Ok. I ran everything as is - I don't save form info. Here's the logs:
ComboFix 08-02.01.6 - Jenn 2008-02-01 16:30:14.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.573 [GMT -5:00]
Running from: H:\Documents and Settings\[removed]\Local Settings\Temporary Internet Files\Content.IE5\3DMYRUBG\ComboFix[1].exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
H:\WINDOWS\system32\gebyy.dll
H:\WINDOWS\system32\ssttt.dll
H:\WINDOWS\system32\wvututs.dll
H:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
H:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
H:\Documents and Settings\Jenn\My Documents\ASKS~1
H:\Documents and Settings\Jenn\My Documents\ASKS~1\?asks\
H:\Program Files\Common Files\mantec~1
H:\Program Files\Common Files\mantec~1\w?nspool.exe
H:\WINDOWS\system32\byxutqo.dll
H:\WINDOWS\system32\cauikyek.dll
H:\WINDOWS\system32\gebyy.dll
H:\WINDOWS\system32\ljjggfg.dll
H:\WINDOWS\system32\ljjjiii.dll
H:\WINDOWS\system32\mljghih.dll
H:\WINDOWS\system32\rqrsrrr.dll
H:\WINDOWS\system32\ssttt.dll
H:\WINDOWS\system32\tttss.ini
H:\WINDOWS\system32\tttss.ini2
H:\WINDOWS\system32\vybeg.ini
H:\WINDOWS\system32\vybeg.ini2
H:\WINDOWS\system32\wvututs.dll
H:\WINDOWS\system32\yybeg.ini
H:\WINDOWS\system32\yybeg.ini2
—– BITS: Possible infected sites —–
hxxp://au.download.windowsupdate.com
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\LEGACY_CMDSERVICE
——-\LEGACY_NETWORK_MONITOR
((((((((((((((((((((((((( Files Created from 2008-01-01 to 2008-02-01 )))))))))))))))))))))))))))))))
.
2008-02-01 16:27 . 2008-02-01 16:29 d——– H:\Program Files\CCleaner
2008-01-31 12:09 . 2008-01-31 12:09 d——– H:\Program Files\Trend Micro
2008-01-31 08:31 . 2008-01-31 09:00 d——– H:\Documents and Settings\Nate\Application Data\Winamp
2008-01-30 13:44 . 2008-01-30 13:44 d——– H:\Documents and Settings\Nate\Application Data\PCToolsFirewallPlus
2008-01-29 17:29 . 2008-01-29 17:29 d——– H:\Program Files\Microsoft Visual Studio 8
2008-01-29 17:28 . 2008-01-29 17:29 d——– H:\Program Files\Microsoft Expression
2008-01-29 17:12 . 2007-07-30 19:19 271,224 –a—— H:\WINDOWS\system32\mucltui.dll
2008-01-29 17:12 . 2007-07-30 19:19 207,736 –a—— H:\WINDOWS\system32\muweb.dll
2008-01-29 17:12 . 2007-07-30 19:19 30,072 –a—— H:\WINDOWS\system32\mucltui.dll.mui
2008-01-29 17:10 . 2008-01-29 17:10 162 –a—— H:\WINDOWS\ODBC.INI
2008-01-29 17:04 . 2006-10-26 19:56 32,592 –a—— H:\WINDOWS\system32\msonpmon.dll
2008-01-29 17:03 . 2008-01-29 17:03 d——– H:\Program Files\MSBuild
2008-01-29 17:03 . 2008-01-29 17:03 d——– H:\Program Files\Microsoft Works
2008-01-29 16:59 . 2008-01-29 17:12 d——– H:\WINDOWS\SHELLNEW
2008-01-29 16:59 . 2008-01-29 16:59 dr-h—– H:\MSOCache
2008-01-29 16:59 . 2008-01-30 13:42 d——– H:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-01-29 16:54 . 2008-01-29 16:54 d——– H:\Program Files\PowerISO
2008-01-29 16:43 . 2008-01-29 16:43 d——– H:\Program Files\MagicISO Maker v5 4
2008-01-29 16:43 . 2008-01-29 16:51 d——– H:\Program Files\MagicISO
2008-01-28 23:51 . 2008-01-28 23:51 d——– H:\Program Files\TweakNow RegCleaner Std
2008-01-28 22:26 . 2008-01-28 22:26 d–hs—- H:\found.000
2008-01-26 14:03 . 2008-01-28 23:03 d——– H:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-26 13:58 . 2008-01-26 13:58 d——– H:\Program Files\NoAd HOSTS file
2008-01-23 20:32 . 2008-01-29 16:02 d——– H:\Documents and Settings\Jenn\Application Data\Winamp
2008-01-21 14:36 . 2008-01-21 14:36 d——– H:\Documents and Settings\Jenn\Application Data\PCToolsFirewallPlus
2008-01-21 14:29 . 2008-01-21 14:59 d——– H:\Program Files\PC Tools Firewall Plus
2008-01-21 14:29 . 2008-01-21 14:29 d——– H:\Program Files\Common Files\PC Tools
2008-01-21 14:29 . 2008-02-01 16:33 d-a—— H:\Documents and Settings\All Users\Application Data\TEMP
2008-01-21 14:29 . 2008-01-04 14:13 218,520 –a—— H:\WINDOWS\system32\drivers\pctfw2.sys
2008-01-21 14:29 . 2008-01-04 14:13 125,848 –a—— H:\WINDOWS\system32\drivers\pctfw.sys
2008-01-21 14:29 . 2008-01-04 14:13 40,856 –a—— H:\WINDOWS\system32\drivers\pctmp.sys
2008-01-21 14:29 . 2008-01-04 14:13 18,328 –a—— H:\WINDOWS\system32\drivers\pctssipc.sys
2008-01-21 14:27 . 2008-01-29 16:55 d——– H:\Documents and Settings\Jenn\Application Data\BitTorrent
2008-01-21 14:00 . 2008-01-28 23:24 d——– H:\Documents and Settings\Jenn\Application Data\AVG7
2008-01-21 13:56 . 2008-01-21 13:56 d——– H:\Documents and Settings\LocalService\Application Data\AVG7
2008-01-21 13:56 . 2008-01-21 13:56 d——– H:\Documents and Settings\All Users\Application Data\Grisoft
2008-01-21 13:56 . 2008-01-21 14:17 d——– H:\Documents and Settings\All Users\Application Data\avg7
2008-01-21 13:56 . 2008-01-21 13:56 499,712 –a—— H:\WINDOWS\system32\msvcp71.dll
2008-01-21 13:56 . 2008-01-21 13:56 348,160 –a—— H:\WINDOWS\system32\msvcr71.dll
2008-01-21 13:39 . 2008-01-28 23:09 d——– H:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-21 13:31 . 2005-06-28 10:21 22,752 –a—— H:\WINDOWS\system32\spupdsvc.exe
2008-01-21 13:20 . 2008-01-21 13:20 4,286 –a—— H:\WINDOWS\system32\Jamster.ico
2008-01-21 13:15 . 2008-01-21 13:51 d–hs—- H:\WINDOWS\RWwgTWluZ28
2008-01-20 09:20 . 2004-08-04 05:00 221,184 –a—— H:\WINDOWS\system32\wmpns.dll
2008-01-19 16:37 . 2008-01-21 15:45 d——– H:\Program Files\DAEMON Tools Pro
2008-01-19 16:30 . 2008-01-19 16:58 715,248 –a—— H:\WINDOWS\system32\drivers\sptd.sys
2008-01-19 11:55 . 2008-01-29 16:02 d——– H:\Program Files\Winamp
2008-01-19 09:44 . 2008-01-19 09:44 d——– H:\Program Files\BitTorrent
2008-01-10 09:54 . 2008-01-10 09:54 d——– H:\WINDOWS\Sun
2008-01-10 09:44 . 2008-01-10 09:44 d–hs—- H:\Documents and Settings\Jenn\UserData
2008-01-08 20:07 . 2008-01-08 20:07 d——– H:\Program Files\CyberLink
2008-01-08 20:05 . 2008-01-08 20:05 d——– H:\WINDOWS\system32\vmm32
2008-01-08 20:05 . 2008-01-08 20:05 d——– H:\Program Files\Dell
2008-01-08 20:02 . 1998-11-06 14:33 244,417 –a—— H:\WINDOWS\system32\odbcjet.hlp
2008-01-08 20:02 . 1998-06-17 23:00 89,360 –a—— H:\WINDOWS\system32\VB5DB.DLL
2008-01-08 20:02 . 2001-08-22 08:42 13,632 ——— H:\WINDOWS\system32\drivers\omci.sys
2008-01-08 20:02 . 1998-11-06 14:38 8,198 –a—— H:\WINDOWS\system32\odbcjet.cnt
2008-01-08 19:56 . 2008-01-08 19:57 d——– H:\Program Files\ATI Technologies
2008-01-08 19:52 . 2003-11-03 18:15 1,902 –a—— H:\WINDOWS\system32\SetupBD.din
2008-01-08 19:51 . 2008-01-08 19:51 d——– H:\Program Files\CONEXANT
2008-01-08 19:50 . 2008-01-08 19:50 d——– H:\Program Files\Modem Helper
2008-01-08 19:50 . 2008-01-08 19:50 d——– H:\Program Files\Java
2008-01-08 19:50 . 2008-01-08 19:50 d——– H:\Program Files\Common Files\Java
2008-01-08 19:50 . 2003-11-19 17:48 61,555 –a—— H:\WINDOWS\system32\jpicpl32.cpl
2008-01-08 19:48 . 2008-01-08 19:48 d——– H:\Program Files\Intel
2008-01-08 19:46 . 2008-01-08 19:46 d——– H:\Program Files\SigmaTel
2008-01-08 19:46 . 2008-01-08 20:07 d–h—– H:\Program Files\InstallShield Installation Information
2008-01-08 19:46 . 2005-06-14 17:40 180,864 –a—— H:\WINDOWS\system32\drivers\sthda.sys
2008-01-08 19:46 . 2004-08-04 00:56 130,048 –a—— H:\WINDOWS\system32\ksproxy.ax
2008-01-08 19:46 . 2004-08-04 00:56 130,048 –a–c— H:\WINDOWS\system32\dllcache\ksproxy.ax
2008-01-08 19:46 . 2005-03-21 23:23 103,936 –a—— H:\WINDOWS\system32\staco.dll
2008-01-08 19:46 . 2004-08-03 23:08 60,288 –a—— H:\WINDOWS\system32\drivers\drmk.sys
2008-01-08 19:46 . 2004-08-03 23:08 60,288 –a–c— H:\WINDOWS\system32\dllcache\drmk.sys
2008-01-08 19:46 . 2004-08-04 00:56 4,096 –a—— H:\WINDOWS\system32\ksuser.dll
2008-01-08 19:46 . 2004-08-04 00:56 4,096 –a–c— H:\WINDOWS\system32\dllcache\ksuser.dll
2008-01-08 19:40 . 2008-01-08 19:50 d——– H:\Program Files\Common Files\InstallShield
2008-01-08 17:47 . 2008-01-08 17:47 940 –a—— H:\net_save.dna
2008-01-08 17:46 . 2008-01-08 17:46 d——– H:\Program Files\support.com
2008-01-08 17:45 . 2008-01-08 17:45 d——– H:\Documents and Settings\All Users\Application Data\Support.com
2008-01-08 17:32 . 2008-01-08 17:32 d—s—- H:\WINDOWS\system32\Microsoft
2008-01-08 17:32 . 2008-01-08 17:32 d–h—– H:\Program Files\Uninstall Information
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-08 20:55 ——— d—–w H:\Program Files\microsoft frontpage
2007-11-26 04:43 245,408 —-a-w H:\WINDOWS\system32\unicows.dll
2007-11-07 09:26 721,920 —-a-w H:\WINDOWS\system32\lsasrv.dll
2005-07-29 21:24 472 –sha-r H:\WINDOWS\RWwgTWluZ28\lqT0nq5RtZf.vbs
.
—-a-w 344,064 2008-01-21 19:16:38 H:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx .exe
—-a-w 53,248 2008-01-21 19:16:39 H:\Program Files\CyberLink\PowerDVD\DVDLauncher .exe
—-a-w 579,072 2008-01-21 19:16:40 H:\Program Files\Grisoft\AVG7\avgcc .exe
—-a-w 32,881 2008-01-21 19:16:37 H:\Program Files\Java\j2re1.4.2_03\bin\jusched .exe
—-a-w 37,376 2008-01-21 19:16:39 H:\Program Files\Winamp\winampa .exe
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3638816D-6683-5753-A9C8-68A3E4FDAABB}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{364C846D-6683-5753-A9C8-68A3E4FDAABB}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4263F9A7-EB3F-43F3-8D03-C2709737A092}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{483CF06D-6A86-5767-A9C8-68A3E4FDAABB}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5E85C971-F9E7-4F4D-A059-14FA00220C7A}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7AD776AF-69CB-4DB7-98DF-C7770024EDE8}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B26EDEBA-D240-477A-AC31-D0B7650D9F98}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B55F2E58-AABA-490D-B3EC-6678204AF6D9}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EFC3AF1C-7496-4B88-B60F-EA317A79A0DC}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="H:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00 15360]
"SpybotSD TeaTimer"="H:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46 1460560]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="H:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [ ]
"SigmatelSysTrayApp"="stsystra.exe" [2005-03-22 18:20 339968 H:\WINDOWS\stsystra.exe]
"AVG7_CC"="H:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [ ]
"00PCTFW"="H:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe" [2007-12-31 09:16 2594712]
"Ad-Watch"="H:\Program Files\Lavasoft\Ad-Aware 2007\Ad-Watch2007.exe" [ ]
"WinampAgent"="H:\Program Files\Winamp\winampa.exe" [2008-01-15 17:54 37376]
"PWRISOVM.EXE"="H:\Program Files\PowerISO\PWRISOVM.EXE" [2007-08-06 19:05 200704]
"GrooveMonitor"="H:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 00:47 31016]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="H:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-01-21 13:56 219136]
R1 pctfw2;pctfw2;H:\WINDOWS\system32\drivers\pctfw2.sys [2008-01-04 14:13]
R1 pctmp;PC Tools Firewall Memory Protection Driver;H:\WINDOWS\system32\drivers\pctmp.sys [2008-01-04 14:13]
R1 pctssipc;PC Tools Security Suite IPC Driver;H:\WINDOWS\system32\drivers\pctssipc.sys [2008-01-04 14:13]
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-02-01 16:33:50
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
———————— Other Running Processes ————————
.
H:\WINDOWS\system32\savedump.exe
H:\WINDOWS\system32\Ati2evxx.exe
H:\Program Files\PC Tools Firewall Plus\FWService.exe
H:\WINDOWS\stsystra.exe
H:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe
H:\Program Files\Winamp\winampa.exe
H:\Program Files\PowerISO\PWRISOVM.EXE
H:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
H:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
H:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
H:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
H:\PROGRA~1\Grisoft\AVG7\avgemc.exe
H:\WINDOWS\system32\wdfmgr.exe
H:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-02-01 16:34:36 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-01 21:34:34
.
2008-01-30 18:42:19 — E O F —
Adobe Flash Player ActiveX
ATI - Software Uninstall Utility
ATI Control Panel
ATI Display Driver
ATI Parental Control
AVG 7.5
BitTorrent
CCleaner (remove only)
Comcast High-Speed Internet Install Wizard
Conexant HDA D110 MDC V.92 Modem
Dell Resource CD
High Definition Audio Driver Package - KB835221
HijackThis 2.0.2
Intel® PRO Network Connections Drivers
Java 2 Runtime Environment, SE v1.4.2_03
Magic ISO Maker v5.4 (build 0251)
Microsoft Expression Web
Microsoft Expression Web MUI (English)
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Project MUI (English) 2007
Microsoft Office Project Professional 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Visio MUI (English) 2007
Microsoft Office Visio Professional 2007
Microsoft Office Word MUI (English) 2007
Microsoft Software Update for Web Folders (English) 12
Modem Helper
NoAd HOSTS file (remove only)
PC Tools Firewall Plus 3.0
PowerDVD 5.5
PowerISO
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB936782)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937894)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941568)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB941644)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB943485)
Security Update for Windows XP (KB944653)
SigmaTel Audio
Spybot - Search & Destroy
TweakNow RegCleaner Standard
Update for Outlook 2007 Junk Email Filter (kb943597)
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB908531)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB930916)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
WebFldrs XP
Winamp
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Media Format Runtime
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
WinRAR archiver
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:37:15 PM, on 2/1/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal
Running processes:
H:\WINDOWS\System32\smss.exe
H:\WINDOWS\system32\winlogon.exe
H:\WINDOWS\system32\services.exe
H:\WINDOWS\system32\savedump.exe
H:\WINDOWS\system32\lsass.exe
H:\WINDOWS\system32\Ati2evxx.exe
H:\WINDOWS\system32\svchost.exe
H:\Program Files\PC Tools Firewall Plus\FWService.exe
H:\WINDOWS\System32\svchost.exe
H:\WINDOWS\system32\spoolsv.exe
H:\WINDOWS\Explorer.EXE
H:\WINDOWS\stsystra.exe
H:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe
H:\Program Files\Winamp\winampa.exe
H:\Program Files\PowerISO\PWRISOVM.EXE
H:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
H:\WINDOWS\system32\ctfmon.exe
H:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
H:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
H:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
H:\PROGRA~1\Grisoft\AVG7\avgemc.exe
H:\WINDOWS\system32\wscntfy.exe
H:\WINDOWS\system32\wuauclt.exe
H:\WINDOWS\system32\notepad.exe
H:\Program Files\Internet Explorer\IEXPLORE.EXE
H:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - H:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - H:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O4 - HKLM\..\Run: [ATIPTA] H:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [AVG7_CC] H:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [00PCTFW] "H:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe" -s
O4 - HKLM\..\Run: [Ad-Watch] H:\Program Files\Lavasoft\Ad-Aware 2007\Ad-Watch2007.exe
O4 - HKLM\..\Run: [WinampAgent] "H:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [PWRISOVM.EXE] H:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [GrooveMonitor] "H:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKCU\..\Run: [ctfmon.exe] H:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] H:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] H:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] H:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] H:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] H:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://H:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - H:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - H:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - H:\PROGRA~1\MIC273~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - H:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - H:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/Facebo…toUploader3.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - H:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - H:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - H:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - H:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - H:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - H:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: PC Tools Firewall Plus (PCToolsFirewallPlus) - PC Tools - H:\Program Files\PC Tools Firewall Plus\FWService.exe
–
End of file - 5019 bytes
Thanks for your help Simon! Spybot requested perm to delete a bunch of BHO registry keys upon reboot, so hopefully that's a good sign. Please let me know if there's anything else I should do.
jenn.