Here is the Combofix txt. I notice there is heaps of Limewire stuff on there, what's that all about? We've never had trouble before with this site.
ComboFix 08-07-31.01 - angela 2008-07-31 21:46:19.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.166 [GMT -7:00]
Running from: C:\Documents and Settings\angela\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\angela\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
C:\WINDOWS\system32\kjkUvGgh.ini
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Jen\Application Data\LimeWire
C:\Documents and Settings\Jen\Application Data\LimeWire\active.mojito
C:\Documents and Settings\Jen\Application Data\LimeWire\createtimes.cache
C:\Documents and Settings\Jen\Application Data\LimeWire\fileurns.bak
C:\Documents and Settings\Jen\Application Data\LimeWire\fileurns.cache
C:\Documents and Settings\Jen\Application Data\LimeWire\filters.props
C:\Documents and Settings\Jen\Application Data\LimeWire\installation.props
C:\Documents and Settings\Jen\Application Data\LimeWire\library.dat
C:\Documents and Settings\Jen\Application Data\LimeWire\limewire.props
C:\Documents and Settings\Jen\Application Data\LimeWire\mojito.props
C:\Documents and Settings\Jen\Application Data\LimeWire\questions.props
C:\Documents and Settings\Jen\Application Data\LimeWire\simpp.xml
C:\Documents and Settings\Jen\Application Data\LimeWire\tables.props
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme.lwtp
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\
01_star.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\
02_star.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\
03_star.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\
04_star.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\
05_star.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\button1.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\button1_press.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\button2.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\button2_press.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\button3.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\button3_press.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\button4.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\button4_press.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\button5.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\button5_press.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\chat.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\connections.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\dir_closed.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\dir_open.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\forward_dn.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\forward_up.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\kill.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\kill_on.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\library.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\logo.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\monitor.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\notsearching.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\pause_dn.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\pause_up.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\play_dn.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\play_up.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\plug.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\question.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\rewind_dn.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\rewind_up.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\search.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\searching.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\shopping.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\splash.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\stop_dn.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\stop_up.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\theme.txt
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\warning.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\windows_theme.lwtp
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\windows_theme\
01_star.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\windows_theme\
02_star.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\windows_theme\
03_star.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\windows_theme\
04_star.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\windows_theme\
05_star.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\windows_theme\chat.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\windows_theme\forward_dn.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\windows_theme\forward_up.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\windows_theme\kill.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\windows_theme\kill_on.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\windows_theme\logo.png
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\windows_theme\notsearching.pn g
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\windows_theme\pause_dn.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\windows_theme\pause_up.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\windows_theme\play_dn.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\windows_theme\play_up.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\windows_theme\question.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\windows_theme\rewind_dn.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\windows_theme\rewind_up.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\windows_theme\searching.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\windows_theme\stop_dn.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\windows_theme\stop_up.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\windows_theme\theme.txt
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\windows_theme\version.txt
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\windows_theme\warning.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\version.xml
C:\WINDOWS\system32\kjkUvGgh.ini
.
((((((((((((((((((((((((( Files Created from 2008-07-01 to 2008-08-01 )))))))))))))))))))))))))))))))
.
2008-07-31 20:30 . 2008-07-31 20:30 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Gogii
2008-07-29 20:48 . 2008-07-29 20:48 <DIR> d-------- C:\Documents and Settings\angela\Application Data\Malwarebytes
2008-07-29 20:48 . 2008-07-29 20:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-28 09:15 . 2008-07-28 09:15 <DIR> d-------- C:\WINDOWS\system32\Adobe
2008-07-28 03:05 . 2008-07-28 03:05 <DIR> d-------- C:\Deckard
2008-07-21 12:57 . 2008-07-21 12:56 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2008-07-21 12:56 . 2008-07-21 13:34 <DIR> d-------- C:\Documents and Settings\angela\.housecall6.6
2008-07-21 12:49 . 2008-07-22 15:55 <DIR> d-------- C:\Program Files\Trend Micro
2008-07-20 15:41 . 2008-07-20 15:41 <DIR> d-------- C:\Documents and Settings\angela\Application Data\Ahead
2008-07-20 15:41 . 2008-07-20 15:41 0 --a------ C:\WINDOWS\Irremote.ini
2008-07-20 15:01 . 2008-07-20 15:01 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Ahead
2008-07-20 14:34 . 2008-07-20 14:34 <DIR> d-------- C:\Program Files\Nero
2008-07-20 14:34 . 2008-07-21 09:51 <DIR> d-------- C:\Program Files\Common Files\Ahead
2008-07-20 14:34 . 2008-07-20 14:34 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Nero
2008-07-19 11:08 . 2008-07-20 09:29 <DIR> d-------- C:\Documents and Settings\angela\Application Data\muvee Technologies
2008-07-18 10:14 . 2008-07-31 07:03 <DIR> d--h----- C:\$AVG8.VAULT$
2008-07-18 10:00 . 2008-07-18 10:00 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-07-18 08:12 . 2008-07-31 08:23 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-07-18 08:12 . 2008-07-18 10:00 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-07-18 08:12 . 2008-07-18 10:01 76,040 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-07-18 08:11 . 2008-07-18 08:11 <DIR> d-------- C:\Program Files\AVG
2008-07-18 08:11 . 2008-07-18 08:11 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-07-17 21:05 . 2008-07-18 07:52 <DIR> d--hs---- C:\WINDOWS\ZGF5
2008-07-17 10:48 . 2008-07-17 10:48 149 --a------ C:\WINDOWS\wininit.ini
2008-07-17 09:56 . 2008-07-18 14:59 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-07-17 09:56 . 2008-07-18 15:10 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-17 08:45 . 2008-07-17 09:24 <DIR> d---s---- C:\Documents and Settings\Administrator
2008-07-16 08:48 . 2008-07-16 08:40 109,568 --a------ C:\WINDOWS\system32\pxinsi64.exe
2008-07-16 08:48 . 2008-07-16 08:40 108,544 --a------ C:\WINDOWS\system32\pxcpyi64.exe
2008-07-14 17:24 . 2008-07-14 17:25 <DIR> d-------- C:\Documents and Settings\angela\Application Data\gtk-2.0
2008-07-14 17:23 . 2008-07-14 17:26 <DIR> d-------- C:\Documents and Settings\angela\.gimp-2.4
2008-07-14 14:36 . 2008-07-14 14:36 <DIR> d-------- C:\Program Files\Aurora Digital Imaging
2008-07-14 14:34 . 2008-07-14 14:34 <DIR> d-------- C:\WINDOWS\Downloaded Installations
2008-07-14 09:10 . 2008-07-14 09:12 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-07-14 07:32 . 2008-07-14 07:32 <DIR> d-------- C:\Program Files\Windows Defender
2008-07-14 06:27 . 2008-07-14 06:27 <DIR> d-------- C:\WINDOWS\system32\URTTEMP
2008-07-14 06:18 . 2008-07-14 13:54 2,582 --ahs---- C:\WINDOWS\system32\cffMVvut.ini
2008-07-14 06:13 . 2008-07-15 05:28 <DIR> d-------- C:\WINDOWS\system32\olixds18
2008-07-14 06:13 . 2008-07-31 19:24 <DIR> d-------- C:\Temp
2008-07-13 14:18 . 2008-07-13 14:18 <DIR> d-------- C:\Documents and Settings\angela\Application Data\FastStone
2008-07-10 22:12 . 2008-07-10 22:12 <DIR> d-------- C:\Program Files\iPod
2008-07-10 21:54 . 2008-07-10 21:54 <DIR> d-------- C:\Program Files\Safari
2008-07-02 12:28 . 2008-07-02 12:28 <DIR> d-------- C:\Program Files\DVDVideoSoft
2008-07-02 12:28 . 2008-07-14 10:42 <DIR> d-------- C:\Program Files\Common Files\DVDVideoSoft
2008-07-02 12:28 . 2008-07-02 16:14 <DIR> d-------- C:\DVDVideoSoft
2008-07-02 12:28 . 2002-01-05 15:37 344,064 --a------ C:\WINDOWS\system32\msvcr70.dll
2008-07-01 17:39 . 2008-07-01 17:39 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\IsolatedStorage
2008-07-01 17:31 . 2008-07-02 16:16 <DIR> d-------- C:\Program Files\Flypaper Beta
2008-07-01 17:24 . 2008-07-01 17:24 <DIR> d-------- C:\Program Files\MSBuild
2008-07-01 17:23 . 2008-07-01 17:23 <DIR> d-------- C:\WINDOWS\system32\XPSViewer
2008-07-01 17:23 . 2008-07-01 17:23 <DIR> d-------- C:\Program Files\Reference Assemblies
2008-07-01 17:22 . 2006-06-29 13:07 14,048 --a------ C:\WINDOWS\system32\spmsg2.dll
2008-07-01 17:17 . 2008-07-01 17:17 <DIR> d-------- C:\Program Files\MSXML 6.0
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2008-08-01 04:50 --------- d-----w C:\Documents and Settings\angela\Application Data\Skype
2008-07-22 16:29 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-07-21 23:45 --------- d-----w C:\Program Files\Picasa2
2008-07-20 20:50 --------- d-----w C:\Program Files\Ahead
2008-07-20 13:33 --------- d-----w C:\Program Files\Incomplete
2008-07-16 16:42 --------- d-----w C:\Program Files\Common Files\Adobe
2008-07-14 22:18 129 ----a-w C:\WINDOWS\Fonts\1001freefonts.txt
2008-07-14 20:36 --------- d-----w C:\Program Files\Java
2008-07-13 14:03 --------- d-----w C:\Documents and Settings\angela\Application Data\Apple Computer
2008-07-11 05:12 --------- d-----w C:\Program Files\iTunes
2008-07-11 05:08 --------- d-----w C:\Program Files\QuickTime
2008-07-10 16:35 32,000 ----a-w C:\WINDOWS\system32\drivers\usbaapl.sys
2008-06-29 04:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-19 23:02 --------- d-----w C:\Documents and Settings\Jen\Application Data\Apple Computer
2008-06-13 13:10 272,128 ----a-w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-10 10:04 --------- d-----w C:\Program Files\Microsoft Works
2008-06-08 17:38 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-04-07 20:00 774,144 ----a-w C:\Program Files\RngInterstitial.dll
2008-04-07 00:38 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
.
((((((((((((((((((((((((((((( snapshot@2008-07-30_23.34.31.00 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-08-01 10:04:53 2,216 ----a-w C:\WINDOWS\SoftwareDistribution\EventCache\{2069A2 92-9FED-4ED5-BE82-53C8AD47C81E}.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2006-09-29 17:25 21871656]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2008-02-25 18:23 443968]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00 15360]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 11:34 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-10 09:47 116040]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-05-27 10:50 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-07-10 10:51 289064]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-07-18 10:01 1232152]
"MSConfig"="C:\WINDOWS\pchealth\helpctr\Binaries\M SCONFIG.EXE" [2004-08-04 05:00 158208]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 13:47 57344 C:\WINDOWS\Alcxmntr.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1 \DW\dwtrig20.exe" [2007-03-22 19:29 39264]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.HFYU"= huffyuv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
--------- 2008-07-07 09:42 2156368 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\ \SAGENT4.EXE"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-07-18 10:00]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-07-18 10:00]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-07-18 10:00]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-07-18 10:01]
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\{9ef3de30-ff49-11dc-9a4a-806d6172696f}]
\Shell\AutoRun\command - E:\Info.exe folder.htt 480 480
.
Contents of the 'Scheduled Tasks' folder
2008-07-19 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 17:57]
2008-08-01 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]
2008-08-01 C:\WINDOWS\Tasks\MP Scheduled Scan.job
- C:\Program Files\Windows Defender\MpCmdRun.exe [2006-11-03 19:20]
.
************************************************** ************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-08-01 08:00:29
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\iPod\bin\iPodService.exe
.
************************************************** ************************
.
Completion time: 2008-08-01 8:13:10 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-01 15:13:05
ComboFix2.txt 2008-08-01 02:53:10
ComboFix3.txt 2008-07-31 06:35:11
Pre-Run: 9,798,717,440 bytes free
Post-Run: 9,766,653,952 bytes free
267 --- E O F --- 2008-08-01 10:03:02
HIJACK THIS LOG
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:55:30 PM, on 8/1/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
MSN.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
Live Search
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
Live Search
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
MSN.com
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: TrendProtect - {F83BE649-1CC3-48EE-B2E2-0826CEF3822A} - C:\Program Files\Trend Micro\TrendProtect\MSIE\wrs.dll
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe " -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe " -t (User 'Default user')
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites -
Add to Windows Live Favorites
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Skype add-on - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) -
https://h20436.www2.hp.com/ediags/de...e/HPDEXAXO.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) -
http://paris.ville.orange.fr/CO/acti...CamControl.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/ge...sh/swflash.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: trendprotect - {BC3A5F6F-12A0-4B14-A184-32939F413823} - C:\Program Files\Trend Micro\TrendProtect\MSIE\wrs.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobi