Here's ComboFix Report
"Eric" - 07-02-11 15:54:54 Service Pack 2
ComboFix 07-02-11 - Running from: "C:\Program Files\Mozilla Firefox"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\Program Files\VSAdd-in
((((((((((((((((((((((((((((((( Files Created from 2007-01-11 to 2007-02-11 ))))))))))))))))))))))))))))))))))
2007-02-11 13:42 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-02-11 13:34 <DIR> d-------- C:\!KillBox
2007-02-11 10:27 1,934 --a------ C:\WINDOWS\system32\tmp.reg
2007-02-11 10:25 79,360 --a------ C:\WINDOWS\system32\swxcacls.exe
2007-02-11 10:25 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-02-11 10:25 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-02-11 10:25 40,960 --a------ C:\WINDOWS\system32\swsc.exe
2007-02-11 10:25 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2007-02-11 10:25 135,168 --a------ C:\WINDOWS\system32\swreg.exe
2007-02-11 10:03 <DIR> d-------- C:\Program Files\Hijackthis
2007-02-10 21:55 1,026,435 --ahs---- C:\WINDOWS\system32\ehiii.bak2
2007-02-09 21:53 <DIR> d-------- C:\VundoFix Backups
2007-02-09 21:26 1,152 --a------ C:\WINDOWS\system32\windrv.sys
2007-02-09 21:25 <DIR> d-------- C:\Program Files\Common Files\Download Manager
2007-02-08 17:54 <DIR> d-------- C:\DOCUME~1\WHEELE~1\Application Data\AVG7
2007-02-07 13:01 <DIR> dr-h----- C:\$VAULT$.AVG
2007-02-07 11:14 4,960 --a------ C:\WINDOWS\system32\drivers\avgtdi.sys
2007-02-07 11:14 3,968 --a------ C:\WINDOWS\system32\drivers\avgclean.sys
2007-02-07 11:14 18,432 --a------ C:\WINDOWS\system32\drivers\avgmfx86.sys
2007-02-07 10:29 <DIR> d-------- C:\DOCUME~1\LOCALS~1\Application Data\AVG7
2007-02-07 10:28 12,288,463 --------- C:\AVG7QT.DAT
2007-02-07 00:46 <DIR> d-------- C:\DOCUME~1\Eric\Application Data\AVG7
2007-02-07 00:35 839,936 --a------ C:\WINDOWS\system32\drivers\avg7core.sys
2007-02-07 00:35 4,224 --a------ C:\WINDOWS\system32\drivers\avg7rsw.sys
2007-02-07 00:35 27,776 --a------ C:\WINDOWS\system32\drivers\avg7rsxp.sys
2007-02-07 00:35 <DIR> d-------- C:\Program Files\Grisoft
2007-02-07 00:35 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Grisoft
2007-02-07 00:35 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\avg7
2007-02-05 22:25 <DIR> d-------- C:\Program Files\Common Files\Panda Software
2007-02-05 16:56 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Spybot - Search & Destroy
2007-02-05 10:35 <DIR> d-------- C:\DOCUME~1\Eric\Application Data\Lavasoft
2007-02-05 10:33 <DIR> d-------- C:\Program Files\Lavasoft
2007-02-05 10:03 <DIR> d-------- C:\DOCUME~1\Eric\Application Data\PC Tools
2007-02-05 00:05 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\TEMP
2007-02-04 23:12 <DIR> d-------- C:\Program Files\Common Files\DriveCleaner Free
2007-02-04 22:04 22,616 --------- C:\WINDOWS\system32\opnolll.dll
2007-02-03 13:51 <DIR> d-------- C:\Program Files\Psygnosis
2007-02-03 11:49 <DIR> d-------- C:\DOCUME~1\WHEELE~1\WINDOWS
2007-02-01 07:32 66,560 --------- C:\WINDOWS\system32\rsbmsc.exe
2007-01-30 07:53 61,440 --a------ C:\WINDOWS\system32\WebIQInstall.exe
2007-01-30 07:53 <DIR> d-------- C:\Program Files\WebIQ
2007-01-29 20:01 <DIR> d-------- C:\DOCUME~1\WHEELE~1\Application Data\Snapfish
2007-01-23 21:46 394 --a------ C:\WINDOWS\system32\mbosvc.exe
2007-01-21 22:41 <DIR> d-------- C:\DOCUME~1\WHEELE~1\.thumbnails
2007-01-21 22:36 <DIR> d-------- C:\DOCUME~1\WHEELE~1\Application Data\gtk-2.0
2007-01-21 22:30 <DIR> d-------- C:\DOCUME~1\WHEELE~1\.gimp-2.2
2007-01-21 22:24 <DIR> d-------- C:\Program Files\GIMP-2.0
2007-01-21 22:19 <DIR> d-------- C:\Program Files\Common Files\GTK
2007-01-21 21:31 <DIR> d-------- C:\Program Files\Common Files\Adobe
2007-01-21 21:31 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Adobe
2007-01-21 15:47 <DIR> d-------- C:\DOCUME~1\WHEELE~1\Application Data\AdobeUM
2007-01-17 19:34 <DIR> d-------- C:\DOCUME~1\Eric\Application Data\Viewpoint
2007-01-11 21:31 <DIR> d-------- C:\DOCUME~1\WHEELE~1\Application Data\Viewpoint
2007-01-11 16:51 66,560 --a------ C:\WINDOWS\system32\mgosvc.exe
2007-01-11 08:08 <DIR> d-------- C:\WINDOWS\ie7updates
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-02-11 15:54 -------- d-------- C:\Program Files\mozilla firefox
2007-02-11 10:23 -------- d-------- C:\Program Files\zipcentral
2007-02-07 00:57 -------- d-------- C:\Program Files\yahoo!
2007-02-07 00:52 -------- d-------- C:\Program Files\Common Files\scanner
2007-02-06 22:38 3479 --a--c--- C:\WINDOWS\mozver.dat
2007-02-06 14:09 -------- d--h----- C:\Program Files\installshield installation information
2007-02-06 12:08 -------- d-------- C:\Program Files\quicktime
2007-02-06 00:06 -------- d-------- C:\Program Files\aim6
2007-02-03 11:58 287 --a--c--- C:\WINDOWS\ereg072.dat
2007-01-14 15:27 -------- d-------- C:\Program Files\limewire
2007-01-08 16:49 5868 --a------ C:\WINDOWS\system32\svmbi.exe
2007-01-08 16:38 4212 --ah----- C:\WINDOWS\system32\zllictbl.dat
2007-01-08 16:26 -------- d-------- C:\Program Files\sbc self support tool
2007-01-08 16:26 -------- d-------- C:\DOCUME~1\Eric\Application Data\motive
2007-01-08 16:24 -------- d-------- C:\Program Files\Common Files\motive
2007-01-05 22:55 -------- d-------- C:\Program Files\tweaknow regcleaner std
2006-12-29 18:39 76560 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2006-12-25 18:03 -------- d-------- C:\Program Files\musicmatch
2006-12-11 22:27 -------- d-------- C:\Program Files\Common Files\aol
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"Aim6"=""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"HostManager"="C:\\Program Files\\Common Files\\AOL\\1138144130\\ee\\AOLSoftware.exe"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"Motive SmartBridge"="C:\\PROGRA~1\\SBCSEL~1\\SMARTB~1\\MotiveSB.exe"
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"
"!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
"8B7FA6D7"="C:\\WINDOWS\\system32\\rsbmsc.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
"backup"="C:\\WINDOWS\\pss\\Adobe Reader Speed Launch.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\Adobe\\ACROBA~1.0\\Reader\\READER~1.EXE "
"item"="Adobe Reader Speed Launch"
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Adobe Reader Speed Launch.lnk"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"=""
"hkey"="HKCU"
"command"=""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BJCFD]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="CFD"
"hkey"="HKLM"
"command"="C:\\Program Files\\BroadJump\\Client Foundation\\CFD.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ctfmon"
"hkey"="HKCU"
"command"="C:\\WINDOWS\\system32\\ctfmon.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="tfswctrl"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\system32\\dla\\tfswctrl.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EM_EXEC]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="EM_EXEC"
"hkey"="HKLM"
"command"="C:\\PROGRA~1\\Logitech\\MOUSEW~1\\SYSTEM\\EM_EXEC.EXE"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="AOLSoftware"
"hkey"="HKLM"
"command"="C:\\Program Files\\Common Files\\AOL\\1138144130\\ee\\AOLSoftware.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="HPWuSchd2"
"hkey"="HKLM"
"command"="C:\\Program Files\\HP\\HP Software Update\\HPWuSchd2.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHUPD08]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="hphupd08"
"hkey"="HKLM"
"command"="C:\\Program Files\\HP\\Digital Imaging\\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\\hphupd08.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IPHSend]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="IPHSend"
"hkey"="HKLM"
"command"="C:\\Program Files\\Common Files\\AOL\\IPHSend\\IPHSend.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NvCpl"
"hkey"="HKLM"
"command"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NvMcTray"
"hkey"="HKLM"
"command"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="nwiz"
"hkey"="HKLM"
"command"="nwiz.exe /install"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OFFICEKB]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="kbdap32a"
"hkey"="HKLM"
"command"="C:\\Program Files\\Micro Innovations\\Keyboard\\kbdap32a.EXE"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PrinTray]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="printray"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\2\\printray.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="qttask"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sonic RecordNow!]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"=""
"hkey"="HKCU"
"command"=""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StorageGuard]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="sgtray"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Common Files\\Sonic\\Update Manager\\sgtray.exe\" /r"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="jusched"
"hkey"="HKLM"
"command"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ViewMgr]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ViewMgr"
"hkey"="HKLM"
"command"="C:\\Program Files\\Viewpoint\\Viewpoint Manager\\ViewMgr.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{7F5A2699-38CD-4B98-B193-5916D6566B01}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\opnolll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\XoftSpy.job
********************************************************************
catchme 0.1 W2K/XP - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
********************************************************************
Completion time: 07-02-11 16:02:02