Here's a new combofix log and hijackthis log, in that order.
ComboFix 09-01-13.04 - Andrew 2009-01-14 7:50:03.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.502.230 [GMT -4:00]
Running from: c:\documents and settings\Andrew\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Andrew\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Andrew\Application Data\Azureus
c:\documents and settings\Andrew\Application Data\Azureus\.certs
c:\documents and settings\Andrew\Application Data\Azureus\.keystore
c:\documents and settings\Andrew\Application Data\Azureus\.lock
c:\documents and settings\Andrew\Application Data\Azureus\active\cache.dat
c:\documents and settings\Andrew\Application Data\Azureus\azureus.config
c:\documents and settings\Andrew\Application Data\Azureus\azureus.config.bak
c:\documents and settings\Andrew\Application Data\Azureus\azureus.statistics
c:\documents and settings\Andrew\Application Data\Azureus\azureus.statistics.bak
c:\documents and settings\Andrew\Application Data\Azureus\banips.config
c:\documents and settings\Andrew\Application Data\Azureus\banips.config.bak
c:\documents and settings\Andrew\Application Data\Azureus\dht\addresses.dat
c:\documents and settings\Andrew\Application Data\Azureus\dht\contacts.dat
c:\documents and settings\Andrew\Application Data\Azureus\dht\diverse.dat
c:\documents and settings\Andrew\Application Data\Azureus\dht\general.dat
c:\documents and settings\Andrew\Application Data\Azureus\dht\version.dat
c:\documents and settings\Andrew\Application Data\Azureus\downloads.config
c:\documents and settings\Andrew\Application Data\Azureus\downloads.config.bak
c:\documents and settings\Andrew\Application Data\Azureus\friends.config
c:\documents and settings\Andrew\Application Data\Azureus\friends.config.bak
c:\documents and settings\Andrew\Application Data\Azureus\ipfilter.cache
c:\documents and settings\Andrew\Application Data\Azureus\logs\alerts_1.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\AutoSpeed_1.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\AutoSpeed_2.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\AutoSpeedSearchHistory_1.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\AutoSpeedSearchHistory_2.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\clientid_1.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\debug_1.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\debug_2.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\Friends_1.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\Friends_2.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\MetaSearch_1.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\NetStatus_1.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\save\1230657581084_alerts_1.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\save\1230657581084_AutoSpeed_1.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\save\1230657581084_AutoSpeed_2.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\save\1230657581084_AutoSpeedSearchHistory_1.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\save\1230657581084_AutoSpeedSearchHistory_2.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\save\1230657581084_clientid_1.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\save\1230657581084_debug_1.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\save\1230657581084_debug_2.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\save\1230657581084_Friends_1.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\save\1230657581084_Friends_2.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\save\1230657581084_MetaSearch_1.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\save\1230657581084_NetStatus_1.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\save\1230657581084_seltrace_1.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\save\1230657581084_SpeedMan_1.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\save\1230657581084_SpeedMan_2.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\save\1230657581084_Subscriptions_1.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\save\1230657581084_thread_1.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\save\1230657581084_thread_2.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\save\1230657581084_v3.ads_1.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\save\1230657581084_v3.CMsgr_1.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\save\1230657581084_v3.emp_1.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\save\1230657581084_v3.Friends_1.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\save\1230657581084_v3.Friends_2.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\save\1230657581084_v3.PMsgr_1.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\save\1230657581084_v3.Stream_1.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\save\1230932929156_alerts_1.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\save\1230932929156_AutoSpeed_1.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\save\1230932929156_AutoSpeed_2.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\save\1230932929156_AutoSpeedSearchHistory_1.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\save\1230932929156_AutoSpeedSearchHistory_2.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\save\1230932929156_clientid_1.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\save\1230932929156_debug_1.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\save\1230932929156_debug_2.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\save\1230932929156_Friends_1.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\save\1230932929156_Friends_2.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\save\1230932929156_MetaSearch_1.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\save\1230932929156_NetStatus_1.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\save\1230932929156_seltrace_1.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\save\1230932929156_SpeedMan_1.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\save\1230932929156_SpeedMan_2.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\save\1230932929156_Subscriptions_1.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\save\1230932929156_thread_1.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\save\1230932929156_thread_2.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\save\1230932929156_v3.ads_1.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\save\1230932929156_v3.CMsgr_1.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\save\1230932929156_v3.emp_1.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\save\1230932929156_v3.Friends_1.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\save\1230932929156_v3.Friends_2.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\save\1230932929156_v3.PMsgr_1.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\save\1230932929156_v3.Stream_1.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\seltrace_1.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\SpeedMan_1.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\SpeedMan_2.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\Subscriptions_1.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\thread_1.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\thread_2.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\v3.ads_1.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\v3.CMsgr_1.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\v3.emp_1.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\v3.Friends_1.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\v3.Friends_2.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\v3.PMsgr_1.log
c:\documents and settings\Andrew\Application Data\Azureus\logs\v3.Stream_1.log
c:\documents and settings\Andrew\Application Data\Azureus\metasearch.config
c:\documents and settings\Andrew\Application Data\Azureus\metasearch.config.bak
c:\documents and settings\Andrew\Application Data\Azureus\net\pm_11260.dat
c:\documents and settings\Andrew\Application Data\Azureus\net\pm_default.dat
c:\documents and settings\Andrew\Application Data\Azureus\plugins\azump\azump_1.2.jar
c:\documents and settings\Andrew\Application Data\Azureus\plugins\azump\azump_1.2.zip
c:\documents and settings\Andrew\Application Data\Azureus\plugins\azump\mplayer.exe
c:\documents and settings\Andrew\Application Data\Azureus\plugins\azump\mplayer\config
c:\documents and settings\Andrew\Application Data\Azureus\sidebarauto.config
c:\documents and settings\Andrew\Application Data\Azureus\sidebarauto.config.bak
c:\documents and settings\Andrew\Application Data\Azureus\subs\A57341AB2AA7A98D5F19.vuze
c:\documents and settings\Andrew\Application Data\Azureus\subs\CEA06BACAA04C3DAA925.vuze
c:\documents and settings\Andrew\Application Data\Azureus\subs\F79561DE25ADCAEF8BE3.vuze
c:\documents and settings\Andrew\Application Data\Azureus\subscriptions.config
c:\documents and settings\Andrew\Application Data\Azureus\subscriptions.config.bak
c:\documents and settings\Andrew\Application Data\Azureus\tables.config
c:\documents and settings\Andrew\Application Data\Azureus\tables.config.bak
c:\documents and settings\Andrew\Application Data\Azureus\timingstats.dat
c:\documents and settings\Andrew\Application Data\Azureus\tmp\AZU57760.tmp
c:\documents and settings\Andrew\Application Data\Azureus\tmp\AZU57761.tmp
c:\documents and settings\Andrew\Application Data\Azureus\tmp\AZU57762.tmp
c:\documents and settings\Andrew\Application Data\Azureus\tmp\AZU57763.tmp
c:\documents and settings\Andrew\Application Data\Azureus\tmp\AZU57764.tmp
c:\documents and settings\Andrew\Application Data\Azureus\tmp\AZU57765.tmp
c:\documents and settings\Andrew\Application Data\Azureus\tmp\AZU57766.tmp
c:\documents and settings\Andrew\Application Data\Azureus\tmp\AZU57767.tmp
c:\documents and settings\Andrew\Application Data\Azureus\tmp\AZU57769.tmp
c:\documents and settings\Andrew\Application Data\Azureus\tmp\AZU57770.tmp
c:\documents and settings\Andrew\Application Data\Azureus\torrents\AZU16121.tmp
c:\documents and settings\Andrew\Application Data\Azureus\torrents\AZU16125.tmp
c:\documents and settings\Andrew\Application Data\Azureus\torrents\AZU29922.tmp
c:\documents and settings\Andrew\Application Data\Azureus\torrents\AZU35932.tmp
c:\documents and settings\Andrew\Application Data\Azureus\torrents\AZU38074.tmp
c:\documents and settings\Andrew\Application Data\Azureus\torrents\AZU38210.tmp
c:\documents and settings\Andrew\Application Data\Azureus\torrents\AZU38214.tmp
c:\documents and settings\Andrew\Application Data\Azureus\torrents\AZU44108.tmp
c:\documents and settings\Andrew\Application Data\Azureus\torrents\AZU44115.tmp
c:\documents and settings\Andrew\Application Data\Azureus\tracker.config
c:\documents and settings\Andrew\Application Data\Azureus\tracker.config.bak
c:\documents and settings\Andrew\Application Data\Azureus\unsentdata.config
c:\documents and settings\Andrew\Application Data\Azureus\unsentdata.config.bak
c:\documents and settings\Andrew\Application Data\Azureus\update.log
c:\documents and settings\Andrew\Application Data\Azureus\update.properties
c:\documents and settings\Andrew\Application Data\Azureus\v3.Friends.dat
c:\documents and settings\Andrew\Application Data\Azureus\v3.Friends.dat.bak
c:\documents and settings\Andrew\Application Data\Azureus\VuzeActivities.config
c:\documents and settings\Andrew\Application Data\Azureus\VuzeActivities.config.bak
c:\documents and settings\Andrew\Application Data\LimeWire
c:\documents and settings\Andrew\Application Data\LimeWire\active.mojito
c:\documents and settings\Andrew\Application Data\LimeWire\createtimes.cache
c:\documents and settings\Andrew\Application Data\LimeWire\fileurns.bak
c:\documents and settings\Andrew\Application Data\LimeWire\fileurns.cache
c:\documents and settings\Andrew\Application Data\LimeWire\filters.props
c:\documents and settings\Andrew\Application Data\LimeWire\gnutella.net
c:\documents and settings\Andrew\Application Data\LimeWire\installation.props
c:\documents and settings\Andrew\Application Data\LimeWire\library.dat
c:\documents and settings\Andrew\Application Data\LimeWire\limewire.props
c:\documents and settings\Andrew\Application Data\LimeWire\mojito.props
c:\documents and settings\Andrew\Application Data\LimeWire\passive.mojito
c:\documents and settings\Andrew\Application Data\LimeWire\questions.props
c:\documents and settings\Andrew\Application Data\LimeWire\responses.cache
c:\documents and settings\Andrew\Application Data\LimeWire\simpp.xml
c:\documents and settings\Andrew\Application Data\LimeWire\spam.dat
c:\documents and settings\Andrew\Application Data\LimeWire\tables.props
c:\documents and settings\Andrew\Application Data\LimeWire\themes\windows_theme.lwtp
c:\documents and settings\Andrew\Application Data\LimeWire\themes\windows_theme\
01_star.gif
c:\documents and settings\Andrew\Application Data\LimeWire\themes\windows_theme\
02_star.gif
c:\documents and settings\Andrew\Application Data\LimeWire\themes\windows_theme\
03_star.gif
c:\documents and settings\Andrew\Application Data\LimeWire\themes\windows_theme\
04_star.gif
c:\documents and settings\Andrew\Application Data\LimeWire\themes\windows_theme\
05_star.gif
c:\documents and settings\Andrew\Application Data\LimeWire\themes\windows_theme\chat.gif
c:\documents and settings\Andrew\Application Data\LimeWire\themes\windows_theme\forward_dn.gif
c:\documents and settings\Andrew\Application Data\LimeWire\themes\windows_theme\forward_up.gif
c:\documents and settings\Andrew\Application Data\LimeWire\themes\windows_theme\kill.gif
c:\documents and settings\Andrew\Application Data\LimeWire\themes\windows_theme\kill_on.gif
c:\documents and settings\Andrew\Application Data\LimeWire\themes\windows_theme\logo.png
c:\documents and settings\Andrew\Application Data\LimeWire\themes\windows_theme\notsearching.png
c:\documents and settings\Andrew\Application Data\LimeWire\themes\windows_theme\pause_dn.gif
c:\documents and settings\Andrew\Application Data\LimeWire\themes\windows_theme\pause_up.gif
c:\documents and settings\Andrew\Application Data\LimeWire\themes\windows_theme\play_dn.gif
c:\documents and settings\Andrew\Application Data\LimeWire\themes\windows_theme\play_up.gif
c:\documents and settings\Andrew\Application Data\LimeWire\themes\windows_theme\question.gif
c:\documents and settings\Andrew\Application Data\LimeWire\themes\windows_theme\rewind_dn.gif
c:\documents and settings\Andrew\Application Data\LimeWire\themes\windows_theme\rewind_up.gif
c:\documents and settings\Andrew\Application Data\LimeWire\themes\windows_theme\searching.gif
c:\documents and settings\Andrew\Application Data\LimeWire\themes\windows_theme\stop_dn.gif
c:\documents and settings\Andrew\Application Data\LimeWire\themes\windows_theme\stop_up.gif
c:\documents and settings\Andrew\Application Data\LimeWire\themes\windows_theme\theme.txt
c:\documents and settings\Andrew\Application Data\LimeWire\themes\windows_theme\version.txt
c:\documents and settings\Andrew\Application Data\LimeWire\themes\windows_theme\warning.gif
c:\documents and settings\Andrew\Application Data\LimeWire\ttrees.cache
c:\documents and settings\Andrew\Application Data\LimeWire\ttroot.cache
c:\documents and settings\Andrew\Application Data\LimeWire\version.xml
c:\documents and settings\Andrew\Application Data\LimeWire\xml\data\audio.sxml
c:\program files\Azureus
c:\program files\Azureus\plugins\azemp\azemp_2.0.14.jar
c:\program files\Azureus\plugins\azemp\azemp_2.0.14.zip
c:\program files\Azureus\plugins\azemp\azemp_2.0.16.jar
c:\program files\Azureus\plugins\azemp\azemp_2.0.16.zip
c:\program files\Azureus\plugins\azemp\azemp_2.0.28.jar
c:\program files\Azureus\plugins\azemp\azemp_2.0.28.zip
c:\program files\Azureus\plugins\azemp\azemp_2.0.32.jar
c:\program files\Azureus\plugins\azemp\azemp_2.0.32.zip
c:\program files\Azureus\plugins\azemp\azmplay.exe.bak
c:\program files\Azureus\plugins\azemp\cp1250-a.raw.bak
c:\program files\Azureus\plugins\azemp\cp1250-b.raw.bak
c:\program files\Azureus\plugins\azemp\font.desc.bak
c:\program files\Azureus\plugins\azemp\mplayer\config
c:\program files\Azureus\plugins\azemp\osd-mplayer-a.raw.bak
c:\program files\Azureus\plugins\azemp\osd-mplayer-b.raw.bak
c:\program files\Azureus\plugins\azemp\plugin.properties_2.0.14
c:\program files\Azureus\plugins\azemp\plugin.properties_2.0.16
c:\program files\Azureus\plugins\azemp\plugin.properties_2.0.28
c:\program files\Azureus\plugins\azemp\plugin.properties_2.0.32
c:\program files\Azureus\plugins\azupnpav\azupnpav_0.2.1.jar
c:\program files\Azureus\plugins\azupnpav\azupnpav_0.2.1.zip
c:\program files\Azureus\plugins\azupnpav\azupnpav_0.2.2.jar
c:\program files\Azureus\plugins\azupnpav\azupnpav_0.2.2.zip
c:\program files\Azureus\plugins\azupnpav\plugin.properties_0.2.1
c:\program files\Azureus\plugins\azupnpav\plugin.properties_0.2.2
.
((((((((((((((((((((((((( Files Created from 2008-12-14 to 2009-01-14 )))))))))))))))))))))))))))))))
.
2009-01-13 18:59 . 2009-01-14 07:41 <DIR> d-------- c:\windows\system32\drivers\Avg
2009-01-13 18:59 . 2009-01-13 18:59 97,928 --a------ c:\windows\system32\drivers\avgldx86.sys
2009-01-13 18:59 . 2009-01-13 18:59 76,040 --a------ c:\windows\system32\drivers\avgtdix.sys
2009-01-13 18:59 . 2009-01-13 18:59 10,520 --a------ c:\windows\system32\avgrsstx.dll
2009-01-09 20:39 . 2009-01-09 20:39 <DIR> d--hs---- C:\found.000
2009-01-07 21:11 . 2009-01-07 21:11 <DIR> d-------- c:\program files\Trend Micro
2009-01-06 21:20 . 2009-01-06 21:20 213 --a------ c:\windows\wininit.ini
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-13 22:59 --------- d-----w c:\documents and settings\All Users\Application Data\Avg8
2009-01-07 02:34 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-01-07 00:45 --------- d-----w c:\program files\Spybot - Search & Destroy
2009-01-03 19:30 --------- d-----w c:\program files\DivX
2008-12-13 03:01 --------- d-----w c:\program files\PartyGaming
2008-12-12 07:06 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2008-11-20 11:52 3,532 ----a-w C:\drmHeader.bin
2008-05-19 22:34 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008051920080520\index.dat
.
((((((((((((((((((((((((((((( snapshot@2009-01-13_11.00.26.35 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-01-13 22:59:46 26,824 ----a-w c:\windows\system32\drivers\avgmfx86.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-04-05 94208]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-04-05 77824]
"Persistence"="c:\windows\system32\igfxpers.exe" [2005-04-05 114688]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-03-28 413696]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-01-13 1261336]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Andrew^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\documents and settings\Andrew\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 21:16 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2007-08-03 11:51 202024 c:\program files\Common Files\Nero\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
--a------ 2005-08-05 13:56 64512 c:\windows\ehome\ehtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2008-04-13 20:12 1695232 c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
--a------ 2007-08-08 08:25 1828136 c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Nero PhotoShow Media Manager]
--a------ 2007-04-27 14:22 312848 c:\progra~1\Nero\PHOTOS~1\data\Xtras\mssysmgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2007-03-01 14:57 153136 c:\program files\Common Files\Nero\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Orb]
--a------ 2008-03-31 21:54 507904 c:\program files\Winamp Remote\bin\OrbTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-03-28 22:37 413696 c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-02-22 03:25 144784 c:\program files\Java\jre1.6.0_05\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
--a------ 2005-03-22 18:20 339968 c:\windows\stsystra.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Winamp Remote\\bin\\Orb.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe"=
"c:\\Program Files\\Nero\\Nero8\\Nero Home\\NeroHome.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-01-13 97928]
R4 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-01-13 875288]
R4 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-01-13 231704]
R4 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-01-13 76040]
R4 pgsql-8.3;PostgreSQL Database Server 8.3;c:\program files\PostgreSQL\8.3\bin\pg_ctl.exe [2008-02-01 65536]
.
Contents of the 'Scheduled Tasks' folder
2009-01-08 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 16:57]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-01-14 07:54:07
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
c:\program files\PostgreSQL\8.3\bin\postgres.exe
c:\windows\ehome\mcrdsvc.exe
c:\program files\PostgreSQL\8.3\bin\postgres.exe
c:\program files\PostgreSQL\8.3\bin\postgres.exe
c:\program files\PostgreSQL\8.3\bin\postgres.exe
c:\program files\PostgreSQL\8.3\bin\postgres.exe
c:\program files\PostgreSQL\8.3\bin\postgres.exe
c:\program files\AVG\AVG8\avgrsx.exe
.
**************************************************************************
.
Completion time: 2009-01-14 7:56:56 - machine was rebooted
ComboFix-quarantined-files.txt 2009-01-14 11:56:51
ComboFix2.txt 2009-01-13 15:01:26
Pre-Run: 142,228,738,048 bytes free
Post-Run: 142,230,040,576 bytes free
352 --- E O F --- 2008-12-17 21:09:16
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:00:20 AM, on 1/14/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\andyjd.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-21-823518204-1677128483-839522115-1006\..\RunOnce: [NeroHomeFirstStart] "C:\Program Files\Common Files\Nero\Lib\NMFirstStart.exe" (User 'postgres')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) -
http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.microsoft.com/win...ls/en/x86/client/wuweb_site.cab?1207191747390
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) -
http://sdlc-esd.sun.com/ESD40/JSCDL...-jc.cab&File=jinstall-6u5-windows-i586-jc.cab
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) -
http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} (Domino Web Access 7 Control) -
https://www.avivaavantage.ca/dwa7W.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: dlcc_device - Unknown owner - C:\WINDOWS\system32\dlcccoms.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: PostgreSQL Database Server 8.3 (pgsql-8.3) - PostgreSQL Global Development Group - C:\Program Files\PostgreSQL\8.3\bin\pg_ctl.exe
--
End of file - 6271 bytes