I think it all started with a MSN virus my brother gotten lately... but in that process I found more things that just didn't really seem to make any sense. I downloaded AVG and it showed some files to be Trojan Backdoor.agent something. Can't really remember... (my bad... :sad: )
Searched up that string of letters and found this place and thought it might help. Here's a ComboFix and HijackThis log.
ComboFix 07-12-21.4 - NICHOLAS CHEW 2007-12-21 17:46:09.1 - NTFSx86
Running from: C:\Documents and Settings\NICHOLAS CHEW\desktop\ComboFix.exe
Command switches used :: /KillAll
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\autorun.inf
C:\WINDOWS\system32\9_exception.nls
C:\WINDOWS\SYSTEM32\bmehgltd.ini
C:\WINDOWS\system32\drivers\sfsync02.sys
C:\WINDOWS\system32\dtlghemb.dll
C:\WINDOWS\SYSTEM32\lndpcegs.ini
C:\WINDOWS\system32\nnnmkji.dll
C:\WINDOWS\SYSTEM32\qrtwa.ini
C:\WINDOWS\SYSTEM32\qrtwa.ini2
C:\WINDOWS\system32\sgecpdnl.dll
C:\WINDOWS\system32\upbdgpmb.dll
C:\WINDOWS\SYSTEM32\vuutv.ini2
C:\WINDOWS\system32\vwtvwosy.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_SFSYNC02
-------\sfsync02
((((((((((((((((((((((((( Files Created from 2007-11-21 to 2007-12-21 )))))))))))))))))))))))))))))))
.
2007-12-21 17:56 . 2007-12-21 17:56 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2007-12-21 17:56 . 2007-12-21 17:56 1,409 --a------ C:\WINDOWS\QTFont.for
2007-12-21 17:31 . 2007-12-21 17:31 <DIR> d-------- C:\Program Files\Windows Defender
2007-12-21 16:01 . 2007-12-21 16:01 0 --a------ C:\WINDOWS\SYSTEM32\SBRC.dat
2007-12-21 16:01 . 2007-12-21 16:01 0 --a------ C:\WINDOWS\SYSTEM32\SBFC.dat
2007-12-21 15:50 . 2007-12-21 15:50 <DIR> d-------- C:\Documents and Settings\NICHOLAS CHEW\Application Data\Sunbelt Software
2007-12-21 03:23 . 2007-12-21 13:12 <DIR> d-------- C:\Program Files\Windows Live Safety Center
2007-12-21 02:59 . 2007-12-21 02:59 <DIR> d-------- C:\Program Files\WIZET
2007-12-20 05:50 . 2007-12-20 06:02 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2007-12-20 05:49 . 2007-12-21 17:21 <DIR> d-------- C:\Program Files\Windows Live
2007-12-20 05:48 . 2007-12-21 17:19 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2007-12-20 05:40 . 2007-12-21 09:30 <DIR> d-------- C:\BackUpMSNCleaner
2007-12-20 03:41 . 2007-12-20 03:41 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2007-12-20 03:39 . 2007-12-20 03:39 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-20 03:39 . 2007-12-21 04:52 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg7
2007-12-20 03:16 . 2007-12-20 03:16 <DIR> d-------- C:\Program Files\Plasma Pong
2007-12-20 02:50 . 2007-12-21 12:59 <DIR> d-------- C:\Documents and Settings\NICHOLAS CHEW\Application Data\AVG7
2007-12-20 02:47 . 2007-12-20 03:16 <DIR> d-------- C:\Program Files\Grisoft(2)
2007-12-20 02:47 . 2007-12-20 03:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft(2)
2007-12-20 02:47 . 2007-12-20 03:15 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg7(2)
2007-12-20 02:21 . 2007-12-20 02:21 <DIR> d-------- C:\Documents and Settings\NICHOLAS CHEW\DoctorWeb
2007-12-19 21:54 . 2007-12-19 21:54 74,304 --a------ C:\WINDOWS\SYSTEM32\pwajtnmk.exe
2007-12-19 11:33 . 2007-12-19 11:33 74,304 --a------ C:\WINDOWS\SYSTEM32\mnfnwrop.exe
2007-12-18 09:53 . 2007-12-18 10:17 6,630 --ahs---- C:\WINDOWS\SYSTEM32\fhkmp.ini
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-21 09:32 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-21 09:29 --------- d-----w C:\Documents and Settings\NICHOLAS CHEW\Application Data\Skype
2007-12-20 20:29 --------- d-----w C:\Documents and Settings\NICHOLAS CHEW\Application Data\Azureus
2007-12-20 19:15 --------- d-----w C:\Program Files\Azureus
2007-12-19 19:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-04 15:39 729,088 ----a-w C:\WINDOWS\iun6002.exe
2007-12-04 15:39 --------- d-----w C:\Program Files\Warcraft III
2007-11-21 17:11 --------- d-----w C:\Documents and Settings\NICHOLAS CHEW\Application Data\mIRC
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-08 15:14 --------- d-----w C:\Documents and Settings\SIMON CHEW\Application Data\mIRC
2007-11-08 10:59 --------- d-----w C:\Program Files\mIRC
2007-11-03 17:38 --------- d-----w C:\Program Files\Windows Media Connect 2
2007-10-21 13:45 --------- d-----w C:\Program Files\iTunes
2007-10-21 13:45 --------- d-----w C:\Program Files\iPod
2007-10-21 13:44 --------- d-----w C:\Program Files\QuickTime
2007-10-21 13:42 --------- d-----w C:\Program Files\Apple Software Update
2007-10-21 13:41 --------- d-----w C:\Program Files\Common Files\Apple
2007-10-21 13:41 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
2006-01-21 02:00 4,234 ----a-w C:\Documents and Settings\SIMON CHEW\!versions.dat
2005-05-13 09:12 217,073 --sha-r C:\WINDOWS\meta4.exe
2005-10-24 03:13 66,560 --sha-r C:\WINDOWS\MOTA113.exe
2005-10-13 13:27 422,400 --sha-r C:\WINDOWS\x2.64.exe
2005-10-07 11:14 308,224 --sha-r C:\WINDOWS\SYSTEM32\avisynth.dll
2005-07-14 04:31 27,648 --sha-r C:\WINDOWS\SYSTEM32\AVSredirect.dll
2005-06-26 07:32 616,448 --sha-r C:\WINDOWS\SYSTEM32\cygwin1.dll
2005-06-21 14:37 45,568 --sha-r C:\WINDOWS\SYSTEM32\cygz.dll
2004-01-24 16:00 70,656 --sha-r C:\WINDOWS\SYSTEM32\i420vfw.dll
2006-04-27 02:24 2,945,024 --sha-r C:\WINDOWS\SYSTEM32\Smab.dll
2005-02-28 05:16 240,128 --sha-r C:\WINDOWS\SYSTEM32\x.264.exe
2004-01-24 16:00 70,656 --sha-r C:\WINDOWS\SYSTEM32\yv12vfw.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2007-02-09 16:00]
"PcSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 06:24]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-09-26 14:42]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-12-21 02:30]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-14 00:24]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 16:38]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-12-20 03:40]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2004-08-04 05:00 C:\WINDOWS\SYSTEM32\NARRATOR.EXE]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2004-08-04 05:00 15360 --a------ C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
2004-12-06 01:05 127035 --a------ C:\WINDOWS\system32\dla\tfswctrl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DMXLauncher]
2005-01-27 01:02 86016 --a------ C:\Program Files\Dell\Media Experience\DMXLauncher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
2004-10-12 16:54 57344 --------- C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe -start
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2007-09-26 14:42 267064 --a------ C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
C:\Program Files\MSN Messenger\msnmsgr.exe /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MyWebSearch Email Plugin]
C:\PROGRA~1\MYWEBS~1\bar\3.bin\mwsoemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
2004-10-14 14:42 1404928 --a------ C:\Program Files\Analog Devices\Core\smax4pnp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2005-11-10 13:03 36975 --a------ C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe /r
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
C:\Program Files\Windows Defender\MSASCui.exe -hide
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WinDefend"=2 (0x2)
"usnjsvc"=3 (0x3)
"ServiceLayer"=3 (0x3)
"NetSvc"=3 (0x3)
"iPod Service"=3 (0x3)
"IDriverT"=3 (0x3)
"ATI Smart"=2 (0x2)
"Ati HotKey Poller"=2 (0x2)
S3 CEDRIVER51;CEDRIVER51;C:\Documents and Settings\NICHOLAS CHEW\My Documents\Cheat Engine\DBK32.sys []
S3 CEDRIVER52;CEDRIVER52;C:\Documents and Settings\NICHOLAS CHEW\My Documents\Cheat Engine\Cheat Engine\dbk32.sys []
S3 geebers12;geebers12;C:\Documents and Settings\SIMON CHEW\Desktop\Msea V0.42 hacks pack\Buffy Engine 2\nvid888.sys [2007-05-03 14:37]
S3 IlvMoneyDRIVER53;IlvMoneyDRIVER53;C:\Documents and Settings\NICHOLAS CHEW\My Documents\PSP Games\moonlight engine 1105.1\moonlight engine 1105.1\IlvMoney1105.sys []
.
Contents of the 'Scheduled Tasks' folder
"2007-12-07 10:30:01 C:\WINDOWS\Tasks\ANZ McAfee.com Scan for Viruses - My Computer (FAMILYROOM-JEANNIE CHAR).job"
- c:\program files\mcafee.com\vso\mcmnhdlr.exe
"2007-12-07 10:30:02 C:\WINDOWS\Tasks\ANZ McAfee.com Scan for Viruses - My Computer (FAMILYROOM-SIMON CHEW).job"
- c:\program files\mcafee.com\vso\mcmnhdlr.exe
"2007-12-20 09:27:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-12-21 09:58:06 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-21 17:56:03
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-21 17:58:53 - machine was rebooted [NICHOLAS CHEW]
.
2007-12-20 19:05:22 --- E O F ---
Logfile of HijackThis v1.99.1
Scan saved at 6:07:35 PM, on 12/21/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\conime.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Skype\Plugin Manager\SkypePM.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\NICHOLAS CHEW\My Documents\hijackthis\HijackThis.exe
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {2B866353-E598-4403-8E4D-B871AB30DC55} (Speed Class) - http://www.singnet.com.sg/technical/helptools/media/SpeedCtrl.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cab
O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games.com.my/com/EGamesPlugin.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase4009.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1138189840578
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
Hope there's someone who can save me. Thanks! :)
(Oh yes anyway, some of the files I mentioned seem to be picked up by ComboFix and deleted by CF. o.o)