Here is the combofix log. It also asked me to write down several file names during the initial scan that had to do with rootkit activity so I have those if you need them.
ComboFix 09-07-29.03 - Owner 07/29/2009 16:18.1.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.511.193 [GMT -7:00]
Running from: c:\documents and settings\Owner\Desktop\Commy.exe
Command switches used :: c:\documents and settings\Owner\Desktop\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\ALLUSE~1\APPLIC~1\Microsoft\Network\Downloader\qmgr0.dat
c:\docume~1\ALLUSE~1\APPLIC~1\Microsoft\Network\Downloader\qmgr1.dat
c:\progra~1\COMMON~1\{3C44B~1
c:\progra~1\COMMON~1\{6C44B~1
c:\program files\Common Files\SLMSS
c:\recycler\S-1-5-21-1915603095-2777713432-2000865000-1003
c:\recycler\S-1-5-21-2795692431-2410440851-3507117092-1003
c:\windows\cdmxtras
c:\windows\Fonts\acrsec.fon
c:\windows\Install.txt
c:\windows\Installer\1018a3.msi
c:\windows\Installer\1018aa.msi
c:\windows\Installer\11691f.msi
c:\windows\Installer\128cb.msi
c:\windows\Installer\12b892.msi
c:\windows\Installer\14d23b.msi
c:\windows\Installer\14d243.msi
c:\windows\Installer\1fb14.msp
c:\windows\Installer\1fb52.msp
c:\windows\Installer\1fb8a.msi
c:\windows\Installer\233b13.msi
c:\windows\Installer\24eba88.msi
c:\windows\Installer\25c226.msi
c:\windows\Installer\2609df.msi
c:\windows\Installer\27d3a6.msi
c:\windows\Installer\2921ff.msi
c:\windows\Installer\39468e.msi
c:\windows\Installer\3b7567.msi
c:\windows\Installer\3dae14.msi
c:\windows\Installer\400615.msi
c:\windows\Installer\45a5ca.msi
c:\windows\Installer\47abcc.msi
c:\windows\Installer\47abd2.msi
c:\windows\Installer\486e09.msi
c:\windows\Installer\5efa5.msi
c:\windows\Installer\704aae.msi
c:\windows\Installer\704ab9.msi
c:\windows\Installer\786cc.msi
c:\windows\Installer\8333aa.msi
c:\windows\Installer\a28c8.msi
c:\windows\Installer\aaf779.msi
c:\windows\Installer\aaf77c.msi
c:\windows\Installer\b08855.msi
c:\windows\Installer\b4cf46.msi
c:\windows\Installer\b73b7b.msi
c:\windows\Installer\b73b81.msi
c:\windows\Installer\b73b87.msi
c:\windows\Installer\b73b8d.msi
c:\windows\Installer\b73b93.msi
c:\windows\Installer\b7e4a.msi
c:\windows\Installer\bb6df.msi
c:\windows\Installer\c1117c.msi
c:\windows\patch.exe
c:\windows\Readme.txt
c:\windows\smbols~1
c:\windows\system32\drivers\TDSSserv.sys
c:\windows\system32\drivers\UACqyisdhpbcbkssqcfr.sys
c:\windows\system32\iAlmcoin.dll
c:\windows\system32\Install.txt
c:\windows\system32\skinboxer43.dll
c:\windows\system32\sklh.dat
c:\windows\system32\uacinit.dll
c:\windows\system32\UACjmjpjmpqdgwcndmgj.dll
c:\windows\system32\UACkjlwkktcvonyrudvq.dll
c:\windows\system32\UAClxbfpxvgbvfuvtmvr.dat
c:\windows\system32\UACmstsfvmydbawqibip.db
c:\windows\system32\UACpqjpibeexevnftiob.dll
c:\windows\system32\UACqiuoeuidrtkjtutub.dll
c:\windows\system32\UACvwauwbparrpiewmoe.dll
c:\windows\system32\vimc.exe
D:\Autorun.inf
----- BITS: Possible infected sites -----
hxxp://download.linksys.com
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_TDSSSERV
-------\Service_UACd.sys
-------\Legacy_RPCTFTPD
((((((((((((((((((((((((( Files Created from 2009-06-28 to 2009-07-29 )))))))))))))))))))))))))))))))
.
2009-07-28 23:04 . 2009-07-28 23:11 15 ----a-w- C:\settings.dat
2009-07-28 23:03 . 2009-07-28 16:14 471040 ----a-w- C:\RootRepeal.exe
2009-07-28 23:02 . 2009-07-28 23:02 463738 ----a-w- C:\RootRepeal.zip
2009-07-28 21:08 . 2009-07-28 21:08 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\Office Genuine Advantage
2009-07-28 18:00 . 2009-07-28 18:04 -------- d-----w- C:\HostsXpert
2009-07-28 17:59 . 2009-07-28 17:59 353485 ----a-w- C:\HostsXpert.zip
2009-07-27 19:08 . 2009-07-27 19:08 -------- d-----w- c:\program files\Trend Micro
2009-07-23 08:15 . 2009-07-23 08:15 -------- d-----w- c:\program files\Eusing Free Registry Cleaner
2009-07-23 07:46 . 2009-07-24 18:16 -------- d-----w- c:\program files\SpybotX - Search&Destroy
2009-07-22 20:55 . 2009-07-22 20:55 -------- d-----w- c:\documents and settings\Administrator.FAMILY-COMPUTER\Application Data\Malwarebytes
2009-07-22 06:09 . 2009-07-13 20:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-22 06:09 . 2009-07-13 20:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-07-22 06:09 . 2009-07-22 06:10 -------- d-----w- c:\program files\Kyle's Anti-Malware
2009-07-21 23:24 . 2009-07-21 23:24 -------- d-----w- c:\program files\CCleaner
2009-07-21 21:23 . 2009-07-21 21:23 604416 ----a-w- c:\windows\system32\TUProgSt.exe
2009-07-21 21:23 . 2009-04-27 21:21 28928 ----a-w- c:\windows\system32\uxtuneup.dll
2009-07-21 21:23 . 2009-07-21 21:23 361216 ----a-w- c:\windows\system32\TuneUpDefragService.exe
2009-07-21 21:22 . 2009-07-21 21:24 -------- d-----w- c:\program files\TuneUp Utilities 2009
2009-07-21 21:22 . 2009-07-21 21:22 -------- d-sh--w- c:\docume~1\ALLUSE~1\APPLIC~1\{55A29068-F2CE-456C-9148-C869879E2357}
2009-07-10 05:20 . 2009-07-18 00:17 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\FLVService
2009-07-10 05:20 . 2009-07-10 05:20 -------- d-----w- c:\windows\Ask & Record Toolbar
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-29 22:49 . 2009-05-14 04:12 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\avg8
2009-07-28 20:59 . 2009-01-15 01:00 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-07-28 20:46 . 2003-08-29 03:15 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-07-28 20:29 . 2003-08-29 03:16 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\Symantec
2009-07-28 20:26 . 2004-07-23 08:17 -------- d-----w- c:\program files\Common Files\Java
2009-07-28 20:26 . 2003-11-03 03:19 -------- d-----w- c:\program files\Java
2009-07-28 20:04 . 2008-04-17 02:44 -------- d-----w- c:\documents and settings\Owner\Application Data\uTorrent
2009-07-28 18:36 . 2006-12-27 22:06 -------- d---a-w- c:\docume~1\ALLUSE~1\APPLIC~1\TEMP
2009-07-28 18:11 . 2007-01-28 05:53 -------- d-----w- c:\program files\eMulePlus
2009-07-24 18:16 . 2003-12-20 22:43 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2009-07-23 17:36 . 2003-12-20 22:42 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-07-21 22:15 . 2008-11-11 04:12 -------- d-----w- c:\program files\Microsoft Silverlight
2009-07-17 18:44 . 2009-05-14 04:12 335752 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-07-10 06:27 . 2009-04-20 07:29 -------- d-----w- c:\program files\Media Catcher
2009-07-10 06:24 . 2009-04-20 07:30 323584 ----a-w- c:\windows\system32\AUDIOGENIE2.DLL
2009-06-28 22:38 . 2009-06-28 15:42 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\AVG Security Toolbar
2009-06-28 15:42 . 2009-06-28 15:42 -------- d-----w- c:\documents and settings\LocalService\Application Data\AVGTOOLBAR
2009-06-28 15:42 . 2009-05-14 04:12 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-06-28 15:42 . 2009-05-14 04:12 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-06-26 16:50 . 2005-06-18 07:49 666624 ----a-w- c:\windows\system32\wininet.dll
2009-06-26 16:50 . 2004-08-04 07:56 81920 ------w- c:\windows\system32\ieencode.dll
2009-06-25 21:02 . 2008-08-24 05:01 -------- d-----w- c:\program files\MediaMonkey
2009-06-16 14:36 . 2003-08-08 16:18 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 . 2003-08-08 15:35 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-06 19:39 . 2009-04-18 00:23 -------- d-----w- c:\program files\Common Files\DivX Shared
2009-06-06 19:11 . 2006-07-23 17:57 -------- d-----w- c:\program files\DivX
2009-06-06 04:54 . 2003-12-06 04:44 -------- d-----w- c:\program files\Roms
2009-06-03 19:09 . 2005-08-30 17:14 1291264 ----a-w- c:\windows\system32\quartz.dll
2009-05-21 22:25 . 2009-04-20 07:31 156672 ----a-w- c:\windows\system32\rmc_fixasf.exe
2009-05-21 22:25 . 2009-04-20 07:31 237568 ----a-w- c:\windows\system32\rmc_rtspdl.dll
2009-05-14 04:12 . 2009-05-14 04:12 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-05-07 15:32 . 2003-08-08 16:23 345600 ----a-w- c:\windows\system32\localspl.dll
2009-05-01 21:02 . 2009-05-01 21:02 823296 ----a-w- c:\windows\system32\divx_xx0c.dll
2009-05-01 21:02 . 2009-05-01 21:02 823296 ----a-w- c:\windows\system32\divx_xx07.dll
2009-05-01 21:02 . 2009-05-01 21:02 815104 ----a-w- c:\windows\system32\divx_xx0a.dll
2009-05-01 21:02 . 2009-05-01 21:02 811008 ----a-w- c:\windows\system32\divx_xx16.dll
2009-05-01 21:02 . 2009-05-01 21:02 802816 ----a-w- c:\windows\system32\divx_xx11.dll
2009-05-01 21:02 . 2009-05-01 21:02 685056 ----a-w- c:\windows\system32\DivX.dll
2004-10-20 03:30 . 2004-10-20 03:23 8603976 ----a-w- c:\program files\gcsp20.exe
2004-08-20 02:56 . 2004-08-20 05:20 4918 ----a-w- c:\program files\DoomConfig.cfg
2002-03-23 01:50 . 2004-11-17 05:36 2061 -c--a-w- c:\program files\readme.txt
1997-04-09 00:41 . 2004-09-11 20:28 3934 -c--a-w- c:\program files\LICINFO.TXT
2009-07-22 03:04 . 2008-08-27 19:16 134648 ----a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-26 1008896]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-06-26 17:36 1008896 ----a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-26 1008896]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-26 1008896]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"KBD"="c:\hp\KBD\KBD.EXE" [2005-02-02 61440]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-08-24 7696384]
"nmctxth"="c:\program files\Common Files\Pure Networks Shared\Platform\nmctxth.exe" [2008-05-16 648504]
"nmapp"="c:\program files\Pure Networks\Network Magic\nmapp.exe" [2008-05-22 451896]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-28 1948440]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-08-24 86016]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-28 148888]
c:\windows\system32\config\systemprofile\Start Menu\Programs\Startup\
AutoTBar.exe [2003-6-18 53248]
mod_sm.lnk - c:\hp\bin\cloaker.exe [1999-11-7 27136]
c:\documents and settings\Administrator\Start Menu\Programs\Startup\
mod_sm.lnk - c:\hp\bin\cloaker.exe [1999-11-7 27136]
c:\documents and settings\Administrator.FAMILY-COMPUTER\Start Menu\Programs\Startup\
AutoTBar.exe [2003-6-18 53248]
mod_sm.lnk - c:\hp\bin\cloaker.exe [1999-11-7 27136]
c:\documents and settings\Default User\Start Menu\Programs\Startup\
AutoTBar.exe [2003-6-18 53248]
mod_sm.lnk - c:\hp\bin\cloaker.exe [1999-11-7 27136]
c:\docume~1\ALLUSE~1\STARTM~1\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472]
HP Photosmart Premier Fast Start.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqthb08.exe [2006-2-10 73728]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"HideShutdownScripts"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system]
"NoVisualStyleChoice"= 0 (0x0)
"NoColorChoice"= 0 (0x0)
"NoSizeChoice"= 0 (0x0)
"HideLogonScripts"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"= 0 (0x0)
"NoHelp"= 0 (0x0)
"NoViewOnDrive"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoChangeAnimation"= 0 (0x0)
"RestrictCpl"= 0 (0x0)
"DisallowCpl"= 0 (0x0)
"NoViewOnDrive"= 0 (0x0)
"RestrictRun"= 0 (0x0)
"NoRecycleFiles"= 0 (0x0)
"ForceRecycleBinSize"= 0 (0x0)
"NoCustomizeWebView"= 0 (0x0)
"NoFileAssociate"= 0 (0x0)
"NoDFSTab"= 0 (0x0)
"NoCustomizeThisFolder"= 0 (0x0)
"NoWebView"= 0 (0x0)
"DontShowSuperHidden"= 0 (0x0)
"NoOnlinePrintsWizard"= 0 (0x0)
"NoPublishingWizard"= 0 (0x0)
"NoSMConfigurePrograms"= 0 (0x0)
"NoSMMyPictures"= 0 (0x0)
"NoStartMenuMyMusic"= 0 (0x0)
"NoHelp"= 0 (0x0)
"NoCommonGroups"= 0 (0x0)
"NoStartMenuEjectPC"= 0 (0x0)
"NoSimpleStartMenu"= 0 (0x0)
"NoStartMenuSubFolders"= 0 (0x0)
"NoDisconnect"= 0 (0x0)
"NoNtSecurity"= 0 (0x0)
"GreyMSIAds"= 0 (0x0)
"ForceMaxRecentDocs"= 0 (0x0)
"NoSMBalloonTip"= 0 (0x0)
"NoSMBalloonTips"= 0 (0x0)
"NoTaskGrouping"= 0 (0x0)
"NoWebServices"= 0 (0x0)
"NoFileUrl"= 0 (0x0)
"NoExpandedNewMenu"= 0 (0x0)
"SpecifyDefaultButtons"= 0 (0x0)
"NoRecentDocsNetHood"= 0 (0x0)
"PromptRunasInstallNetPath"= 1 (0x1)
"NoResolveTrack"= 0 (0x0)
"NoDevMgrUpdate"= 0 (0x0)
"NoThumbnailCache"= 0 (0x0)
"ForceCopyAclwithFile"= 0 (0x0)
"StartRunNoHOMEPATH"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoThemesTab"= 0 (0x0)
"NoChangeAnimation"= 0 (0x0)
"RestrictCpl"= 0 (0x0)
"DisallowCpl"= 0 (0x0)
"NoViewOnDrive"= 0 (0x0)
"RestrictRun"= 0 (0x0)
"DisallowRun"= 0 (0x0)
"NoRecycleFiles"= 0 (0x0)
"ForceRecycleBinSize"= 0 (0x0)
"NoCustomizeWebView"= 0 (0x0)
"NoFileAssociate"= 0 (0x0)
"NoDFSTab"= 0 (0x0)
"NoCustomizeThisFolder"= 0 (0x0)
"NoWebView"= 0 (0x0)
"DontShowSuperHidden"= 0 (0x0)
"NoOnlinePrintsWizard"= 0 (0x0)
"NoPublishingWizard"= 0 (0x0)
"NoSMConfigurePrograms"= 0 (0x0)
"NoSMMyPictures"= 0 (0x0)
"NoStartMenuMyMusic"= 0 (0x0)
"NoHelp"= 0 (0x0)
"NoCommonGroups"= 0 (0x0)
"NoStartMenuEjectPC"= 0 (0x0)
"NoSimpleStartMenu"= 0 (0x0)
"NoStartMenuSubFolders"= 0 (0x0)
"NoDisconnect"= 0 (0x0)
"NoNtSecurity"= 0 (0x0)
"GreyMSIAds"= 0 (0x0)
"ForceMaxRecentDocs"= 0 (0x0)
"NoSMBalloonTip"= 0 (0x0)
"NoSMBalloonTips"= 0 (0x0)
"HideClock"= 0 (0x0)
"NoTaskGrouping"= 0 (0x0)
"NoWebServices"= 0 (0x0)
"NoFileUrl"= 0 (0x0)
"NoExpandedNewMenu"= 0 (0x0)
"SpecifyDefaultButtons"= 0 (0x0)
"NoRecentDocsNetHood"= 0 (0x0)
"PromptRunasInstallNetPath"= 1 (0x1)
"NoResolveTrack"= 0 (0x0)
"NoDevMgrUpdate"= 0 (0x0)
"NoThumbnailCache"= 0 (0x0)
"ForceCopyAclwithFile"= 0 (0x0)
"StartRunNoHOMEPATH"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OPXPGina]
2003-02-21 10:50 40960 ----a-w- c:\program files\Softex\OmniPass\OPXPGina.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-06-28 15:42 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AVG Anti-Spyware Driver]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AVG Anti-Spyware Guard]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^msmsgs.exe]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Scheduled Updates.lnk]
backup=c:\windows\pss\Quicken Scheduled Updates.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Sonic CinePlayer Quick Launch.lnk]
backup=c:\windows\pss\Sonic CinePlayer Quick Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Updates from HP.lnk]
backup=c:\windows\pss\Updates from HP.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^Adobe Gamma.lnk]
backup=c:\windows\pss\Adobe Gamma.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^spamsubtract.lnk]
backup=c:\windows\pss\spamsubtract.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Messenger"=3 (0x3)
"BITS"=2 (0x2)
"Fax"=3 (0x3)
"SNDSrvc"=3 (0x3)
"ccPwdSvc"=3 (0x3)
"ccEvtMgr"=3 (0x3)
"Adobe LM Service"=3 (0x3)
"iPodService"=3 (0x3)
"avast! Web Scanner"=3 (0x3)
"avast! Mail Scanner"=3 (0x3)
"avast! Antivirus"=2 (0x2)
"aswUpdSv"=2 (0x2)
"AVGEMS"=2 (0x2)
"Avg7UpdSvc"=2 (0x2)
"Avg7Alrt"=2 (0x2)
"VSS"=3 (0x3)
"Schedule"=2 (0x2)
"IDriverT"=3 (0x3)
"WMPNetworkSvc"=3 (0x3)
"TUWinStylerThemeSvc"=3 (0x3)
"CachemanXPService"=3 (0x3)
"iPod Service"=3 (0x3)
"AresChatServer"=3 (0x3)
"usnjsvc"=3 (0x3)
"Client IP-IPX"=2 (0x2)
"Apple Mobile Device"=2 (0x2)
"Bonjour Service"=2 (0x2)
"PnkBstrA"=2 (0x2)
"Creative Service for CDROM Access"=2 (0x2)
"JavaQuickStarterService"=2 (0x2)
"navapsvc"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"nwiz"=nwiz.exe /install
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Google\\Google Video Player\\GoogleVideoPlayer.exe"=
"c:\\WINDOWS\\system32\\ftp.exe"=
"c:\\Program Files\\Ares\\Ares.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\TrackMania Sunrise\\TmSunrise.exe"=
"c:\\Documents and Settings\\Owner\\My Documents\\LimeWire\\LimeWire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaws.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgui.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgtray.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Media Catcher\\MediaCatcher.exe"=
"c:\\WINDOWS\\system32\\javaw.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"4662:TCP"= 4662:TCP:eMule
"4672:UDP"= 4672:UDP:eMule
"4663:TCP"= 4663:TCP:eMule2
"4673:UDP"= 4673:UDP:eMule22
"67:UDP"= 67:UDP:DHCP Discovery Service
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [5/13/2009 9:12 PM 335752]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [5/13/2009 9:12 PM 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [5/13/2009 9:12 PM 907032]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [5/13/2009 9:12 PM 298776]
S2 mrtRate;mrtRate; [x]
S3 pohci13F;pohci13F;\??\c:\docume~1\Owner\LOCALS~1\Temp\pohci13F.sys --> c:\docume~1\Owner\LOCALS~1\Temp\pohci13F.sys [?]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-BHR - c:\program files\Browser Hijack Retaliator 4.5\BHR.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.netscape.com/
uDefault_Search_URL = hxxp://srch-ca9.hpwis.com/
mStart Page = hxxp://ca9.hpwis.com/
mSearch Bar = hxxp://srch-ca9.hpwis.com/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = localhost;*.local
LSP: SpSubLSP.dll
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\docume~1\Owner\APPLIC~1\Mozilla\Firefox\Profiles\oxkf16ee.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - prefs.js: browser.startup.homepage - www.netscape.com
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
---- FIREFOX POLICIES ----
FF - user.js: general.useragent.extra.zencast - .
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-07-29 16:33
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Cryptography\RNG*]
"Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d,
bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(784)
c:\program files\Softex\OmniPass\opxpgina.dll
- - - - - - - > 'lsass.exe'(844)
c:\windows\system32\SpSubLSP.dll
- - - - - - - > 'explorer.exe'(2200)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Softex\OmniPass\omniServ.exe
c:\windows\system32\TUProgSt.exe
c:\program files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\program files\Softex\OmniPass\OPXPApp.exe
c:\windows\system32\wscntfy.exe
c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqimzone.exe
c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqste08.exe
.
**************************************************************************
.
Completion time: 2009-07-29 16:43 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-29 23:43
Pre-Run: 3,607,453,696 bytes free
Post-Run: 3,441,811,456 bytes free
468 --- E O F --- 2009-07-28 20:41