Combofix step
Ran Combofix again. log below:
ComboFix 08-12-07.04 - Susan Chew 2008-12-09 11:25:05.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.452 [GMT -6:00]
Running from: c:\documents and settings\Susan Chew\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Susan Chew\Desktop\CFScript.txt
* Created a new restore point
FILE ::
c:\windows\system32\TDSSqxgx.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Susan Chew\My Documents\LimeWire
c:\documents and settings\Susan Chew\My Documents\LimeWire\.NetworkShare\LimeWirePackedJars4.10.2.7z
c:\documents and settings\Susan Chew\My Documents\LimeWire\.NetworkShare\LimeWireWin4.10.2.exe
c:\documents and settings\Susan Chew\My Documents\LimeWire\clink.jar
c:\documents and settings\Susan Chew\My Documents\LimeWire\commons-httpclient.jar
c:\documents and settings\Susan Chew\My Documents\LimeWire\commons-logging.jar
c:\documents and settings\Susan Chew\My Documents\LimeWire\commons-net.jar
c:\documents and settings\Susan Chew\My Documents\LimeWire\daap.jar
c:\documents and settings\Susan Chew\My Documents\LimeWire\data.ser
c:\documents and settings\Susan Chew\My Documents\LimeWire\donotremove.htm
c:\documents and settings\Susan Chew\My Documents\LimeWire\GenericWindowsUtils.dll
c:\documents and settings\Susan Chew\My Documents\LimeWire\hashes
c:\documents and settings\Susan Chew\My Documents\LimeWire\hs_err_pid1052.log
c:\documents and settings\Susan Chew\My Documents\LimeWire\hs_err_pid1712.log
c:\documents and settings\Susan Chew\My Documents\LimeWire\hs_err_pid1900.log
c:\documents and settings\Susan Chew\My Documents\LimeWire\hs_err_pid4944.log
c:\documents and settings\Susan Chew\My Documents\LimeWire\hs_err_pid528.log
c:\documents and settings\Susan Chew\My Documents\LimeWire\i18n.jar
c:\documents and settings\Susan Chew\My Documents\LimeWire\icu4j.jar
c:\documents and settings\Susan Chew\My Documents\LimeWire\id3v2.jar
c:\documents and settings\Susan Chew\My Documents\LimeWire\install.log
c:\documents and settings\Susan Chew\My Documents\LimeWire\jcraft.jar
c:\documents and settings\Susan Chew\My Documents\LimeWire\jl011.jar
c:\documents and settings\Susan Chew\My Documents\LimeWire\jmdns.jar
c:\documents and settings\Susan Chew\My Documents\LimeWire\language.prop
c:\documents and settings\Susan Chew\My Documents\LimeWire\LimeWire On Startup.lnk
c:\documents and settings\Susan Chew\My Documents\LimeWire\LimeWire.exe
c:\documents and settings\Susan Chew\My Documents\LimeWire\LimeWire.ico
c:\documents and settings\Susan Chew\My Documents\LimeWire\LimeWire.jar
c:\documents and settings\Susan Chew\My Documents\LimeWire\LimeWire20.dll
c:\documents and settings\Susan Chew\My Documents\LimeWire\log.txt
c:\documents and settings\Susan Chew\My Documents\LimeWire\log4j.jar
c:\documents and settings\Susan Chew\My Documents\LimeWire\log4j.properties
c:\documents and settings\Susan Chew\My Documents\LimeWire\logicrypto.jar
c:\documents and settings\Susan Chew\My Documents\LimeWire\looks.jar
c:\documents and settings\Susan Chew\My Documents\LimeWire\MessagesBundle.properties
c:\documents and settings\Susan Chew\My Documents\LimeWire\MessagesBundles.jar
c:\documents and settings\Susan Chew\My Documents\LimeWire\mp3sp14.jar
c:\documents and settings\Susan Chew\My Documents\LimeWire\pmf.ico
c:\documents and settings\Susan Chew\My Documents\LimeWire\ProgressTabs.jar
c:\documents and settings\Susan Chew\My Documents\LimeWire\root\magnet10\badge.img
c:\documents and settings\Susan Chew\My Documents\LimeWire\root\magnet10\canHandle.img
c:\documents and settings\Susan Chew\My Documents\LimeWire\root\magnet10\limewire.gif
c:\documents and settings\Susan Chew\My Documents\LimeWire\root\magnet10\options.js
c:\documents and settings\Susan Chew\My Documents\LimeWire\root\magnet10\silentdetect.js
c:\documents and settings\Susan Chew\My Documents\LimeWire\SOURCE
c:\documents and settings\Susan Chew\My Documents\LimeWire\spacer.gif
c:\documents and settings\Susan Chew\My Documents\LimeWire\themes.jar
c:\documents and settings\Susan Chew\My Documents\LimeWire\tritonus.jar
c:\documents and settings\Susan Chew\My Documents\LimeWire\uninstall.exe
c:\documents and settings\Susan Chew\My Documents\LimeWire\unpack.log
c:\documents and settings\Susan Chew\My Documents\LimeWire\update.ver
c:\documents and settings\Susan Chew\My Documents\LimeWire\vorbis.jar
c:\documents and settings\Susan Chew\My Documents\LimeWire\WindowsV5PlusUtils.dll
c:\documents and settings\Susan Chew\My Documents\LimeWire\xerces.jar
c:\documents and settings\Susan Chew\My Documents\LimeWire\xml-apis.jar
c:\documents and settings\Susan Chew\My Documents\LimeWire\xml.war
c:\program files\mypoints
c:\program files\mypoints\mypoints1.old
c:\program files\mypoints\uninstall.exe
c:\program files\PremierOpinion
c:\program files\PremierOpinion\pmai.dll
c:\program files\PremierOpinion\pmls.dll
c:\program files\PremierOpinion\pmoci.bin
c:\program files\PremierOpinion\pmph.dll
c:\program files\PremierOpinion\pmropn.exe
c:\program files\PremierOpinion\pmservice.exe
c:\program files\PremierOpinion\pmxf.dll
c:\windows\system32\TDSSqxgx.dll
.
((((((((((((((((((((((((( Files Created from 2008-11-09 to 2008-12-09 )))))))))))))))))))))))))))))))
.
2008-12-08 22:06 . 2008-12-08 22:06 <DIR> d-------- c:\windows\LastGood
2008-12-08 22:06 . 2008-12-08 22:06 <DIR> d-------- c:\program files\Secunia
2008-12-08 21:06 . 2008-12-08 21:06 <DIR> d-------- c:\program files\Trend Micro
2008-12-03 09:37 . 2008-12-03 09:37 <DIR> d-------- c:\program files\Enigma Software Group
2008-12-03 00:05 . 2008-12-05 16:47 <DIR> d-------- c:\documents and settings\Susan Chew\Application Data\AVGTOOLBAR
2008-12-02 19:43 . 2008-12-05 13:49 <DIR> d--h----- C:\$AVG8.VAULT$
2008-12-02 19:16 . 2008-12-08 08:29 <DIR> d-------- c:\windows\system32\drivers\Avg
2008-12-02 19:16 . 2008-12-02 19:16 <DIR> d-------- c:\program files\AVG
2008-12-02 19:16 . 2008-12-03 00:04 <DIR> d-------- c:\documents and settings\Andrew Chalk\Application Data\AVGTOOLBAR
2008-12-02 19:16 . 2008-12-02 19:16 <DIR> d-------- c:\documents and settings\All Users\Application Data\avg8
2008-12-02 19:16 . 2008-12-02 19:16 97,928 --a------ c:\windows\system32\drivers\avgldx86.sys
2008-12-02 19:16 . 2008-12-02 19:16 10,520 --a------ c:\windows\system32\avgrsstx.dll
2008-12-02 19:14 . 2008-12-02 19:14 410,984 --a------ c:\windows\system32\deploytk.dll
2008-11-23 14:34 . 2008-11-23 14:34 <DIR> d-------- c:\program files\iTunes
2008-11-23 14:34 . 2008-11-23 14:34 <DIR> d-------- c:\program files\iPod
2008-11-23 14:34 . 2008-11-23 14:34 <DIR> d-------- c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-11-23 14:33 . 2008-11-23 14:33 <DIR> d-------- c:\program files\QuickTime
2008-11-18 07:36 . 2008-11-18 07:36 7,808 --a------ c:\windows\system32\drivers\psi_mf.sys
2008-11-11 20:53 . 2008-09-04 11:15 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll
2008-11-11 20:53 . 2008-10-24 05:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-09 05:00 --------- d-----w c:\documents and settings\All Users\Application Data\Google Updater
2008-12-09 04:29 --------- d-----w c:\program files\Java
2008-12-09 04:16 --------- d-----w c:\program files\Common Files\Adobe
2008-12-09 01:03 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
2008-12-03 02:00 --------- d-----w c:\program files\ezt
2008-12-01 00:50 295,424 ----a-w c:\windows\system32\termsrv.dll
2008-11-23 20:32 --------- d-----w c:\program files\Common Files\Apple
2008-11-23 20:21 --------- d-----w c:\program files\Safari
2008-11-04 04:10 --------- d-----w c:\documents and settings\Susan Chew\Application Data\dvdcss
2008-11-01 19:14 --------- d-----w c:\program files\Google
2008-10-29 00:06 --------- d-----w c:\program files\Quicken
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-19 20:22 --------- d-----w c:\documents and settings\Susan Chew\Application Data\ZoomBrowser EX
2008-10-19 16:31 --------- d-----w c:\documents and settings\Susan Chew\Application Data\CameraWindowDC
2008-10-16 20:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 20:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 20:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 20:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 20:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 20:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 20:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 20:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 20:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 20:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-09-15 12:12 1,846,400 ----a-w c:\windows\system32\win32k.sys
2008-09-10 01:14 1,307,648 ------w c:\windows\system32\msxml6.dll
2006-05-06 16:42 7,260,160 ----a-w c:\program files\mozilla firefox\plugins\libvlc.dll
2004-08-04 07:56 4,096 --sha-w c:\windows\system32\1112.dat
.
((((((((((((((((((((((((((((( snapshot_2008-12-08_19.40.28.95 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-12-09 04:17:22 295,606 ----a-r c:\windows\Installer\{AC76BA86-7AD7-1033-7B44-A81300000003}\SC_Reader.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"Google Update"="c:\documents and settings\Susan Chew\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-03 133104]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-30 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-11-07 111936]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-09-17 185896]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-12-02 1261336]
"SpyHunter Security Suite"="c:\program files\Enigma Software Group\SpyHunter\SpyHunter3.exe" [2008-10-08 864256]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-02 136600]
"MSConfig"="c:\windows\pchealth\helpctr\Binaries\MSCONFIG.EXE" [2008-04-13 169984]
c:\documents and settings\Susan Chew\Start Menu\Programs\Startup\
Secunia PSI.lnk - c:\program files\Secunia\PSI\psi.exe [2008-11-25 728408]
[HKLM\~\startupfolder\C:^Documents and Settings^Susan Chew^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
path=c:\documents and settings\Susan Chew\Start Menu\Programs\Startup\LimeWire On Startup.lnk
backup=c:\windows\pss\LimeWire On Startup.lnkStartup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Wireless Sync\\Client\\Monitor.exe"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"1743:UDP"= 1743:UDP:*

isabled:Windows Media Format SDK (wmplayer.exe)
"1742:UDP"= 1742:UDP:*

isabled:Windows Media Format SDK (wmplayer.exe)
"1749:UDP"= 1749:UDP:*

isabled:Windows Media Format SDK (wmplayer.exe)
R0 PQV2i;PQV2i;c:\windows\system32\drivers\PQV2i.sys [2004-07-29 138780]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-12-02 97928]
R1 PQIMount;PQIMount;c:\windows\system32\drivers\PQIMount.sys [2004-07-29 46779]
R3 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-12-02 231704]
R3 MusCDriverV32;MusCDriverV32;c:\windows\system32\drivers\MusCDriverV32.sys [2008-08-21 509312]
R3 MusCVideo32;MusCVideo32;c:\windows\system32\DRIVERS\MusCVideo32.sys [2008-08-21 3768]
R3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf.sys [2008-11-18 7808]
S4 SoundMovieServer;SoundMovieServer;"c:\windows\system32\snmvtsvc.exe" [2008-08-21 200704]
*Newly Created Service* - PSI
.
Contents of the 'Scheduled Tasks' folder
2008-08-27 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2008-11-19 c:\windows\Tasks\GoogleUpdateTaskUser.job
- c:\documents and settings\Susan Chew\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-03 14:39]
2008-12-03 c:\windows\Tasks\SpyHunter Scanner.job
- c:\program files\Enigma Software Group\SpyHunter\SpyHunter3.exe [2008-10-08 16:30]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-PremierOpinion - c:\program files\PremierOpinion\pmropn.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
FireFox -: Profile - c:\documents and settings\Susan Chew\Application Data\Mozilla\Firefox\Profiles\g7hij9fj.default\
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-12-09 11:29:06
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(740)
c:\program files\Enigma Software Group\SpyHunter\SpyHunterMonitor.dll
c:\windows\system32\igfxsrvc.dll
c:\windows\system32\hccutils.DLL
- - - - - - - > 'lsass.exe'(796)
c:\program files\Enigma Software Group\SpyHunter\SpyHunterMonitor.dll
.
Completion time: 2008-12-09 11:32:14
ComboFix-quarantined-files.txt 2008-12-09 17:30:55
ComboFix2.txt 2008-12-09 01:43:03
ComboFix3.txt 2008-05-18 04:27:20
Pre-Run: 17,976,123,392 bytes free
Post-Run: 18,000,457,728 bytes free
230 --- E O F --- 2008-11-27 05:44:11