OK: Renaming the executable worked and after running has allowed me to run Hijackthis also. Log files attached below. Combofix is a neat programme!!
Still some work to do i think as IE AVG and ZA still not working but this is a great start...
ComboFix 08-02-25.3 - Martin 2008-02-28 19:50:28.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.662 [GMT 0:00]
Running from: C:\Documents and Settings\Martin\Desktop\Combo-Fix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\drivers\down
C:\WINDOWS\system32\drivers\down\1041579734.exe
C:\WINDOWS\system32\drivers\down\1041584703.exe
C:\WINDOWS\system32\drivers\down\1041586046.exe
C:\WINDOWS\system32\drivers\down\1041587640.exe
C:\WINDOWS\system32\drivers\down\1041589640.exe
C:\WINDOWS\system32\drivers\down\1041608984.exe
C:\WINDOWS\system32\drivers\down\1041616531.exe
C:\WINDOWS\system32\drivers\down\1041618265.exe
C:\WINDOWS\system32\drivers\down\1041620062.exe
C:\WINDOWS\system32\drivers\down\1041622625.exe
C:\WINDOWS\system32\drivers\down\1041633093.exe
C:\WINDOWS\system32\drivers\down\1041635859.exe
C:\WINDOWS\system32\drivers\down\1041636218.exe
C:\WINDOWS\system32\drivers\down\1041639515.exe
C:\WINDOWS\system32\drivers\down\1041644546.exe
C:\WINDOWS\system32\drivers\down\1041646187.exe
C:\WINDOWS\system32\drivers\down\1041699671.exe
C:\WINDOWS\system32\drivers\down\155890.exe
C:\WINDOWS\system32\drivers\down\158875.exe
C:\WINDOWS\system32\drivers\down\160000.exe
C:\WINDOWS\system32\drivers\down\161640.exe
C:\WINDOWS\system32\drivers\down\165421.exe
C:\WINDOWS\system32\drivers\down\179437.exe
C:\WINDOWS\system32\drivers\down\182625.exe
C:\WINDOWS\system32\drivers\down\184203.exe
C:\WINDOWS\system32\drivers\down\186062.exe
C:\WINDOWS\system32\drivers\down\186500.exe
C:\WINDOWS\system32\drivers\down\204984.exe
C:\WINDOWS\system32\drivers\down\209937.exe
C:\WINDOWS\system32\drivers\down\210156.exe
C:\WINDOWS\system32\drivers\down\211765.exe
C:\WINDOWS\system32\drivers\down\213375.exe
C:\WINDOWS\system32\drivers\down\215750.exe
C:\WINDOWS\system32\drivers\down\217375.exe
C:\WINDOWS\system32\drivers\down\218875.exe
C:\WINDOWS\system32\drivers\down\220078.exe
C:\WINDOWS\system32\drivers\down\220546.exe
C:\WINDOWS\system32\drivers\down\222812.exe
C:\WINDOWS\system32\drivers\down\223203.exe
C:\WINDOWS\system32\drivers\down\225640.exe
C:\WINDOWS\system32\drivers\down\226875.exe
C:\WINDOWS\system32\drivers\down\228656.exe
C:\WINDOWS\system32\drivers\down\230250.exe
C:\WINDOWS\system32\drivers\down\231140.exe
C:\WINDOWS\system32\drivers\down\233687.exe
C:\WINDOWS\system32\drivers\down\234000.exe
C:\WINDOWS\system32\drivers\down\234296.exe
C:\WINDOWS\system32\drivers\down\236171.exe
C:\WINDOWS\system32\drivers\down\237750.exe
C:\WINDOWS\system32\drivers\down\270156.exe
C:\WINDOWS\system32\drivers\down\282187.exe
C:\WINDOWS\system32\drivers\hldrrr.exe
C:\WINDOWS\system32\drivers\srosa.sys
C:\WINDOWS\system32\mdelk.exe
C:\WINDOWS\system32\wintems.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_SROSA
-------\srosa
((((((((((((((((((((((((( Files Created from 2008-01-28 to 2008-02-28 )))))))))))))))))))))))))))))))
.
2008-02-28 08:02 . 2008-02-28 08:02 <DIR> d-------- C:\Program Files\Trend Micro
2008-02-28 02:13 . 2008-02-28 02:13 <DIR> d-------- C:\Program Files\Lavasoft
2008-02-28 02:13 . 2008-02-28 02:14 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-28 02:12 . 2008-02-28 02:12 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-02-04 00:17 . 2008-02-28 00:47 <DIR> d-------- C:\Program Files\Easy Video Joiner
2008-02-03 22:57 . 2008-02-04 00:16 <DIR> d-------- C:\Program Files\All Video Joiner
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-27 06:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg7
2008-02-24 18:22 --------- d-----w C:\Documents and Settings\Martin\Application Data\AVG7
2008-02-06 13:43 --------- d-----w C:\Documents and Settings\Martin\Application Data\uTorrent
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 16:24 1694208]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:56 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2005-11-11 06:07 90112 C:\WINDOWS\soundman.exe]
"Zone Labs Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-02-28 19:51 968696]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2008-02-28 19:51 579072]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-22 12:22 7700480]
"nwiz"="nwiz.exe" [2006-10-22 12:22 1622016 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="NvMCTray.dll" [2006-10-22 12:22 86016 C:\WINDOWS\system32\nvmctray.dll]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-01-22 02:36 185896]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 07:56 15360]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe" [2008-02-28 07:53 219136]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04 83360]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avgemc.exe"=
"G:\\Program Files\\Shareaza\\Shareaza.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
R1 nltdi;nltdi;C:\WINDOWS\system32\drivers\nltdi.sys [2006-02-27 15:50]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - D:\SETUP.EXE
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-02-28 20:01:09
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\NetLimiter 2 Pro\nlsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\NetLimiter 2 Pro\NLClient.exe
.
**************************************************************************
.
Completion time: 2008-02-28 20:03:37 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-28 20:03:34