Here's the log John. Thanks
ComboFix 09-12-17.01 - Jim's 12/17/2009 18:09:16.11.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1983.1503 [GMT -7:00]
Running from: c:\documents and settings\Jim's\My Documents\Currency Scanss\Family pictures\combofix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_IMAPISERVICE
-------\Service_ImapiService
((((((((((((((((((((((((( Files Created from 2009-11-18 to 2009-12-18 )))))))))))))))))))))))))))))))
.
2009-12-11 16:45 . 2009-11-25 16:42 3514648 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgui.exe
2009-12-11 16:45 . 2009-11-25 16:42 2029336 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgtray.exe
2009-12-05 16:05 . 2009-12-05 16:05 196608 ----a-w- c:\windows\system32\HMIPCore.dll
2009-11-27 01:08 . 2009-11-27 01:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Azureus
2009-11-27 01:08 . 2009-11-27 01:11 -------- d-----w- c:\documents and settings\Jim's\Application Data\Azureus
2009-11-27 01:08 . 2009-11-27 01:08 -------- d-----w- c:\program files\AskBarDis
2009-11-25 16:42 . 2009-11-25 16:42 2063640 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcorex.dll
2009-11-24 22:13 . 2009-11-24 22:13 79488 ----a-w- c:\documents and settings\Denise's\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-11-22 18:20 . 2009-11-22 18:20 388608 ----a-w- c:\windows\system32\CF10184.exe
2009-11-21 17:52 . 2009-11-21 17:56 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Temp
2009-11-21 17:49 . 2009-11-21 17:49 -------- d-----w- c:\windows\system32\wbem\Repository
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-13 16:24 . 2009-04-12 14:31 1 ----a-w- c:\documents and settings\Jim's\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-12-08 15:38 . 2009-07-20 15:41 -------- d-----w- c:\program files\Hide My IP 2009
2009-12-03 01:16 . 2006-02-18 23:20 -------- d-----w- c:\program files\PartyGaming
2009-11-21 16:57 . 2008-09-27 05:09 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-10-30 17:19 . 2009-10-30 17:19 -------- d-----w- c:\program files\Microsoft
2009-10-30 17:18 . 2004-08-10 14:08 -------- d-----w- c:\program files\Java
2009-10-23 00:09 . 2009-10-23 00:09 -------- d-----w- c:\documents and settings\Jim's\Application Data\Mozilla-Cache
2009-10-08 20:45 . 2009-08-28 14:10 152576 -c--a-w- c:\documents and settings\Jim's\Application Data\Sun\Java\jre1.6.0_15\lzma.dll
2008-03-01 19:13 . 2008-03-01 19:13 67 -c--a-w- c:\program files\rem_cdk.bat
2006-09-05 21:35 . 2006-09-05 21:35 60518 -c--a-w- c:\program files\mozilla firefox\components\jar50.dll
2006-09-05 21:35 . 2006-09-05 21:35 49248 -c--a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2006-09-05 21:35 . 2006-09-05 21:35 165992 -c--a-w- c:\program files\mozilla firefox\components\xpinstal.dll
.
((((((((((((((((((((((((((((( SnapShot_2009-11-22_18.38.19 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-12-18 01:21 . 2009-12-18 01:21 16384 c:\windows\temp\Perflib_Perfdata_88.dat
+ 2009-08-23 04:17 . 2009-12-16 05:17 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2009-08-23 04:17 . 2009-11-10 20:03 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2004-08-10 13:42 . 2009-12-16 05:17 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2004-08-10 13:42 . 2009-11-10 20:03 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-12-16 05:17 . 2009-12-16 05:17 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2009-09-27 20:42 . 2009-11-10 20:03 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2009-12-05 07:07 . 2009-12-05 07:07 25214 c:\windows\Installer\{9074AFC0-CFDA-11DE-B484-005056806466}\UNINST_Uninstall_G_F6A848FB884248E6A4CDCBDCF41F6A74_1.exe
+ 2009-12-05 07:07 . 2009-12-05 07:07 25214 c:\windows\Installer\{9074AFC0-CFDA-11DE-B484-005056806466}\UNINST_Uninstall_G_F6A848FB884248E6A4CDCBDCF41F6A74.exe
+ 2009-12-05 07:07 . 2009-12-05 07:07 25214 c:\windows\Installer\{9074AFC0-CFDA-11DE-B484-005056806466}\ShortcutOGL_EB071909B9884F8CBF3D6115D4ADEE5E.exe
+ 2009-12-05 07:07 . 2009-12-05 07:07 25214 c:\windows\Installer\{9074AFC0-CFDA-11DE-B484-005056806466}\ShortcutDX_EB071909B9884F8CBF3D6115D4ADEE5E.exe
+ 2009-12-05 07:07 . 2009-12-05 07:07 25214 c:\windows\Installer\{9074AFC0-CFDA-11DE-B484-005056806466}\googleearth.exe1_F6A848FB884248E6A4CDCBDCF41F6A74.exe
+ 2009-12-05 07:07 . 2009-12-05 07:07 25214 c:\windows\Installer\{9074AFC0-CFDA-11DE-B484-005056806466}\googleearth.exe_F6A848FB884248E6A4CDCBDCF41F6A74.exe
+ 2009-12-05 07:07 . 2009-12-05 07:07 25214 c:\windows\Installer\{9074AFC0-CFDA-11DE-B484-005056806466}\ARPPRODUCTICON.exe
+ 2009-12-05 07:07 . 2009-12-05 07:07 1258496 c:\windows\Installer\3839252.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 1107200]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2009-04-02 19:47 333192 ----a-w- c:\program files\AskBarDis\bar\bin\askBar.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-09-02 18:58 1107200 ----a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 1107200]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2009-04-02 333192]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 1107200]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2009-04-02 333192]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-08-04 1667584]
"Desktop Software"="c:\program files\ComcastUI\Universal Installer\uinstaller.exe" [2008-03-18 984616]
"Universal Installer"="c:\program files\ComcastUI\Universal Installer\uinstaller.exe" [2008-03-18 984616]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-17 68856]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-12-11 2043160]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2009-10-10 203264]
"AGRSMMSG"="AGRSMMSG.exe" [2004-06-30 88363]
"AlcxMonitor"="ALCXMNTR.EXE" [2003-04-04 50176]
"VTTimer"="VTTimer.exe" [2004-03-27 49152]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-28 35696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-28 16:52 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^palstart.exe]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\palstart.exe
backup=c:\windows\pss\palstart.exeCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [7/1/2009 11:32 AM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [7/1/2009 11:32 AM 108552]
R2 ASKService;ASKService;c:\program files\AskBarDis\bar\bin\AskService.exe [11/26/2009 6:08 PM 464264]
R2 ASKUpgrade;ASKUpgrade;c:\program files\AskBarDis\bar\bin\ASKUpgrade.exe [11/26/2009 6:08 PM 234888]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [7/1/2009 11:31 AM 908056]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [7/1/2009 11:31 AM 297752]
R2 litsgt;litsgt;c:\windows\system32\drivers\litsgt.sys [5/17/2006 5:20 PM 137344]
R2 tansgt;tansgt;c:\windows\system32\drivers\tansgt.sys [5/17/2006 5:20 PM 12032]
R3 HideMyIpSRV;HideMyIpSRV;c:\program files\Hide My IP 2009\HideMyIpSrv.exe [12/5/2009 9:05 AM 2396464]
S2 gupdate1ca1eb267fa681e;Google Update Service (gupdate1ca1eb267fa681e);c:\program files\Google\Update\GoogleUpdate.exe [12/11/2008 9:52 PM 133104]
S3 XIRLINK;Veo PC Camera;c:\windows\system32\drivers\ucdnt.sys [2/11/2005 4:13 PM 899884]
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mStart Page = about:blank
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q404&bd=presario&pf=desktop
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: Add to Windows &Live Favorites -
http://favorites.live.com/quickadd.aspx
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
LSP: c:\windows\system32\HMIPCore.dll
FF - ProfilePath - c:\documents and settings\Jim's\Application Data\Mozilla\Firefox\Profiles\pmmfpy17.default\
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-12-17 18:43
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(760)
c:\windows\system32\HMIPCore.dll
- - - - - - - > 'explorer.exe'(3888)
c:\windows\system32\msi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\drivers\KodakCCS.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
c:\windows\system32\wdfmgr.exe
c:\progra~1\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\windows\AGRSMMSG.exe
c:\windows\ALCXMNTR.EXE
c:\windows\system32\VTTimer.exe
.
**************************************************************************
.
Completion time: 2009-12-17 18:49:18 - machine was rebooted
ComboFix-quarantined-files.txt 2009-12-18 01:49
ComboFix2.txt 2009-12-15 18:41
ComboFix3.txt 2009-12-12 18:09
ComboFix4.txt 2009-12-11 19:23
ComboFix5.txt 2009-12-18 01:08
Pre-Run: 52,768,055,296 bytes free
Post-Run: 53,039,493,120 bytes free
- - End Of File - - 302ED93FA24FBDE5E37A0A36D1729906