working on the rest you wanted I'll post ASAP.
ComboFix 09-01-01.01 - HP_Owner 2009-01-02 13:56:22.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.639.337 [GMT -5:00]
Running from: c:\documents and settings\HP_Owner\Desktop\CombiFxx.exe
Command switches used :: c:\documents and settings\HP_Owner\Desktop\CFScript.txt
* Created a new restore point
FILE ::
c:\documents and settings\the zoo\Start Menu\Programs\Startup\LimeWire On Startup.lnk
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\the zoo\Application Data\LimeWire
c:\documents and settings\the zoo\Application Data\LimeWire\414splashfree.png
c:\documents and settings\the zoo\Application Data\LimeWire\createtimes.cache
c:\documents and settings\the zoo\Application Data\LimeWire\fileurns.bak
c:\documents and settings\the zoo\Application Data\LimeWire\fileurns.cache
c:\documents and settings\the zoo\Application Data\LimeWire\installation.props
c:\documents and settings\the zoo\Application Data\LimeWire\library.dat
c:\documents and settings\the zoo\Application Data\LimeWire\limewire.props
c:\documents and settings\the zoo\Application Data\LimeWire\mojito.props
c:\documents and settings\the zoo\Application Data\LimeWire\questions.props
c:\documents and settings\the zoo\Application Data\LimeWire\simpp.xml
c:\documents and settings\the zoo\Application Data\LimeWire\tables.props
c:\documents and settings\the zoo\Application Data\LimeWire\themes\windows_theme.lwtp
c:\documents and settings\the zoo\Application Data\LimeWire\themes\windows_theme\
01_star.gif
c:\documents and settings\the zoo\Application Data\LimeWire\themes\windows_theme\
02_star.gif
c:\documents and settings\the zoo\Application Data\LimeWire\themes\windows_theme\
03_star.gif
c:\documents and settings\the zoo\Application Data\LimeWire\themes\windows_theme\
04_star.gif
c:\documents and settings\the zoo\Application Data\LimeWire\themes\windows_theme\
05_star.gif
c:\documents and settings\the zoo\Application Data\LimeWire\themes\windows_theme\chat.gif
c:\documents and settings\the zoo\Application Data\LimeWire\themes\windows_theme\forward_dn.gif
c:\documents and settings\the zoo\Application Data\LimeWire\themes\windows_theme\forward_up.gif
c:\documents and settings\the zoo\Application Data\LimeWire\themes\windows_theme\kill.gif
c:\documents and settings\the zoo\Application Data\LimeWire\themes\windows_theme\kill_on.gif
c:\documents and settings\the zoo\Application Data\LimeWire\themes\windows_theme\logo.png
c:\documents and settings\the zoo\Application Data\LimeWire\themes\windows_theme\notsearching.png
c:\documents and settings\the zoo\Application Data\LimeWire\themes\windows_theme\pause_dn.gif
c:\documents and settings\the zoo\Application Data\LimeWire\themes\windows_theme\pause_up.gif
c:\documents and settings\the zoo\Application Data\LimeWire\themes\windows_theme\play_dn.gif
c:\documents and settings\the zoo\Application Data\LimeWire\themes\windows_theme\play_up.gif
c:\documents and settings\the zoo\Application Data\LimeWire\themes\windows_theme\question.gif
c:\documents and settings\the zoo\Application Data\LimeWire\themes\windows_theme\rewind_dn.gif
c:\documents and settings\the zoo\Application Data\LimeWire\themes\windows_theme\rewind_up.gif
c:\documents and settings\the zoo\Application Data\LimeWire\themes\windows_theme\searching.gif
c:\documents and settings\the zoo\Application Data\LimeWire\themes\windows_theme\splash.png
c:\documents and settings\the zoo\Application Data\LimeWire\themes\windows_theme\splashpro.png
c:\documents and settings\the zoo\Application Data\LimeWire\themes\windows_theme\stop_dn.gif
c:\documents and settings\the zoo\Application Data\LimeWire\themes\windows_theme\stop_up.gif
c:\documents and settings\the zoo\Application Data\LimeWire\themes\windows_theme\theme.txt
c:\documents and settings\the zoo\Application Data\LimeWire\themes\windows_theme\version.txt
c:\documents and settings\the zoo\Application Data\LimeWire\themes\windows_theme\warning.gif
c:\documents and settings\the zoo\Application Data\LimeWire\version.xml
c:\documents and settings\the zoo\Application Data\LimeWire\xml\data\delete_me
c:\documents and settings\the zoo\Application Data\LimeWire\xml\misc\application.gif
c:\documents and settings\the zoo\Application Data\LimeWire\xml\misc\audio.gif
c:\documents and settings\the zoo\Application Data\LimeWire\xml\misc\document.gif
c:\documents and settings\the zoo\Application Data\LimeWire\xml\misc\image.gif
c:\documents and settings\the zoo\Application Data\LimeWire\xml\misc\video.gif
c:\documents and settings\the zoo\Application Data\LimeWire\xml\schemas\application.xsd
c:\documents and settings\the zoo\Application Data\LimeWire\xml\schemas\audio.xsd
c:\documents and settings\the zoo\Application Data\LimeWire\xml\schemas\document.xsd
c:\documents and settings\the zoo\Application Data\LimeWire\xml\schemas\image.xsd
c:\documents and settings\the zoo\Application Data\LimeWire\xml\schemas\video.xsd
.
((((((((((((((((((((((((( Files Created from 2008-12-02 to 2009-01-02 )))))))))))))))))))))))))))))))
.
2009-01-02 13:43 . 2009-01-02 13:43 <DIR> d-------- c:\program files\Common Files\Adobe AIR
2008-12-30 15:34 . 2008-12-30 15:33 73,728 --a------ c:\windows\system32\javacpl.cpl
2008-12-18 18:56 . 2008-12-30 15:33 410,984 --a------ c:\windows\system32\deploytk.dll
2008-12-07 10:37 . 2008-12-07 10:37 <DIR> d-------- c:\documents and settings\the zoo\Application Data\Aim
2008-12-07 10:26 . 2008-12-07 10:26 <DIR> d-------- c:\documents and settings\the zoo\Incomplete
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-02 18:41 --------- d-----w c:\program files\Common Files\Adobe
2009-01-02 17:07 3,645 ----a-w c:\windows\viassary-hp.reg
2009-01-02 13:11 --------- d-----w c:\program files\Incomplete
2008-12-31 14:31 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-30 20:33 --------- d-----w c:\program files\Java
2008-12-25 03:58 --------- d-----w c:\program files\Google
2008-12-21 14:07 --------- d-----w c:\program files\Common Files\AOL
2008-12-13 06:40 3,593,216 ----a-w c:\windows\system32\dllcache\mshtml.dll
2008-12-04 00:08 --------- d-----w c:\documents and settings\HP_Owner\Application Data\Apple Computer
2008-12-02 01:12 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-01 23:41 45,056 ----a-w c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\uninstallUI\eHelpSetup.exe
2008-12-01 23:41 44,032 ----a-w c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Scripts\devcon.exe
2008-12-01 21:34 162 ----a-w c:\documents and settings\HP_Owner\Application Data\wklnhst.dat
2008-12-01 21:34 --------- d-----w c:\documents and settings\HP_Owner\Application Data\Template
2008-11-26 13:30 --------- d-----w c:\documents and settings\the zoo\Application Data\AOL
2008-11-21 14:58 --------- d-----w c:\documents and settings\All Users\Application Data\AOL
2008-11-19 15:27 --------- d-----w c:\program files\AIM
2008-11-10 13:12 --------- d-----w c:\program files\Microsoft Works
2008-10-24 11:10 453,632 ----a-w c:\windows\system32\dllcache\mrxsmb.sys
2008-10-23 13:01 283,648 ----a-w c:\windows\system32\gdi32.dll
2008-10-23 13:01 283,648 ----a-w c:\windows\system32\dllcache\gdi32.dll
2008-10-16 19:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 19:13 202,776 ----a-w c:\windows\system32\dllcache\wuweb.dll
2008-10-16 19:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 19:13 1,809,944 ----a-w c:\windows\system32\dllcache\wuaueng.dll
2008-10-16 19:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 19:12 561,688 ----a-w c:\windows\system32\dllcache\wuapi.dll
2008-10-16 19:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 19:12 323,608 ----a-w c:\windows\system32\dllcache\wucltui.dll
2008-10-16 19:09 92,696 ----a-w c:\windows\system32\dllcache\cdm.dll
2008-10-16 19:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 19:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 19:09 51,224 ----a-w c:\windows\system32\dllcache\wuauclt.exe
2008-10-16 19:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 19:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 19:08 34,328 ----a-w c:\windows\system32\dllcache\wups.dll
2008-10-16 13:11 70,656 ----a-w c:\windows\system32\dllcache\ie4uinit.exe
2008-10-16 13:11 13,824 ------w c:\windows\system32\dllcache\ieudinit.exe
2008-10-15 16:57 332,800 ----a-w c:\windows\system32\dllcache\netapi32.dll
2008-10-15 07:06 633,632 ----a-w c:\windows\system32\dllcache\iexplore.exe
2008-10-15 07:04 161,792 ----a-w c:\windows\system32\dllcache\ieakui.dll
2008-10-03 10:15 247,326 ----a-w c:\windows\system32\strmdll.dll
2008-10-03 10:15 247,326 ----a-w c:\windows\system32\dllcache\strmdll.dll
.
((((((((((((((((((((((((((((( snapshot@2009-01-02_12.12.03.56 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-12-12 20:06:42 295,606 ----a-r c:\windows\Installer\{AC76BA86-7AD7-1033-7B44-A90000000001}\SC_Reader.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"AIM"="c:\program files\AIM\aim.exe" [2006-08-01 67112]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-24 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-02-26 245760]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-14 253952]
"AOLDialer"="c:\program files\Common Files\AOL\ACS\AOLDial.exe" [2006-10-23 71216]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2005-05-26 180269]
"HostManager"="c:\program files\Common Files\AOL\1184594124\ee\AOLSoftware.exe" [2007-10-08 41824]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 241664]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb10.exe" [2006-01-13 172032]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 517768]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2007-11-14 286720]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2007-11-15 267048]
"HPHmon06"="c:\windows\system32\hphmon06.exe" [2004-06-07 659456]
"Pure Networks Port Magic"="c:\progra~1\PURENE~1\PORTMA~1\PortAOL.exe" [2004-08-24 99480]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-30 136600]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"SiSPower"="SiSPower.dll" [2005-04-12 c:\windows\system32\SiSPower.dll]
c:\documents and settings\HP_Owner\Start Menu\Programs\Startup\
HP Organize.lnk - c:\program files\Hewlett-Packard\HP Organize\bin\displayAgent.exe [2005-05-26 36864]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
America Online 9.0 Tray Icon.lnk - c:\program files\America Online 9.0a\aoltray.exe [2008-05-06 156784]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-11-05 258048]
Updates from HP.lnk - c:\program files\Updates from HP\309731\Program\Updates from HP.exe [2005-05-26 45056]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\
0lsdelete
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Updates from HP\\309731\\Program\\Updates from HP.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AOL\\1184594124\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\America Online 9.0a\\waol.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
.
Contents of the 'Scheduled Tasks' folder
2009-01-01 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 14:57]
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = hxxp://www.aol.com/
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: Add To HP Organize... - c:\progra~1\HEWLET~1\HPORGA~1\bin/module.main/favorites\ie_add_to.html
c:\windows\Downloaded Program Files\SFImageUploadRes.09.xml - c:\windows\system32\ijl11.dll
c:\windows\Downloaded Program Files\SFImageUpload1_8.ocx
O16 -: {8646A6AF-0AE4-4BF8-B716-DB1513803972}
hxxp://riteaid.storefront.com/images/global/activex/SFImageUpload1_8.CAB
c:\windows\Downloaded Program Files\SFImageUpload1_8.INF
c:\windows\Downloaded Program Files\WMDownload.dll - O16 -: {A922B6AB-3B87-11D3-B3C2-0008C7DA6CB9}
hxxps://media.pineconeresearch.com/ActiveX/downloadcontrol.cab
c:\windows\Downloaded Program Files\WMDL.inf
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-01-02 13:58:26
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-01-02 14:00:15
ComboFix-quarantined-files.txt 2009-01-02 18:59:07
ComboFix2.txt 2009-01-02 17:14:06
Pre-Run: 133,188,214,784 bytes free
Post-Run: 133,182,296,064 bytes free
210 --- E O F --- 2008-12-19 08:01:29