKCU\..\Run: [msfw.exe] C:\Program Files\Microsoft Security Adviser\msfw.exe
O21 - SSODL: SrvAlrt - {abb85924-42b2-45a1-99d7-6776e8051568} - C:\WINDOWS\Installer\{abb85924-42b2-45a1-99d7-6776e8051568}\SrvAlrt.dll
O21 - SSODL: AvpPrx - {ac30c57f-c8fb-48f5-93fd-c9a6577e64f8} - C:\WINDOWS\Installer\{ac30c57f-c8fb-48f5-93fd-c9a6577e64f8}\AvpPrx.dll
O21 - SSODL: VolumeRam - {1d35c5dd-9f8f-49a2-8c04-4db84357e10d} - C:\WINDOWS\Installer\{1d35c5dd-9f8f-49a2-8c04-4db84357e10d}\VolumeRam.dll
O21 - SSODL: zip - {b1240015-2f58-49bc-9a93-0ef9ffec7ee9} - C:\WINDOWS\Installer\{b1240015-2f58-49bc-9a93-0ef9ffec7ee9}\zip.dll
O21 - SSODL: KbdPrx - {01ad806b-3219-4aa4-be5e-39c18911e809} - C:\WINDOWS\Installer\{01ad806b-3219-4aa4-be5e-39c18911e809}\KbdPrx.dll
O21 - SSODL: DrvMon - {65aa727e-edd2-4396-966d-3a05112b739f} - C:\WINDOWS\Installer\{65aa727e-edd2-4396-966d-3a05112b739f}\DrvMon.dll
O21 - SSODL: DbdPrx - {65aa727e-edd2-4396-966d-3a05112b739f} - C:\WINDOWS\Installer\{65aa727e-edd2-4396-966d-3a05112b739f}\DrvMon.dll Close all other browsers/windows, click fix, close HJT.
Open a new Notepad session (Do not use a Word Processor or WordPad). Click "Format" and be certain that Word Wrap is not enabled.
Copy and paste all the text in the quote box below into Notepad.
Click File, Save as..., and set the location to your Desktop, and enter (including quotation marks) as the filename: "CFscript.txt" . Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown at the bottom of this post.
File::
C:\WINDOWS\System32\credu.dll
C:\Program Files\Microsoft Security Adviser\msctrl.exe
C:\Program Files\Microsoft Security Adviser\msavsc.exe
C:\Program Files\Microsoft Security Adviser\msscan.exe
C:\Program Files\Microsoft Security Adviser\msiemon.exe
C:\Program Files\Microsoft Security Adviser\msfw.exe
C:\WINDOWS\Installer\{abb85924-42b2-45a1-99d7-6776e8051568}\SrvAlrt.dll
C:\WINDOWS\Installer\{ac30c57f-c8fb-48f5-93fd-c9a6577e64f8}\AvpPrx.dll
C:\WINDOWS\Installer\{1d35c5dd-9f8f-49a2-8c04-4db84357e10d}\VolumeRam.dll
C:\WINDOWS\Installer\{b1240015-2f58-49bc-9a93-0ef9ffec7ee9}\zip.dll
C:\WINDOWS\Installer\{01ad806b-3219-4aa4-be5e-39c18911e809}\KbdPrx.dll
C:\WINDOWS\Installer\{65aa727e-edd2-4396-966d-3a05112b739f}\DrvMon.dll
Folder::
C:\Documents and Settings\Owner\Application Data\Anti-Virus-Pro.com
C:\Program Files\AntiVirusPro
DirLook::
C:\Program Files\toawbhfc
This will start ComboFix again.
Close all browser/windows first. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HJT log.
Please submit these files for analysis
To submit a file to virustoal, please click om this link
www.virustotal.comcopy and paste the following into the upload a file box (one at a time if more than one file is listed)
C:\Program Files\tmp48125.exe
C:\Program Files\tmp48703.exe
C:\Program Files\tmp48687.exe
C:\Program Files\tmp46265.exe
C:\Program Files\tmp532265.exe scroll down a bit and click "send file", wait for the results and post then in your next reply.