Thanks! Sorry about the code tags

, I've removed them now. here's the combofix result...
ComboFix 09-10-17.01 - Peter 20/10/2009 10:59.3.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.765.468 [GMT 0:00]
Running from: c:\documents and settings\Peter\Desktop\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}
.
((((((((((((((((((((((((( Files Created from 2009-09-20 to 2009-10-20 )))))))))))))))))))))))))))))))
.
2009-10-18 23:25 . 2009-10-18 23:25 -------- d-----w- c:\program files\Trend Micro
2009-10-18 23:19 . 2008-04-14 05:42 18944 -c--a-w- c:\windows\system32\dllcache\xrxscnui.dll
2009-10-18 23:19 . 2008-04-14 05:42 116224 -c--a-w- c:\windows\system32\dllcache\xrxwiadr.dll
2009-10-18 23:19 . 2001-08-17 22:36 23040 -c--a-w- c:\windows\system32\dllcache\xrxwbtmp.dll
2009-10-18 23:19 . 2001-08-17 22:37 4608 -c--a-w- c:\windows\system32\dllcache\xrxflnch.exe
2009-10-18 23:19 . 2001-08-17 22:37 27648 -c--a-w- c:\windows\system32\dllcache\xrxftplt.exe
2009-10-18 23:19 . 2001-08-17 22:37 99865 -c--a-w- c:\windows\system32\dllcache\xlog.exe
2009-10-18 23:19 . 2001-08-17 12:11 16970 -c--a-w- c:\windows\system32\dllcache\xem336n5.sys
2009-10-18 23:19 . 2008-04-13 22:04 19455 -c--a-w- c:\windows\system32\dllcache\wvchntxx.sys
2009-10-18 23:19 . 2008-04-14 00:16 19200 -c--a-w- c:\windows\system32\dllcache\wstcodec.sys
2009-10-18 23:19 . 2008-04-13 22:04 12063 -c--a-w- c:\windows\system32\dllcache\wsiintxx.sys
2009-10-18 23:19 . 2008-04-14 05:42 8192 -c--a-w- c:\windows\system32\dllcache\wshirda.dll
2009-10-18 23:17 . 2001-08-17 14:56 172768 -c--a-w- c:\windows\system32\dllcache\t2r4disp.dll
2009-10-18 23:16 . 2001-08-17 14:56 182272 -c--a-w- c:\windows\system32\dllcache\s3mt3d.dll
2009-10-18 23:15 . 2001-08-17 22:36 123776 -c--a-w- c:\windows\system32\dllcache\nv3.dll
2009-10-18 23:14 . 2001-08-17 13:52 6528 -c--a-w- c:\windows\system32\dllcache\miniqic.sys
2009-10-18 23:13 . 2001-08-17 13:47 13056 -c--a-w- c:\windows\system32\dllcache\inport.sys
2009-10-18 23:12 . 2008-04-14 00:15 59136 -c--a-w- c:\windows\system32\dllcache\gckernel.sys
2009-10-18 23:11 . 2001-08-17 22:36 236060 -c--a-w- c:\windows\system32\dllcache\ditrace.exe
2009-10-18 23:10 . 2001-08-17 13:51 13824 -c--a-w- c:\windows\system32\dllcache\bulltlp3.sys
2009-10-18 23:09 . 2001-08-17 14:56 66048 -c--a-w- c:\windows\system32\dllcache\s3legacy.dll
2009-10-18 23:09 . 2008-04-14 00:54 2145280 -c--a-w- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-10-18 21:46 . 2009-10-20 11:02 -------- d-----w- C:\TEMP
2009-10-18 20:53 . 2009-10-18 20:53 -------- d-----w- c:\documents and settings\Peter\Local Settings\Application Data\PCHealth
2009-10-18 19:49 . 2009-03-30 10:33 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-10-18 19:49 . 2009-02-13 12:29 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2009-10-18 19:49 . 2009-02-13 12:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2009-10-18 19:49 . 2009-10-18 19:49 -------- d-----w- c:\program files\Avira
2009-10-18 19:49 . 2009-10-18 19:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2009-10-18 19:16 . 2001-08-23 14:00 20992 -c--a-w- c:\windows\system32\dllcache\permchk.dll
2009-10-18 19:15 . 2008-04-14 04:42 142848 -c--a-w- c:\windows\system32\dllcache\fxsclnt.exe
2009-10-18 18:20 . 2001-08-23 14:00 13312 -c--a-w- c:\windows\system32\dllcache\irclass.dll
2009-10-18 18:20 . 2001-08-23 14:00 13312 ----a-w- c:\windows\system32\irclass.dll
2009-10-18 18:20 . 2001-08-23 14:00 24661 -c--a-w- c:\windows\system32\dllcache\spxcoins.dll
2009-10-18 18:20 . 2001-08-23 14:00 24661 ----a-w- c:\windows\system32\spxcoins.dll
2009-10-18 18:11 . 2009-10-18 18:11 -------- d-----w- c:\windows\msapps
2009-10-05 21:00 . 2009-10-05 21:00 -------- d-----w- c:\documents and settings\Peter\Application Data\Trusteer
2009-10-05 21:00 . 2009-10-05 21:00 -------- d-----w- c:\documents and settings\All Users\Application Data\Trusteer
2009-10-05 21:00 . 2009-10-05 21:00 -------- d-----w- c:\program files\Trusteer
2009-10-04 17:13 . 2008-10-16 13:06 268648 ----a-w- c:\windows\system32\mucltui.dll
2009-10-04 17:13 . 2008-10-16 13:06 208744 ----a-w- c:\windows\system32\muweb.dll
2009-10-04 12:13 . 2009-10-04 12:13 -------- d-----w- c:\program files\Microsoft Silverlight
2009-10-02 19:18 . 2009-10-01 09:29 195440 ----a-w- c:\windows\system32\MpSigStub.exe
2009-09-28 17:24 . 2009-09-28 17:24 -------- d-----w- c:\program files\Windows Defender
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2009-10-18 19:20 . 2009-10-18 19:20 512 ----atw- c:\windows\~DFBDF0.tmp
2009-10-18 19:20 . 2009-10-18 19:20 16384 ----a-w- c:\windows\~DFBDE6.tmp
2009-10-18 19:20 . 2009-10-18 19:20 512 ----atw- c:\windows\~DFB9F5.tmp
2009-10-18 19:20 . 2009-10-18 19:20 16384 ----a-w- c:\windows\~DFB9EB.tmp
2009-10-18 19:12 . 2007-07-24 15:31 23348 ----a-w- c:\windows\system32\emptyregdb.dat
2009-10-18 18:23 . 2009-10-18 18:23 0 ----a-w- c:\documents and settings\Default User\vgaE7.tmp
2009-10-16 18:33 . 2008-12-15 21:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2009-10-14 21:20 . 2007-07-25 01:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-09-09 01:33 . 2009-08-28 19:37 -------- d-----w- c:\documents and settings\All Users\Application Data\16454214
2009-08-29 22:41 . 2009-08-29 22:41 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-08-24 17:16 . 2009-08-09 21:24 -------- d-----w- c:\documents and settings\All Users\Application Data\DriverCure
2009-08-03 14:07 . 2009-08-03 14:07 403816 ----a-w- c:\windows\system32\OGACheckControl.dll
2009-08-03 14:07 . 2009-08-03 14:07 322928 ----a-w- c:\windows\system32\OGAAddin.dll
2009-08-03 14:07 . 2009-08-03 14:07 230768 ----a-w- c:\windows\system32\OGAEXEC.exe
2009-07-29 10:23 . 2008-11-22 09:19 71544 ----a-w- c:\documents and settings\Peter\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-28 16:33 . 2009-08-25 10:50 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"F5D8071"="c:\program files\Belkin\F5D8071v1\Belkinwcui.exe" [2007-04-19 1630208]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ComPlusSetup]
2008-04-14 00:11 625664 ----a-w- c:\windows\system32\catsrvut.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Find Fast.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Find Fast.lnk
backup=c:\windows\pss\Microsoft Find Fast.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Office Startup.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Office Startup.lnk
backup=c:\windows\pss\Office Startup.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WirelessSelector.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\WirelessSelector.lnk
backup=c:\windows\pss\WirelessSelector.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ose"=3 (0x3)
"odserv"=3 (0x3)
"EapHost"=3 (0x3)
"WmdmPmSN"=3 (0x3)
"SwPrv"=3 (0x3)
"stisvc"=3 (0x3)
"SamSs"=2 (0x2)
"iPod Service"=3 (0x3)
"Bonjour Service"=2 (0x2)
"Apple Mobile Device"=2 (0x2)
"Pml Driver HPZ12"=2 (0x2)
"Microsoft Office Groove Audit Service"=3 (0x3)
"RapportMgmtService"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
R1 RapportKELL;RapportKELL;c:\program files\Trusteer\Rapport\bin\RapportKELL.sys [9/27/2009 11:53 AM 58856]
R1 RapportPG;RapportPG;c:\program files\Trusteer\Rapport\bin\RapportPG.sys [9/27/2009 11:53 AM 333928]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [10/18/2009 7:49 PM 108289]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 6:19 PM 13592]
S4 RapportMgmtService;Rapport Management Service;c:\program files\Trusteer\Rapport\bin\RapportMgmtService.exe [9/27/2009 11:53 AM 967912]
.
Contents of the 'Scheduled Tasks' folder
2009-06-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2009-10-19 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-12-15 15:32]
2009-10-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2008-12-15 08:39]
2009-10-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2008-12-15 08:39]
2009-10-20 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]
2009-10-16 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 14:07]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.co.uk/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mSearch Bar = hxxp://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sb/*
Yahoo! SearchBar Home Page
uInternet Settings,ProxyOverride = 127.0.0.1;*.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Peter\Application Data\Mozilla\Firefox\Profiles\ltt5p6sf.default\
FF - prefs.
js: browser.startup.homepage - hxxp://www.google.co.uk/
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dl l
.
************************************************** ************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
GMER - Rootkit Detector and Remover
Rootkit scan 2009-10-20 11:02
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(1188)
c:\windows\system32\ieframe.dll
.
Completion time: 2009-10-20 11:04
ComboFix-quarantined-files.txt 2009-10-20 11:03
ComboFix2.txt 2009-10-19 00:26
ComboFix3.txt 2009-10-19 00:03
Pre-Run: 109,035,749,376 bytes free
Post-Run: 109,006,053,376 bytes free
172 --- E O F --- 2009-10-16 18:38
and the new HJT....
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:05:53, on 20/10/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Belkin\F5D8071v1\Belkinwcui.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
Google
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
Hotmail, News, Sport, Music, Movies, Money, Cars, Shopping, Windows Live from MSN UK
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
Bing
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
Yahoo! SearchBar Home Page
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
Bing
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
Hotmail, News, Sport, Music, Movies, Money, Cars, Shopping, Windows Live from MSN UK
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = 127.0.0.1;*.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\Office\Office12\GRA8E1~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\s wg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [F5D8071] C:\Program Files\Belkin\F5D8071v1\Belkinwcui.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\Office\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\Office\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\Office\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\Office\Office12\GR99D3~1.DLL
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
--
End of file - 4259 bytes