Done all of that except the KAV online check. As I said, I have dial up. It is actually impossible, due to bad connection and stupidly slow speeds.
The rest all went fine.
HJT log #2:
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 19:57:52, on 26/08/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\libusbd-nt.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AntiFreeze\AntiFreeze.exe
C:\Program Files\Launchy\Launchy.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\FREEDO~1\fdm.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
S:\Computer\HiJackThis\HiJackThis_v2.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [ATITool] "C:\Program Files\ATITool\ATITool.exe" -s
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AntiFreeze] C:\Program Files\AntiFreeze\AntiFreeze.exe /splash
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Launchy.lnk = C:\Program Files\Launchy\Launchy.exe
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O9 - Extra button: (no name) - AutorunsDisabled - (no file)
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.microsoft.com/win...ls/en/x86/client/wuweb_site.cab?1218968902391
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{F5EA10A0-6FDF-4F26-BF9F-2AF2EA4038A3}: NameServer = 212.104.130.9 212.104.130.65
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LibUsb-Win32 - Daemon, Version 0.1.10.1 (libusbd) -
http://libusb-win32.sourceforge.net - C:\WINDOWS\system32\libusbd-nt.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
--
End of file - 5947 bytes
ComboFix CFScript log #1:
ComboFix 08-08-25.01 - James 2008-08-26 19:55:49.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1543 [GMT 1:00]
Running from: S:\New\ComboFix.exe
Command switches used :: S:\New\CFScript
* Created a new restore point
FILE ::
C:\WINDOWS\BM63e869b6.xml
C:\WINDOWS\system32\msxml71.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\BM63e869b6.xml
C:\WINDOWS\system32\msxml71.dll
.
((((((((((((((((((((((((( Files Created from 2008-07-26 to 2008-08-26 )))))))))))))))))))))))))))))))
.
2008-08-26 19:06 . 2008-08-26 18:17 304,640 --a------ C:\Program Files\PhotoResize400.exe
2008-08-26 13:28 . 2008-08-26 13:28 23 --a------ C:\WINDOWS\popcinfot.dat
2008-08-26 13:27 . 2008-08-26 13:27 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Trymedia
2008-08-26 13:25 . 2008-08-26 13:25 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\n7-89-o9-3r-4t-r9
2008-08-26 08:21 . 2008-08-26 08:21 <DIR> d-------- C:\Program Files\PS3ThemeCreator
2008-08-24 23:31 . 2008-08-26 08:21 <DIR> d-------- C:\WINDOWS\Downloaded Installations
2008-08-24 09:21 . 2008-08-24 09:21 <DIR> d-------- C:\Program Files\LibUSB-Win32-0.1.10.1
2008-08-24 09:21 . 2005-03-09 20:50 19,456 --a------ C:\WINDOWS\system32\libusbd-9x.exe
2008-08-24 09:21 . 2005-03-09 20:50 18,944 --a------ C:\WINDOWS\system32\libusbd-nt.exe
2008-08-23 20:49 . 2006-11-23 20:48 40,960 --a------ C:\WINDOWS\system32\ps3sixaxis_en.exe
2008-08-23 20:30 . 2005-03-09 20:50 46,592 --a------ C:\WINDOWS\system32\libusb0.dll
2008-08-23 20:30 . 2005-03-09 20:50 33,792 --a------ C:\WINDOWS\system32\drivers\libusb0.sys
2008-08-23 19:46 . 2008-04-14 05:42 151,552 --a------ C:\WINDOWS\system32\irftp.exe
2008-08-23 19:46 . 2008-04-14 05:42 151,552 --a------ C:\WINDOWS\system32\dllcache\irftp.exe
2008-08-23 19:46 . 2008-04-14 05:41 28,160 --a------ C:\WINDOWS\system32\irmon.dll
2008-08-23 19:46 . 2008-04-14 05:41 28,160 --a------ C:\WINDOWS\system32\dllcache\irmon.dll
2008-08-23 19:46 . 2008-04-14 05:42 8,192 --a------ C:\WINDOWS\system32\wshirda.dll
2008-08-23 19:46 . 2008-04-14 05:42 8,192 --a------ C:\WINDOWS\system32\dllcache\wshirda.dll
2008-08-21 16:46 . 2008-08-21 16:46 <DIR> d-------- C:\Program Files\Tibo Software
2008-08-21 16:46 . 2008-08-21 16:46 <DIR> d-------- C:\Documents and Settings\James\Application Data\Tibo Software
2008-08-21 16:46 . 2008-08-21 16:46 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Tibo Software
2008-08-21 12:38 . 2008-08-21 12:38 <DIR> d-------- C:\Program Files\AviSynth 2.5
2008-08-21 12:38 . 2004-02-22 10:11 719,872 --a------ C:\WINDOWS\system32\devil.dll
2008-08-21 12:38 . 2006-10-07 17:43 502,784 --a------ C:\WINDOWS\x2.64.exe
2008-08-21 12:38 . 2008-02-07 16:15 408,576 --a------ C:\WINDOWS\system32\Smab.dll
2008-08-21 12:38 . 2007-05-17 17:30 318,976 --a------ C:\WINDOWS\system32\avisynth.dll
2008-08-21 12:38 . 2005-02-28 13:16 240,128 --a------ C:\WINDOWS\system32\x.264.exe
2008-08-21 12:38 . 2006-04-12 09:47 217,073 --a------ C:\WINDOWS\meta4.exe
2008-08-21 12:38 . 2004-01-25 00:00 70,656 --a------ C:\WINDOWS\system32\i420vfw.dll
2008-08-21 12:38 . 2006-04-05 08:09 66,560 --a------ C:\WINDOWS\MOTA113.exe
2008-08-21 12:38 . 2005-07-14 12:31 27,648 --a------ C:\WINDOWS\system32\AVSredirect.dll
2008-08-21 12:37 . 2008-08-21 12:37 <DIR> d-------- C:\Program Files\eRightSoft
2008-08-20 16:03 . 2008-08-20 16:03 <DIR> d-------- C:\WINDOWS\Sun
2008-08-20 12:56 . 2008-08-20 12:56 <DIR> d-------- C:\Documents and Settings\James\.thumbnails
2008-08-20 10:48 . 2008-08-20 10:48 <DIR> d-------- C:\Program Files\BurnAware Free Edition
2008-08-20 10:48 . 2008-08-20 10:48 <DIR> d-------- C:\Documents and Settings\James\Application Data\ImgBurn
2008-08-20 10:44 . 2008-08-20 10:44 <DIR> d-------- C:\Program Files\ImgBurn
2008-08-19 21:43 . 2008-08-20 08:01 354 --a------ C:\WINDOWS\wininit.ini
2008-08-19 19:48 . 2008-08-20 21:42 <DIR> d-------- C:\Program Files\mIRC
2008-08-19 19:48 . 2008-08-20 22:26 <DIR> d-------- C:\Documents and Settings\James\Application Data\mIRC
2008-08-19 18:05 . 2008-08-19 18:05 <DIR> d-------- C:\Program Files\arniWORX
2008-08-19 18:02 . 2008-08-19 18:05 <DIR> d-------- C:\Program Files\DAEMON Tools Lite
2008-08-19 17:20 . 2008-08-19 17:20 <DIR> d-------- C:\Documents and Settings\James\Application Data\DAEMON Tools
2008-08-19 17:20 . 2008-08-19 17:20 717,296 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2008-08-19 14:39 . 2008-08-26 10:10 <DIR> d-------- C:\Documents and Settings\James\Application Data\gtk-2.0
2008-08-19 04:44 . 2008-06-23 17:57 6,066,176 --------- C:\WINDOWS\system32\dllcache\ieframe.dll
2008-08-19 04:44 . 2007-04-17 10:32 2,455,488 --------- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-08-19 04:44 . 2007-03-08 06:10 991,232 --------- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-08-19 04:44 . 2008-06-23 17:57 459,264 --------- C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-08-19 04:44 . 2008-06-23 17:57 383,488 --------- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-08-19 04:44 . 2008-06-23 17:57 267,776 --------- C:\WINDOWS\system32\dllcache\iertutil.dll
2008-08-19 04:44 . 2008-06-23 17:57 63,488 --------- C:\WINDOWS\system32\dllcache\icardie.dll
2008-08-19 04:44 . 2008-06-23 17:57 52,224 --------- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-08-19 04:44 . 2008-06-23 10:20 13,824 --------- C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-08-18 20:03 . 2008-08-18 20:03 268 --ah----- C:\sqmdata00.sqm
2008-08-18 20:03 . 2008-08-18 20:03 244 --ah----- C:\sqmnoopt00.sqm
2008-08-18 20:02 . 2008-08-18 20:02 <DIR> d-------- C:\Program Files\MSN Messenger
2008-08-18 18:26 . 2008-04-11 20:04 691,712 --------- C:\WINDOWS\system32\dllcache\inetcomm.dll
2008-08-18 14:36 . 2008-08-18 14:36 <DIR> d-------- C:\Program Files\DiskTrix
2008-08-18 14:21 . 2008-08-20 19:30 <DIR> d-------- C:\Documents and Settings\James\Application Data\SPORE Creature Creator
2008-08-18 14:20 . 2008-08-18 14:20 <DIR> dr-h----- C:\Documents and Settings\James\Application Data\SecuROM
2008-08-18 14:20 . 2008-08-18 14:20 107,888 --a------ C:\WINDOWS\system32\CmdLineExt.dll
2008-08-18 14:17 . 2008-05-01 15:33 331,776 --------- C:\WINDOWS\system32\dllcache\msadce.dll
2008-08-18 14:16 . 2008-08-18 14:16 <DIR> d-------- C:\Program Files\Electronic Arts
2008-08-18 14:00 . 2008-06-13 12:05 272,128 --------- C:\WINDOWS\system32\dllcache\bthport.sys
2008-08-18 12:28 . 2008-05-08 15:02 203,136 --------- C:\WINDOWS\system32\dllcache\rmcast.sys
2008-08-18 09:50 . 2008-04-14 00:15 26,368 --a------ C:\WINDOWS\system32\dllcache\usbstor.sys
2008-08-18 07:21 . 2008-08-18 07:21 <DIR> d-------- C:\Program Files\K-Lite Codec Pack
2008-08-18 00:21 . 2008-08-18 00:21 <DIR> d-------- C:\Program Files\Intel
2008-08-18 00:21 . 2008-08-18 00:21 <DIR> d-------- C:\Intel
2008-08-18 00:01 . 2008-08-18 00:01 <DIR> d-------- C:\Program Files\MSI
2008-08-17 20:22 . 2008-08-17 20:22 <DIR> d-------- C:\Program Files\Lavasoft
2008-08-17 20:22 . 2008-08-21 12:37 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-08-17 20:22 . 2008-08-17 20:24 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-08-17 19:20 . 2008-08-23 14:14 <DIR> d--h----- C:\$AVG8.VAULT$
2008-08-17 16:34 . 2008-08-17 16:34 <DIR> d-------- C:\Program Files\OpenAL
2008-08-17 16:34 . 2008-08-17 16:34 413,696 --a------ C:\WINDOWS\system32\wrap_oal.dll
2008-08-17 16:34 . 2008-08-17 16:34 110,592 --a------ C:\WINDOWS\system32\OpenAL32.dll
2008-08-17 16:33 . 2008-08-17 16:33 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-08-17 16:33 . 2008-08-17 16:33 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-08-17 16:32 . 2008-08-24 15:58 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-08-17 16:32 . 2008-08-17 16:32 <DIR> d-------- C:\Program Files\AVG
2008-08-17 16:32 . 2008-08-17 16:32 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-08-17 16:31 . 2006-10-12 09:40 716,800 --a------ C:\WINDOWS\system32\SysInternals Bluescreen.scr
2008-08-17 16:26 . 2008-08-17 16:26 <DIR> d-------- C:\Program Files\Foxit Software
2008-08-17 16:17 . 2008-08-17 16:17 <DIR> d-------- C:\Documents and Settings\James\Application Data\vlc
2008-08-17 15:36 . 2008-08-18 00:10 <DIR> d-------- C:\Program Files\Setup Files
2008-08-17 15:23 . 2008-08-17 15:23 <DIR> d-------- C:\Documents and Settings\James\Application Data\Windows Search
2008-08-17 15:22 . 2008-08-17 15:22 <DIR> d--h----- C:\WINDOWS\PIF
2008-08-17 15:21 . 2008-08-17 15:21 <DIR> d-------- C:\WINDOWS\system32\GroupPolicy
2008-08-17 15:21 . 2008-08-17 15:21 <DIR> d-------- C:\Program Files\Windows Desktop Search
2008-08-17 15:21 . 2008-08-17 15:21 <DIR> d-------- C:\Documents and Settings\James\Application Data\Windows Desktop Search
2008-08-17 15:21 . 2008-03-07 18:02 192,000 --------- C:\WINDOWS\system32\dllcache\offfilt.dll
2008-08-17 15:21 . 2008-03-07 18:02 98,304 --------- C:\WINDOWS\system32\dllcache\nlhtml.dll
2008-08-17 15:21 . 2008-03-07 18:02 29,696 --------- C:\WINDOWS\system32\dllcache\mimefilt.dll
2008-08-17 15:17 . 2008-07-22 15:45 1,214,526 --------- C:\WINDOWS\system32\dllcache\sysmain.sdb
2008-08-17 15:17 . 2008-07-22 15:45 790,846 --------- C:\WINDOWS\system32\dllcache\apph_sp.sdb
2008-08-17 15:17 . 2008-07-22 15:45 9,696 --------- C:\WINDOWS\system32\dllcache\drvmain.sdb
2008-08-17 14:38 . 2008-08-24 19:53 <DIR> d-------- C:\Documents and Settings\James\Application Data\OpenOffice.org2
2008-08-17 14:13 . 2008-08-17 14:13 <DIR> d-------- C:\Program Files\CCleaner
2008-08-17 13:08 . 2008-08-23 16:07 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-08-17 13:08 . 2008-08-26 11:00 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-08-17 13:05 . 2008-08-19 20:49 <DIR> d-------- C:\Documents and Settings\James\Application Data\Thunderbird
2008-08-17 13:05 . 2008-08-17 13:05 <DIR> d-------- C:\Documents and Settings\James\Application Data\Talkback
2008-08-17 13:05 . 2008-08-17 13:05 0 --a------ C:\WINDOWS\nsreg.dat
2008-08-17 13:04 . 2008-08-26 18:26 <DIR> d-------- C:\Program Files\Mozilla Thunderbird
2008-08-17 13:03 . 2008-08-17 13:03 <DIR> d-------- C:\Program Files\ATITool
2008-08-17 12:59 . 1998-10-02 19:00 327,168 --a------ C:\WINDOWS\IsUninst.exe
2008-08-17 12:58 . 2008-08-17 12:58 <DIR> d-------- C:\Program Files\VideoLAN
2008-08-17 12:51 . 2008-08-26 15:04 <DIR> d-------- C:\Program Files\RSSOwl
2008-08-17 12:51 . 2008-08-17 12:51 <DIR> d-------- C:\Documents and Settings\James\.rssowl2
2008-08-17 12:50 . 2008-08-17 12:50 <DIR> d-------- C:\Program Files\Autoruns
2008-08-17 12:48 . 2008-08-19 23:56 <DIR> d-------- C:\Program Files\Unlocker
2008-08-17 12:48 . 2008-08-17 12:48 <DIR> d-------- C:\Program Files\AntiFreeze
2008-08-17 12:48 . 2008-08-17 12:48 <DIR> d-------- C:\Program Files\7-Zip
2008-08-17 12:44 . 2008-08-17 12:44 127,034 -r------- C:\WINDOWS\bwUnin-8.1.1.50-8876480SL.exe
2008-08-17 12:43 . 2008-08-17 12:44 <DIR> d-------- C:\Program Files\Logitech
2008-08-17 12:43 . 2008-08-17 12:44 <DIR> d-------- C:\Program Files\Common Files\Logishrd
2008-08-17 12:43 . 2008-08-17 12:43 0 --ah----- C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-08-17 12:43 . 2008-08-17 12:43 0 --ah----- C:\WINDOWS\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2008-08-17 12:42 . 2008-08-17 12:43 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\LogiShrd
2008-08-17 12:34 . 2008-08-17 12:36 <DIR> d-------- C:\Program Files\GIMP-2.0
2008-08-17 12:34 . 2008-08-26 15:46 <DIR> d-------- C:\Documents and Settings\James\.gimp-2.4
2008-08-17 12:32 . 2008-08-17 12:32 <DIR> d-------- C:\Program Files\OpenOffice.org 2.4
2008-08-17 12:32 . 2008-08-17 12:32 <DIR> d-------- C:\Program Files\odf-converter-integrator
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-26 18:56 --------- d-----w C:\Documents and Settings\James\Application Data\Free Download Manager
2008-08-26 17:01 --------- d-----w C:\Documents and Settings\James\Application Data\.purple
2008-08-24 18:00 --------- d-----w C:\Program Files\Aspell
2008-08-20 20:04 --------- d-----w C:\Program Files\Pidgin
2008-08-20 20:03 --------- d-----w C:\Program Files\Common Files\GTK
2008-08-18 13:16 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-18 06:50 --------- d-----w C:\Program Files\Java
2008-08-17 10:49 --------- d-----w C:\Program Files\Free Download Manager
2008-08-17 10:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\FreeDownloadManager.ORG
2008-08-17 10:46 --------- d-----w C:\Program Files\MSBuild
2008-08-17 10:44 --------- d-----w C:\Program Files\Reference Assemblies
2008-08-17 10:35 --------- d-----w C:\Documents and Settings\James\Application Data\Xentient
2008-08-17 10:31 --------- d-----w C:\Program Files\Common Files\Java
2008-08-17 10:29 --------- d-----w C:\Program Files\Xentient
2008-08-17 10:28 --------- d-----w C:\Program Files\NVIDIA Corporation
2008-08-17 10:24 319,488 ----a-w C:\WINDOWS\HideWin.exe
2008-08-17 10:24 --------- d-----w C:\Program Files\Realtek
2008-08-17 10:21 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-08-17 09:51 --------- d-----w C:\Program Files\microsoft frontpage
2008-08-17 09:44 --------- d-----w C:\Program Files\Windows Plus
2008-07-25 08:34 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2008-07-25 08:34 683,520 ----a-w C:\WINDOWS\system32\divx.dll
2008-07-24 17:02 4,749,824 ----a-w C:\WINDOWS\system32\drivers\RtkHDAud.sys
2008-07-23 16:50 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2008-07-23 15:51 16,804,864 ----a-w C:\WINDOWS\RTHDCPL.exe
2008-07-21 15:14 9,728 ----a-w C:\WINDOWS\system32\RtNicProp32.dll
2008-07-16 18:51 2,041,363 ----a-w C:\WINDOWS\system32\x264vfw.dll
2008-07-15 12:58 524,288 ----a-w C:\WINDOWS\RtlExUpd.dll
2008-07-15 12:47 1,196,032 ----a-w C:\WINDOWS\RtlUpd.exe
2008-07-07 20:26 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-07-07 20:26 253,952 ------w C:\WINDOWS\system32\dllcache\es.dll
2008-07-01 02:27 108,800 ----a-w C:\WINDOWS\system32\drivers\Rtenicxp.sys
2008-06-24 16:43 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-24 16:43 74,240 ------w C:\WINDOWS\system32\dllcache\mscms.dll
2008-06-24 09:57 3,592,192 ------w C:\WINDOWS\system32\dllcache\mshtml.dll
2008-06-23 09:20 70,656 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2008-06-23 09:20 625,664 ------w C:\WINDOWS\system32\dllcache\iexplore.exe
2008-06-21 05:23 161,792 ----a-w C:\WINDOWS\system32\dllcache\ieakui.dll
2008-06-20 17:46 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 17:46 245,248 ------w C:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 17:46 147,968 ------w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-06-20 11:51 361,600 ------w C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 11:40 138,496 ------w C:\WINDOWS\system32\dllcache\afd.sys
2008-06-20 11:08 225,856 ------w C:\WINDOWS\system32\dllcache\tcpip6.sys
2008-06-19 15:42 2,808,832 ----a-w C:\WINDOWS\alcwzrd.exe
2008-06-19 15:27 9,715,200 ----a-w C:\WINDOWS\RTLCPL.exe
2008-06-19 15:20 57,344 ----a-w C:\WINDOWS\Alcmtr.exe
2008-06-18 17:01 77,824 ----a-w C:\WINDOWS\SoundMan.exe
2008-06-12 18:36 7,680 ----a-w C:\WINDOWS\system32\ff_vfw.dll
2008-05-26 21:21 1,582,592 ----a-w C:\WINDOWS\system32\tquery.dll
2008-05-26 21:21 1,418,240 ----a-w C:\WINDOWS\system32\mssrch.dll
2008-05-26 21:19 97,792 ----a-w C:\WINDOWS\system32\UncCplExt.dll
2008-05-26 21:19 273,408 ----a-w C:\WINDOWS\system32\oeph.dll
2008-05-26 21:19 2,048 ----a-w C:\WINDOWS\system32\UncRes.dll
2008-05-26 21:19 143,872 ----a-w C:\WINDOWS\system32\UncDMS.dll
2008-05-26 21:19 131,072 ----a-w C:\WINDOWS\system32\UncPH.dll
2008-05-26 21:19 11,264 ----a-w C:\WINDOWS\system32\oephRes.dll
2008-05-26 21:19 108,032 ----a-w C:\WINDOWS\system32\UncNE.dll
2008-05-26 21:18 71,680 ----a-w C:\WINDOWS\system32\propdefs.dll
2008-05-26 21:18 56,320 ----a-w C:\WINDOWS\system32\xmlfilter.dll
2008-05-26 21:18 44,032 ----a-w C:\WINDOWS\system32\msstrc.dll
2008-05-26 21:18 439,808 ----a-w C:\WINDOWS\system32\searchindexer.exe
2008-05-26 21:18 38,400 ----a-w C:\WINDOWS\system32\rtffilt.dll
2008-05-26 21:18 350,208 ----a-w C:\WINDOWS\system32\mssph.dll
2008-05-26 21:18 231,936 ----a-w C:\WINDOWS\system32\msshsq.dll
2008-05-26 21:18 203,776 ----a-w C:\WINDOWS\system32\mssphtb.dll
2008-05-26 21:18 184,832 ----a-w C:\WINDOWS\system32\searchprotocolhost.exe
2008-05-26 21:17 87,552 ----a-w C:\WINDOWS\system32\searchfilterhost.exe
2008-05-26 21:17 87,552 ----a-w C:\WINDOWS\system32\mssitlb.dll
2008-05-26 21:17 754,176 ----a-w C:\WINDOWS\system32\propsys.dll
2008-05-26 21:17 60,416 ----a-w C:\WINDOWS\system32\msscntrs.dll
2008-05-26 21:17 34,816 ----a-w C:\WINDOWS\system32\msscb.dll
2008-05-26 21:17 32,768 ----a-w C:\WINDOWS\system32\mssprxy.dll
2008-05-26 21:17 301,568 ----a-w C:\WINDOWS\system32\srchadmin.dll
2008-05-26 21:17 11,776 ----a-w C:\WINDOWS\system32\msshooks.dll
2008-05-26 20:59 18,904 ----a-w C:\WINDOWS\system32\structuredqueryschematrivial.bin
2008-05-26 20:59 106,605 ----a-w C:\WINDOWS\system32\structuredqueryschema.bin
2006-05-03 10:06 163,328 --sh--r C:\WINDOWS\system32\flvDX.dll
2007-02-21 11:47 31,232 --sh--r C:\WINDOWS\system32\msfDX.dll
2007-12-17 13:43 27,648 --sh--w C:\WINDOWS\system32\Smab0.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 05:42 15360]
"AntiFreeze"="C:\Program Files\AntiFreeze\AntiFreeze.exe" [2007-12-16 16:57 139776]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-10 13:00 208952]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-10 13:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-10 13:00 455168]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2004-08-10 04:04 59392]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-05-16 14:01 13529088]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-05-16 14:01 86016]
"ATITool"="C:\Program Files\ATITool\ATITool.exe" [2006-12-08 16:23 3035136]
"nwiz"="nwiz.exe" [2008-05-16 14:01 1630208 C:\WINDOWS\system32\nwiz.exe]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-07-17 17:39 55824 C:\WINDOWS\KHALMNPR.Exe]
"RTHDCPL"="RTHDCPL.EXE" [2008-07-23 16:51 16804864 C:\WINDOWS\RTHDCPL.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 05:42 110592 C:\WINDOWS\system32\bthprops.cpl]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 05:42 15360]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Launchy.lnk - C:\Program Files\Launchy\Launchy.exe [2008-08-17 12:08:06 286720]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 01000000
"NoLogoff"= 0 (0x0)
"NoSMMyPictures"= 01000000
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 22:19 304128]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.I420"= i420vfw.dll
"msacm.l3fhg"= mp3fhg.acm
"msacm.divxa32"= divxa32.acm
"VIDC.X264"= x264vfw.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.i263"= i263_32.drv
"VIDC.YV12"= yv12vfw.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\mIRC\\mirc.exe"=
R3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.10.1;C:\WINDOWS\system32\drivers\libusb0.sys [2005-03-09 20:50]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-08-17 16:33]
S2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-08-17 16:32]
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-08-26 19:56:28
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
AntiFreeze = C:\Program Files\AntiFreeze\AntiFreeze.exe /splash???????????????????????????????????????????????????????????????????????????????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-08-26 19:56:49
ComboFix-quarantined-files.txt 2008-08-26 18:56:45
ComboFix2.txt 2008-08-26 13:03:02
Pre-Run: 239,554,609,152 bytes free
Post-Run: 239,538,933,760 bytes free
300 --- E O F --- 2008-08-19 06:16:56
Please can I not run ComboFix any more, whenever I do a few settings change.

(Firefox default browser, start menu links etc). OK, it doesn't matter at all actually.