Here\'s the Combofix log:
"sheilman" - 07-01-30 13:21:07 Service Pack 2
ComboFix 07.01.30 - Running from: "C:\Documents and Settings\sheilman\Desktop"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\bszip.dll
((((((((((((((((((((((((((((((( Files Created from 2006-12-30 to 2007-01-30 ))))))))))))))))))))))))))))))))))
2007-01-30 11:39 <DIR> d-------- C:\bintheredunthat
2007-01-30 11:19 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-01-30 11:19 <DIR> d-------- C:\Program Files\Grisoft
2007-01-30 11:01 <DIR> d-------- C:\BFU
2007-01-26 15:22 <DIR> d-------- C:\HJT
2007-01-26 11:33 147,456 --a------ C:\WINDOWS\system32\vbzip10.dll
2007-01-26 09:16 <DIR> d--hs---- C:\DOCUME~1\sheilman\Complete
2007-01-18 11:58 <DIR> d-------- C:\OLDGAMES
2007-01-18 08:15 561,152 --a------ C:\WINDOWS\AJScreensaver.scr
2007-01-15 17:02 <DIR> d-------- C:\WINDOWS\ie7updates
2007-01-12 09:17 <DIR> d-------- C:\Program Files\Lavasoft
2007-01-12 09:17 <DIR> d-------- C:\DOCUME~1\sheilman\Application Data\Lavasoft
2007-01-09 12:30 20,640 --------- C:\WINDOWS\system32\drivers\PxHelp20.sys
2007-01-09 12:30 109,568 --------- C:\WINDOWS\system32\pxinsi64.exe
2007-01-09 12:30 108,544 --------- C:\WINDOWS\system32\pxcpyi64.exe
2007-01-09 08:00 <DIR> d-------- C:\Program Files\MTV Networks
2007-01-09 07:26 <DIR> d-------- C:\Program Files\Real
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-01-30 10:46 -------- d---s---- C:\DOCUME~1\sheilman\Application Data\microsoft
2007-01-30 09:48 29392 --a------ C:\WINDOWS\system32\drivers\secdrv.sys
2007-01-30 09:46 -------- d--h----- C:\Program Files\installshield installation information
2007-01-25 13:22 -------- d-------- C:\Program Files\google
2007-01-18 15:50 -------- d-------- C:\Program Files\strucalc 7.0
2007-01-18 09:40 -------- d-------- C:\Program Files\Common Files\adobe
2007-01-18 09:40 -------- d-------- C:\DOCUME~1\sheilman\Application Data\adobe
2007-01-09 12:31 -------- d-------- C:\Program Files\divx
2007-01-04 17:02 -------- d-------- C:\DOCUME~1\sheilman\Application Data\adobeum
2006-12-21 12:55 -------- d-------- C:\DOCUME~1\sheilman\Application Data\downloaded installations
2006-12-19 08:57 -------- d-------- C:\Program Files\java
2006-12-18 13:31 -------- d-------- C:\Program Files\vpholdem
2006-12-15 11:14 -------- d-------- C:\Program Files\Common Files\autodesk shared
2006-12-15 11:14 -------- d-------- C:\Program Files\autodesk impression
2006-12-15 11:13 -------- d-------- C:\DOCUME~1\sheilman\Application Data\autodesk
2006-12-15 11:12 -------- d-------- C:\Program Files\autodesk
2006-12-15 10:44 -------- d-------- C:\Program Files\textaloud
2006-12-12 07:30 520192 --a------ C:\WINDOWS\system32\divxsm.exe
2006-12-12 07:30 3596288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2006-12-12 07:30 200704 --a------ C:\WINDOWS\system32\ssldivx.dll
2006-12-12 07:30 1044480 --a------ C:\WINDOWS\system32\libdivx.dll
2006-12-12 07:25 806912 --a------ C:\WINDOWS\system32\divx_xx0c.dll
2006-12-12 07:25 806912 --a------ C:\WINDOWS\system32\divx_xx07.dll
2006-12-12 07:25 790528 --a------ C:\WINDOWS\system32\divx_xx11.dll
2006-12-12 07:25 73728 --a------ C:\WINDOWS\system32\dpl100.dll
2006-12-12 07:25 635486 --a------ C:\WINDOWS\system32\divx.dll
2006-12-12 07:25 593920 --a------ C:\WINDOWS\system32\dpugui11.dll
2006-12-12 07:25 57344 --a------ C:\WINDOWS\system32\dpv11.dll
2006-12-12 07:25 53248 --a------ C:\WINDOWS\system32\dpugui10.dll
2006-12-12 07:25 344064 --a------ C:\WINDOWS\system32\dpus11.dll
2006-12-12 07:25 294912 --a------ C:\WINDOWS\system32\dpu11.dll
2006-12-12 07:25 294912 --a------ C:\WINDOWS\system32\dpu10.dll
2006-12-12 07:25 196608 --a------ C:\WINDOWS\system32\dtu100.dll
2006-12-12 07:24 12288 --a------ C:\WINDOWS\system32\divxwmpexttype.dll
2006-12-12 07:24 118784 --a------ C:\WINDOWS\system32\divxcodecupdatechecker.exe
2006-12-07 10:45 -------- d-------- C:\Program Files\accurender 4.0
2006-12-07 10:44 -------- d-------- C:\Program Files\Common Files\mcneel shared
2006-11-07 21:03 6049280 --------- C:\WINDOWS\system32\ieframe.dll
2006-11-07 21:03 50688 --------- C:\WINDOWS\system32\msfeedsbs.dll
2006-11-07 21:03 458752 --------- C:\WINDOWS\system32\msfeeds.dll
2006-11-07 21:03 413696 --a------ C:\WINDOWS\system32\vbscript.dll
2006-11-07 21:03 231424 --a------ C:\WINDOWS\system32\webcheck.dll
2006-11-07 21:03 180736 --------- C:\WINDOWS\system32\ieui.dll
2006-11-07 21:03 156160 --a------ C:\WINDOWS\system32\msls31.dll
2006-11-07 20:06 679424 --a------ C:\WINDOWS\system32\inetcomm.dll
2006-11-07 03:27 382976 --a------ C:\WINDOWS\system32\iedkcs32.dll
2006-11-07 03:27 229376 --a------ C:\WINDOWS\system32\ieaksie.dll
2006-11-07 03:26 71680 --a------ C:\WINDOWS\system32\admparse.dll
2006-11-07 03:26 55296 --a------ C:\WINDOWS\system32\iesetup.dll
2006-11-07 03:26 54784 --a------ C:\WINDOWS\system32\ie4uinit.exe
2006-11-07 03:26 43008 --a------ C:\WINDOWS\system32\iernonce.dll
2006-11-07 03:26 152064 --a------ C:\WINDOWS\system32\ieakeng.dll
2006-11-07 03:26 13312 --a------ C:\WINDOWS\system32\ieudinit.exe
2006-11-07 03:26 123904 --a------ C:\WINDOWS\system32\advpack.dll
2006-11-07 03:25 161792 --a------ C:\WINDOWS\system32\ieakui.dll
2006-11-04 14:14 1245696 --a------ C:\WINDOWS\system32\msxml4.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"googletalk"="\"C:\\Program Files\\Google\\Google Talk\\googletalk.exe\" /autostart"
"Exodus"="C:\\Program Files\\Exodus\\Exodus.exe"
"H/PC Connection Agent"="\"C:\\Program Files\\Microsoft ActiveSync\\WCESCOMM.EXE\""
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_10\\bin\\jusched.exe\""
"SigmatelSysTrayApp"="stsystra.exe"
"Document Manager"="C:\\Program Files\\Wave Systems Corp\\Services Manager\\DocMgr\\bin\\docmgr.exe"
"IAAnotif"="C:\\Program Files\\Intel\\Intel Matrix Storage Manager\\iaanotif.exe"
"DVDLauncher"="\"C:\\Program Files\\CyberLink\\PowerDVD\\DVDLauncher.exe\""
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /install"
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit"
"DLPSP"="\"C:\\Program Files\\Dell Printers\\Additional Color Laser Software\\Status Monitor\\DLPSP.EXE\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"appinit_dlls"="wxvault.dll"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter
LocalService REG_MULTI_SZ AlerterWebClientLmHostsRemoteRegistryupnphostSSDPSRV
NetworkService REG_MULTI_SZ DnsCache
DcomLaunch REG_MULTI_SZ DcomLaunchTermService
rpcss REG_MULTI_SZ RpcSs
imgsvc REG_MULTI_SZ StiSvc
termsvcs REG_MULTI_SZ TermService
WudfServiceGroup REG_MULTI_SZ WUDFSvc
Completion time: 07-01-30 13:22:57
And the AVG scan:
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 12:09:37 PM 1/30/2007
+ Scan result:
C:\Documents and Settings\sheilman\My Documents\DVD stuff\The good stuff\TheaterTek DVD 2.4.0.12.rar/Setup.exe -> Backdoor.IRCBot.dd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP133\A0012356.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP134\A0012500.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP134\A0012501.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP134\A0012531.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP135\A0012587.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP135\A0012626.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP138\A0012892.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP138\A0012916.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
C:\WINDOWS\Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
C:\b.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
C:\Documents and Settings\sheilman\Cookies\
[email protected][2].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\sheilman\Cookies\sheilman@adbrite[2].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\sheilman\Cookies\sheilman@advertising[1].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\sheilman\Cookies\sheilman@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\sheilman\Cookies\
[email protected][1].txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\sheilman\Cookies\sheilman@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\sheilman\Cookies\
[email protected][2].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\sheilman\Cookies\sheilman@com[1].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\sheilman\Cookies\sheilman@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned.
C:\Documents and Settings\sheilman\Cookies\sheilman@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\sheilman\Cookies\
[email protected][1].txt -> TrackingCookie.Falkag : Cleaned.
C:\Documents and Settings\sheilman\Cookies\sheilman@fastclick[2].txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\sheilman\Cookies\
[email protected][1].txt -> TrackingCookie.Hitslink : Cleaned.
C:\Documents and Settings\sheilman\Cookies\
[email protected][1].txt -> TrackingCookie.Liveperson : Cleaned.
C:\Documents and Settings\sheilman\Cookies\
[email protected][1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\sheilman\Cookies\sheilman@questionmarket[2].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\sheilman\Cookies\
[email protected][1].txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\sheilman\Cookies\
[email protected][1].txt -> TrackingCookie.Starware : Cleaned.
C:\Documents and Settings\sheilman\Cookies\
[email protected][2].txt -> TrackingCookie.Starware : Cleaned.
C:\Documents and Settings\sheilman\Cookies\sheilman@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\sheilman\Cookies\sheilman@trafficmp[2].txt -> TrackingCookie.Trafficmp : Cleaned.
C:\Documents and Settings\sheilman\Cookies\sheilman@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Documents and Settings\sheilman\Cookies\
[email protected][1].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP133\A0012319.exe -> Worm.VB.an : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP133\A0012333.exe -> Worm.VB.an : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP138\A0012915.exe -> Worm.VB.an : Cleaned with backup (quarantined).
::Report end