Here's the new combofix log:
ComboFix 09-05-31.06 - Pete 06/01/2009 11:38.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1023.525 [GMT -5:00]
Running from: c:\documents and settings\Pete\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\Pete\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: ZoneAlarm Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
* Created a new restore point
FILE ::
"c:\windows\Internet Logs\xDB1.tmp"
"c:\windows\Internet Logs\xDB2.tmp"
"c:\windows\Internet Logs\xDB3.tmp"
"c:\windows\system32\blocker.dll"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Internet Logs\xDB1.tmp
c:\windows\Internet Logs\xDB2.tmp
c:\windows\Internet Logs\xDB3.tmp
c:\windows\system32\blocker.dll
.
((((((((((((((((((((((((( Files Created from 2009-05-01 to 2009-06-01 )))))))))))))))))))))))))))))))
.
2009-06-01 14:50 . 2009-06-01 14:50 20797 ----a-w- C:\MGlogs.zip
2009-06-01 14:50 . 2009-06-01 14:50 -------- d-----w- C:\MGtools
2009-05-29 16:04 . 2009-05-29 16:04 -------- d-----w- C:\emergency
2009-05-26 01:09 . 2009-05-26 01:09 152576 ----a-w- c:\documents and settings\Pete\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-05-23 19:48 . 2009-05-23 19:48 -------- d-----w- c:\program files\videofixer
2009-05-22 18:55 . 2009-05-22 18:56 -------- d-----w- c:\program files\Direct MP3 Joiner
2009-05-20 22:07 . 2009-05-20 22:08 -------- d-----w- c:\program files\FormatFactory
2009-05-20 18:44 . 2008-03-21 18:57 14640 ------w- c:\windows\system32\spmsgXP_2k3.dll
2009-05-20 18:43 . 2009-05-20 18:49 -------- d-----w- c:\program files\Zune
2009-05-20 18:41 . 2008-05-02 09:05 62592 -c----w- c:\windows\system32\dllcache\cdrom.sys
2009-05-20 18:41 . 2008-05-02 13:30 464384 -c----w- c:\windows\system32\dllcache\imapi2fs.dll
2009-05-20 18:41 . 2008-05-02 13:30 464384 ------w- c:\windows\system32\imapi2fs.dll
2009-05-20 18:41 . 2008-05-02 13:30 317952 -c----w- c:\windows\system32\dllcache\imapi2.dll
2009-05-20 18:41 . 2008-05-02 13:30 317952 ------w- c:\windows\system32\imapi2.dll
2009-05-20 05:23 . 2009-05-20 05:23 -------- d-----w- c:\documents and settings\Pete\Application Data\TweetDeckFast.F9107117265DB7542C1A806C8DB837742CE14C21.1
2009-05-20 04:53 . 2009-05-20 04:51 38208 ----a-w- c:\documents and settings\Pete\Application Data\Macromedia\Flash Player\
www.macromedia.com\bin\airappinstaller\airappinstaller.exe2009-05-20 04:53 . 2009-05-20 04:53 -------- d-----w- c:\program files\TweetDeck
2009-05-20 04:52 . 2009-05-20 04:52 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-05-19 02:04 . 2009-05-19 02:04 -------- d-----w- c:\documents and settings\Pete\Application Data\Smith Micro
2009-05-19 00:45 . 2009-05-19 00:45 -------- d-----w- c:\program files\Smith Micro
2009-05-18 16:30 . 2009-05-24 03:22 -------- d-----w- c:\program files\IrfanView
2009-05-11 17:27 . 2009-05-11 17:27 -------- d-----w- c:\documents and settings\Pete\Application Data\Corel
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-01 16:44 . 2008-09-06 16:49 1730 ----a-w- c:\windows\system32\tablet.dat
2009-06-01 16:43 . 2008-11-16 20:05 5943311 ----a-w- c:\windows\Internet Logs\tvDebug.zip
2009-06-01 16:42 . 2008-09-06 14:08 2672060 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-06-01 16:42 . 2008-09-06 14:08 229066784 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-05-28 20:50 . 2008-09-06 07:34 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-05-27 13:46 . 2008-09-07 05:13 -------- d-----w- c:\documents and settings\Pete\Application Data\CoreFTP
2009-05-26 01:10 . 2008-09-07 05:07 -------- d-----w- c:\program files\Java
2009-05-24 19:01 . 2008-09-06 15:36 -------- d-----w- c:\program files\Mozilla Thunderbird
2009-05-21 14:21 . 2008-09-06 23:51 -------- d-----w- c:\program files\PeerGuardian2
2009-05-21 14:19 . 2008-09-08 01:18 -------- d-----w- c:\documents and settings\Pete\Application Data\Azureus
2009-05-20 19:13 . 2009-05-20 19:13 0 ---ha-w- c:\windows\system32\drivers\Msft_User_ZuneDriver_01_07_00.Wdf
2009-05-20 19:13 . 2009-05-20 19:13 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_WinUSB_01007.Wdf
2009-05-20 19:10 . 2009-05-20 19:10 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_user_01_07_00.Wdf
2009-05-20 18:44 . 2009-05-20 18:44 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_zumbus_01007.Wdf
2009-05-20 18:44 . 2009-05-20 18:44 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2009-05-19 13:48 . 2008-09-06 07:34 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-05-19 13:48 . 2008-09-06 07:34 325896 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-05-19 13:48 . 2008-09-06 07:34 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-05-19 13:48 . 2008-09-06 07:34 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-05-18 14:49 . 2008-09-06 22:51 -------- d-----w- c:\program files\AutoCAD R14
2009-05-13 21:50 . 2008-09-07 18:02 -------- d-----w- c:\program files\Trillian
2009-05-12 02:06 . 2008-09-07 03:50 -------- d-----w- c:\documents and settings\Pete\Application Data\Skype
2009-05-10 05:05 . 2008-10-12 04:29 -------- d-----w- c:\documents and settings\Pete\Application Data\skypePM
2009-05-07 00:16 . 2008-09-10 22:35 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-04-15 20:02 . 2009-04-15 20:02 -------- d-----w- c:\documents and settings\Pete\Application Data\dvdcss
2009-03-27 19:10 . 2009-03-27 19:10 285 ----a-w- c:\windows\EReg072.dat
2009-03-27 19:09 . 2009-03-27 19:09 4608 ----a-w- c:\windows\system32\w95inf32.dll
2009-03-27 19:09 . 2009-03-27 19:09 2272 ----a-w- c:\windows\system32\w95inf16.dll
2009-03-24 21:02 . 2009-03-24 21:02 119536 ---ha-w- c:\windows\system32\mlfcache.dat
2009-03-20 01:00 . 2009-03-20 01:00 503808 ----a-w- c:\documents and settings\Pete\Application Data\Sun\Java\Deployment\cache\6.0\38\39ba6e6-728ab9d8-n\msvcp71.dll
2009-03-20 01:00 . 2009-03-20 01:00 499712 ----a-w- c:\documents and settings\Pete\Application Data\Sun\Java\Deployment\cache\6.0\38\39ba6e6-728ab9d8-n\jmc.dll
2009-03-20 01:00 . 2009-03-20 01:00 348160 ----a-w- c:\documents and settings\Pete\Application Data\Sun\Java\Deployment\cache\6.0\38\39ba6e6-728ab9d8-n\msvcr71.dll
2009-03-20 00:57 . 2009-03-20 00:57 152576 ----a-w- c:\documents and settings\Pete\Application Data\Sun\Java\jre1.6.0_12\lzma.dll
2009-03-09 10:19 . 2008-11-26 21:40 410984 ----a-w- c:\windows\system32\deploytk.dll
.
(((((((((((((((((((((((((((((
SnapShot@2009-06-01_15.58.40 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-06-01 16:44 . 2009-06-01 16:44 40960 c:\windows\Temp\rtdrvmon.exe
+ 2009-06-01 16:43 . 2009-06-01 16:43 16384 c:\windows\Temp\Perflib_Perfdata_150.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-08-18 1832272]
"LDM"="c:\program files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe" [2008-09-06 16384]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"Steam"="c:\program files\Valve\Steam\Steam.exe" [2009-05-19 1217784]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-05-19 1947928]
"SoundMAXPnP"="c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [2003-05-29 790528]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-07-09 919016]
"zBrowser Launcher"="c:\program files\Logitech\iTouch\iTouch.exe" [2003-12-01 892928]
"Lexmark 3100 Series"="c:\program files\Lexmark 3100 Series\lxbrbmgr.exe" [2003-09-04 106496]
"LXBRKsk"="c:\progra~1\LEXMAR~1\LXBRKsk.exe" [2003-06-13 294912]
"dvd43"="c:\program files\dvd43\dvd43_tray.exe" [2008-04-09 826880]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-16 13529088]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-16 86016]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2008-12-12 157312]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"Logitech Utility"="Logi_MwX.Exe" - c:\windows\LOGI_MWX.EXE [2003-11-07 19968]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2008-05-16 1630208]
"WinBlueSoft"="" [BU]
c:\documents and settings\Pete\Start Menu\Programs\Startup\
Sonic CinePlayer Quick Launch.lnk - c:\program files\Common Files\Sonic Shared\cinetray.exe [2002-9-18 98304]
Yahoo! Widgets.lnk - c:\program files\Yahoo!\Widgets\YahooWidgets.exe [2008-3-18 4742184]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2008-9-6 169472]
Post-itr Software Notes Lite.lnk - c:\program files\3M\PSNLite\PsnLite.exe [2004-10-15 2080768]
TabUserW.exe.lnk - c:\windows\system32\WTablet\TabUserW.exe [2008-9-6 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-05-19 13:48 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\backWeb-8876480.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [9/6/2008 2:34 AM 325896]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [9/6/2008 2:34 AM 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [9/6/2008 2:34 AM 908568]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [1/28/2009 9:44 AM 298776]
R3 XIRLINK;Veo Web Camera;c:\windows\system32\drivers\ucdnt.sys [9/6/2008 12:25 PM 728067]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-setup2.exe - (no file)
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.google.com/uInternet Settings,ProxyOverride = localhost;*.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Pete\Application Data\Mozilla\Firefox\Profiles\px9cglmh.default\
FF - prefs.js: browser.startup.homepage -
hxxp://www.google.com/.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-06-01 11:46
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(1624)
c:\docume~1\Pete\LOCALS~1\Temp\IadHide4.dll
c:\program files\Logitech\MouseWare\System\LgWndHk.dll
c:\windows\system32\tabhook.dll
c:\program files\Logitech\iTouch\iTchHk.dll
c:\program files\Common Files\Logitech\Scrolling\LgMsgHk.dll
c:\windows\system32\msi.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\nvsvc32.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\windows\system32\PSIService.exe
c:\program files\Analog Devices\SoundMAX\SMAgent.exe
c:\windows\system32\Tablet.exe
c:\windows\system32\ZuneBusEnum.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\windows\system32\wscntfy.exe
c:\program files\Logitech\MouseWare\system\EM_EXEC.EXE
c:\windows\system32\rundll32.exe
c:\program files\Lexmark 3100 Series\lxbrbmon.exe
c:\program files\Lexmark 3100 Series\lxbrcmon.exe
.
**************************************************************************
.
Completion time: 2009-06-01 11:51 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-01 16:51
ComboFix2.txt 2009-06-01 16:01
Pre-Run: 23,246,204,928 bytes free
Post-Run: 23,252,992,000 bytes free
206