Okay, here's what I got from that:
It's alot!
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 11:43:47 PM 2/17/2007
+ Scan result:
C:\Documents and Settings\Home\Local Settings\Temp\New9.tmp\upg_dll.dll -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\Program Files\SpywareRemover -> Adware.SpywareRemover : Cleaned with backup (quarantined).
C:\Program Files\SpywareRemover\DataBaseNew.ref -> Adware.SpywareRemover : Cleaned with backup (quarantined).
C:\Program Files\SpywareRemover\Log -> Adware.SpywareRemover : Cleaned with backup (quarantined).
C:\Program Files\SpywareRemover\Log\log_2007_02_11_08_55_13.log -> Adware.SpywareRemover : Cleaned with backup (quarantined).
C:\Program Files\SpywareRemover\Log\log_2007_02_11_08_55_19.log -> Adware.SpywareRemover : Cleaned with backup (quarantined).
C:\Program Files\SpywareRemover\Quarantine -> Adware.SpywareRemover : Cleaned with backup (quarantined).
C:\Program Files\SpywareRemover\Registry Backups -> Adware.SpywareRemover : Cleaned with backup (quarantined).
C:\Program Files\SpywareRemover\Settings -> Adware.SpywareRemover : Cleaned with backup (quarantined).
C:\Program Files\SpywareRemover\Settings\CustomScan.stg -> Adware.SpywareRemover : Cleaned with backup (quarantined).
C:\Program Files\SpywareRemover\Settings\IgnoreList.stg -> Adware.SpywareRemover : Cleaned with backup (quarantined).
C:\Program Files\SpywareRemover\Settings\ScanInfo.stg -> Adware.SpywareRemover : Cleaned with backup (quarantined).
C:\Program Files\SpywareRemover\Settings\ScanResults.stg -> Adware.SpywareRemover : Cleaned with backup (quarantined).
C:\Program Files\SpywareRemover\Settings\SelectedFolders.stg -> Adware.SpywareRemover : Cleaned with backup (quarantined).
C:\Program Files\SpywareRemover\Settings\Settings.stg -> Adware.SpywareRemover : Cleaned with backup (quarantined).
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\RUIPN01A\TTC[1].exe -> Adware.TTC : Cleaned with backup (quarantined).
C:\WINDOWS\system32\awtrqrs.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\WINDOWS\system32\nnnomki.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\WINDOWS\system32\vtuvsqp.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\WINDOWS\system32\yayvuvs.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\4EZJYNH3\ac4[1].txt -> Downloader.Agent.awb : Cleaned with backup (quarantined).
C:\WINDOWS\system32\w881ebc4.dll -> Downloader.Agent.awb : Cleaned with backup (quarantined).
C:\WINDOWS\system32\w881f007.dll -> Downloader.Agent.awb : Cleaned with backup (quarantined).
C:\WINDOWS\system32\w881f2a6.dll -> Downloader.Agent.awb : Cleaned with backup (quarantined).
C:\WINDOWS\system32\w881f378.dll -> Downloader.Agent.awb : Cleaned with backup (quarantined).
C:\Documents and Settings\Home\Local Settings\Temp\Temporary Internet Files\Content.IE5\T81DZ5HZ\antzom[1].exe -> Downloader.Agent.bgn : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C5D90EED-9F80-4FF0-AD2A-72507F08F350}\RP30\A0016474.exe -> Downloader.Femad : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C5D90EED-9F80-4FF0-AD2A-72507F08F350}\RP30\A0016498.dll -> Downloader.Small.dxm : Cleaned with backup (quarantined).
C:\WINDOWS\system32\__delete_on_reboot__l_d_c_o_r_e_._d_l_l_ -> Downloader.Small.dxm : Cleaned with backup (quarantined).
C:\WINDOWS\system32\ldcore.dll -> Downloader.Small.dxm : Cleaned with backup (quarantined).
[1032] c:\windows\system32\ldcore.dll -> Downloader.Small.dxm : Cleaned with backup (quarantined).
[108] c:\windows\system32\ldcore.dll -> Downloader.Small.dxm : Cleaned with backup (quarantined).
[1116] c:\windows\system32\ldcore.dll -> Downloader.Small.dxm : Cleaned with backup (quarantined).
[1176] c:\windows\system32\ldcore.dll -> Downloader.Small.dxm : Cleaned with backup (quarantined).
[1216] c:\windows\system32\ldcore.dll -> Downloader.Small.dxm : Cleaned with backup (quarantined).
[1276] c:\windows\system32\ldcore.dll -> Downloader.Small.dxm : Cleaned with backup (quarantined).
[1284] c:\windows\system32\ldcore.dll -> Downloader.Small.dxm : Cleaned with backup (quarantined).
[1292] c:\windows\system32\ldcore.dll -> Downloader.Small.dxm : Cleaned with backup (quarantined).
[136] c:\windows\system32\ldcore.dll -> Downloader.Small.dxm : Cleaned with backup (quarantined).
[144] c:\windows\system32\ldcore.dll -> Downloader.Small.dxm : Cleaned with backup (quarantined).
[1560] c:\windows\system32\ldcore.dll -> Downloader.Small.dxm : Cleaned with backup (quarantined).
[1720] c:\windows\system32\ldcore.dll -> Downloader.Small.dxm : Cleaned with backup (quarantined).
[1780] c:\windows\system32\ldcore.dll -> Downloader.Small.dxm : Cleaned with backup (quarantined).
[1792] c:\windows\system32\ldcore.dll -> Downloader.Small.dxm : Cleaned with backup (quarantined).
[1944] c:\windows\system32\ldcore.dll -> Downloader.Small.dxm : Cleaned with backup (quarantined).
[1952] c:\windows\system32\ldcore.dll -> Downloader.Small.dxm : Cleaned with backup (quarantined).
[1988] c:\windows\system32\ldcore.dll -> Downloader.Small.dxm : Cleaned with backup (quarantined).
[2008] c:\windows\system32\ldcore.dll -> Downloader.Small.dxm : Cleaned with backup (quarantined).
[2100] c:\windows\system32\ldcore.dll -> Downloader.Small.dxm : Cleaned with backup (quarantined).
[3380] c:\windows\system32\ldcore.dll -> Downloader.Small.dxm : Cleaned with backup (quarantined).
[372] c:\windows\system32\ldcore.dll -> Downloader.Small.dxm : Cleaned with backup (quarantined).
[864] c:\windows\system32\ldcore.dll -> Downloader.Small.dxm : Cleaned with backup (quarantined).
[876] c:\windows\system32\ldcore.dll -> Downloader.Small.dxm : Cleaned with backup (quarantined).
[916] c:\windows\system32\ldcore.dll -> Downloader.Small.dxm : Cleaned with backup (quarantined).
[992] c:\windows\system32\ldcore.dll -> Downloader.Small.dxm : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C5D90EED-9F80-4FF0-AD2A-72507F08F350}\RP25\A0012480.exe -> Downloader.Tiny.fk : Cleaned with backup (quarantined).
C:\Program Files\Common Files\orfz\orfzd\vocabulary -> Downloader.TSUpdate.j : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C5D90EED-9F80-4FF0-AD2A-72507F08F350}\RP24\A0010452.exe -> Heuristic.Win32.Dialer : Cleaned with backup (quarantined).
C:\Documents and Settings\Home\Local Settings\Temp\Temporary Internet Files\Content.IE5\PI57LVMT\antizom[1].exe -> Logger.Agent.or : Cleaned with backup (quarantined).
C:\Program Files\Common Files\svchost.exe -> Logger.Agent.or : Cleaned with backup (quarantined).
C:\Documents and Settings\Home\Local Settings\Temp\Cookies\home@adopt.specificclick[2].txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\Home\Local Settings\Temp\Cookies\home@anad.tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Home\Local Settings\Temp\Temporary Internet Files\Content.IE5\J3DLLTT2\antzom[1].exe -> Trojan.Agent.qt : Cleaned with backup (quarantined).
C:\WINDOWS\system32\drvcun.dll -> Trojan.Agent.qt : Cleaned with backup (quarantined).
C:\WINDOWS\system32\drvdab.dll -> Trojan.Agent.qt : Cleaned with backup (quarantined).
C:\Documents and Settings\Home\Local Settings\Temp\mst133.tmp -> Trojan.Agent.vg : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C5D90EED-9F80-4FF0-AD2A-72507F08F350}\RP30\A0016499.dll -> Trojan.Agent.vg : Cleaned with backup (quarantined).
C:\WINDOWS\system32\__delete_on_reboot__w_i_n_k_e_i_3_2_._d_l_l_ -> Trojan.Agent.vg : Cleaned with backup (quarantined).
C:\Program Files\Outlook Express\rydimyz.dll -> Trojan.BHO.ab : Cleaned with backup (quarantined).
C:\WINDOWS\system32\durvilz.exe -> Trojan.Durvil : Cleaned with backup (quarantined).
C:\WINDOWS\system32\drivera.dll -> Trojan.Kolweb.j : Cleaned with backup (quarantined).
C:\WINDOWS\system32\durvilz.dll -> Trojan.Kolweb.j : Cleaned with backup (quarantined).
C:\Documents and Settings\Home\Local Settings\Temp\Temporary Internet Files\Content.IE5\298HOL43\xi6[1].exe -> Trojan.LdPinch.sh : Cleaned with backup (quarantined).
C:\WINDOWS\system32\13B.tmp -> Worm.Locksky.aw : Cleaned with backup (quarantined).
C:\WINDOWS\system32\13C.tmp -> Worm.Locksky.aw : Cleaned with backup (quarantined).
C:\WINDOWS\system32\9D.tmp -> Worm.Locksky.aw : Cleaned with backup (quarantined).
C:\WINDOWS\system32\9E.tmp -> Worm.Locksky.aw : Cleaned with backup (quarantined).
C:\WINDOWS\system32\instcat.dll -> Worm.Locksky.aw : Cleaned with backup (quarantined).
::Report end
AND THE OTHER:
Logfile of HijackThis v1.99.1
Scan saved at 11:57:25 PM, on 2/17/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
C:\WINDOWS\system32\ZONELABS\vsmon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust Anti-Spam\QSP-2.1.215.5\QOELoader.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Firewall\ca.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Home\Desktop\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://us.rd.yahoo.c.../search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://us.rd.yahoo.c...//www.yahoo.com
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,vihrmvt.exe
O1 - Hosts: localhost 127.0.0.1
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QOELOADER] "C:\Program Files\CA\eTrust EZ Armor\eTrust Anti-Spam\QSP-2.1.215.5\QOELoader.exe"
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Firewall\ca.exe"
O4 - HKLM\..\Run: [sys01203532082] C:\WINDOWS\sys01203532082.exe
O4 - HKLM\..\Run: [sys02035320822] C:\WINDOWS\sys02035320822.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [oajrwbh.dll] C:\WINDOWS\System32\rundll32.exe "C:\Documents and Settings\Home\Local Settings\Application Data\oajrwbh.dll",wjkmomf
O4 - HKLM\..\Run: [CTDrive] rundll32.exe C:\WINDOWS\System32\drvcun.dll,startup
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [Microsoft Windows Installer] C:\DOCUME~1\Home\LOCALS~1\Temp\stdrun1.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: .protected
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: .protected
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) -
http://supportcenter...oad/tgctlsr.cab
O16 - DPF: {010123DF-5E80-11D8-9E86-0007E96C65AE} (SprtCtlBrowse Class) -
http://supportcenter...d/sprtctlbr.cab
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) -
http://supportcenter...oad/tgctlcm.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.micros...b?1171219238547
O20 - AppInit_DLLs: c:\windows\system32\ldcore.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZONELABS\vsmon.exe