Ok i did the AVG remover and then re ran Combofix, it looks like AVG is still there though? The remover seemed to run fine.
Here is the Combofix log:
ComboFix 11-04-23.01 - User 23/04/2011 23:39:25.5.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1546 [GMT 1:00]
Running from: C:\Documents and Settings\User\Desktop\ComboFix.exe
AV: AntiVir Desktop *Disabled/Outdated* {AD166499-45F9-482A-A743-FDD3350758C7}
AV: AVG Anti-Virus Free Edition 2011 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_JATMLANO
-------\Service_jatmlano
((((((((((((((((((((((((( Files Created from 2011-03-23 to 2011-04-23 )))))))))))))))))))))))))))))))
2011-04-23 22:00:58 . 2011-04-23 22:00:58 -------- d-----w- C:\Program Files\khwsfwle
2011-04-23 12:22:34 . 2011-04-23 13:15:05 -------- d---a-w- C:\Documents and Settings\All Users\Application Data\TEMP
2011-04-23 12:20:57 . 2011-04-23 13:14:53 -------- d-----w- C:\Documents and Settings\All Users\Application Data\PC Tools
2011-04-23 02:56:20 . 2011-04-23 02:56:20 -------- d-----w- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
2011-04-23 02:53:29 . 2011-04-23 02:54:38 -------- dc-h--w- C:\WINDOWS\ie8
2011-04-23 02:53:18 . 2011-04-23 02:53:18 -------- d-----w- C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
2011-04-23 02:53:13 . 2011-04-23 02:57:35 -------- d-----w- C:\Documents and Settings\User\Local Settings\Application Data\Google
2011-04-23 02:52:47 . 2011-04-23 02:53:13 -------- d-----w- C:\Program Files\Google
2011-04-23 00:58:53 . 2011-04-23 22:23:55 -------- d-----w- C:\WINDOWS\system32\NtmsData
2011-04-23 00:57:01 . 2011-04-23 00:57:01 -------- d-----w- C:\Documents and Settings\User\Application Data\Avira
2011-04-23 00:55:54 . 2011-03-04 15:11:12 137656 ----a-w- C:\WINDOWS\system32\drivers\avipbb.sys
2011-04-23 00:55:54 . 2011-03-04 13:37:13 61960 ----a-w- C:\WINDOWS\system32\drivers\avgntflt.sys
2011-04-23 00:55:54 . 2010-06-17 13:27:24 45416 ----a-w- C:\WINDOWS\system32\drivers\avgntdd.sys
2011-04-23 00:55:54 . 2010-06-17 13:27:24 22360 ----a-w- C:\WINDOWS\system32\drivers\avgntmgr.sys
2011-04-23 00:55:53 . 2011-04-23 00:55:53 -------- d-----w- C:\Program Files\Avira
2011-04-23 00:55:53 . 2011-04-23 00:55:53 -------- d-----w- C:\Documents and Settings\All Users\Application Data\Avira
2011-04-22 21:30:59 . 2011-04-23 00:48:09 166768 ----a-w- C:\Program Files\Common Files\InstallShield\UpdateService\isuspmmgr.exe
2011-04-22 21:30:59 . 2011-04-23 00:48:09 166768 ----a-w- C:\Program Files\Common Files\InstallShield\UpdateService\agentmgr.exe
2011-04-22 21:23:14 . 2011-04-22 21:23:14 -------- d-----w- C:\Program Files\VS Revo Group
2011-04-22 21:18:02 . 2011-04-23 22:37:33 -------- d-----w- C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
2011-04-15 17:17:32 . 2011-04-15 17:17:32 -------- d-----w- C:\Documents and Settings\User\Local Settings\Application Data\Trusteer
2011-04-14 22:04:15 . 2011-04-14 22:04:16 -------- d-----w- C:\Program Files\Spotify
2011-04-06 11:23:51 . 2011-04-06 11:23:51 -------- d-----w- C:\found.000
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2011-03-07 05:33:50 . 2010-10-08 10:55:46 692736 ----a-w- C:\WINDOWS\system32\inetcomm.dll
2011-03-04 06:37:06 . 2006-02-28 12:00:00 420864 ----a-w- C:\WINDOWS\system32\vbscript.dll
2011-03-03 13:21:11 . 2006-02-28 12:00:00 1857920 ----a-w- C:\WINDOWS\system32\win32k.sys
2011-02-22 23:06:29 . 2006-02-28 12:00:00 916480 ----a-w- C:\WINDOWS\system32\wininet.dll
2011-02-22 23:06:29 . 2006-02-28 12:00:00 43520 ----a-w- C:\WINDOWS\system32\licmgr10.dll
2011-02-22 23:06:29 . 2006-02-28 12:00:00 1469440 ----a-w- C:\WINDOWS\system32\inetcpl.cpl
2011-02-22 11:41:59 . 2006-02-28 12:00:00 385024 ----a-w- C:\WINDOWS\system32\html.iec
2011-02-17 13:18:24 . 2006-02-28 12:00:00 455936 ----a-w- C:\WINDOWS\system32\drivers\mrxsmb.sys
2011-02-17 13:18:03 . 2006-02-28 12:00:00 357888 ----a-w- C:\WINDOWS\system32\drivers\srv.sys
2011-02-17 12:32:12 . 2010-10-08 11:31:35 5120 ----a-w- C:\WINDOWS\system32\xpsp4res.dll
2011-02-15 12:56:39 . 2006-02-28 12:00:00 290432 ----a-w- C:\WINDOWS\system32\atmfd.dll
2011-02-09 13:53:52 . 2006-02-28 12:00:00 270848 ----a-w- C:\WINDOWS\system32\sbe.dll
2011-02-09 13:53:52 . 2006-02-28 12:00:00 186880 ----a-w- C:\WINDOWS\system32\encdec.dll
2011-02-08 13:33:55 . 2006-02-28 12:00:00 978944 ----a-w- C:\WINDOWS\system32\mfc42.dll
2011-02-08 13:33:55 . 2006-02-28 12:00:00 974848 ----a-w- C:\WINDOWS\system32\mfc42u.dll
2011-02-02 07:58:35 . 2010-10-08 10:52:49 2067456 ----a-w- C:\WINDOWS\system32\mstscax.dll
2011-01-27 11:57:06 . 2010-10-08 10:52:49 677888 ----a-w- C:\WINDOWS\system32\mstsc.exe
((((((((((((((((((((((((((((( SnapShot@2011-04-23_18.25.46 )))))))))))))))))))))))))))))))))))))))))
+ 2011-04-23 22:44:50 . 2011-04-23 22:44:50 16384 C:\WINDOWS\Temp\Perflib_Perfdata_72c.dat
+ 2011-04-23 22:04:26 . 2011-04-23 22:04:26 16384 C:\WINDOWS\Temp\Perflib_Perfdata_5a0.dat
+ 2010-10-08 10:56:04 . 2010-06-18 13:36:12 3558912 C:\WINDOWS\system32\dllcache\moviemk.exe
- 2010-10-08 10:56:04 . 2008-04-14 04:42:28 3558912 C:\WINDOWS\system32\dllcache\moviemk.exe
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="C:\Program Files\Steam\steam.exe" [2011-01-12 20:46:45 1242448]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-04-23 02:53:11 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2010-07-09 15:24:16 13923432]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [BU]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 15:30:30 81920]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 15:45:14 35736]
"Adobe ARM"="C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-10 12:49:34 932288]
"NPSStartup"="" [BU]
"DivXUpdate"="C:\Program Files\DivX\DivX Update\DivXUpdate.exe" [2011-03-21 21:10:00 1230704]
"avgnt"="C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" [2011-03-04 13:36:51 281768]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 04:42:18 15360]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [N/A]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll" [BU]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="C:\WINDOWS\system32\userinit.exe,,C:\Program Files\khwsfwle\skofparu.exe"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
backup=C:\WINDOWS\pss\Windows Search.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^User^Start Menu^Programs^Startup^OpenOffice.org 3.2.lnk]
path=C:\Documents and Settings\User\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk
backup=C:\WINDOWS\pss\OpenOffice.org 3.2.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 04:42:18 15360 ----a-w- C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
2005-12-20 10:27:57 155648 ----a-w- C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2010-07-09 15:24:16 13923432 ----a-w- C:\WINDOWS\system32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2010-07-09 15:24:18 110696 ----a-w- C:\WINDOWS\system32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2010-07-07 22:52:40 1753192 ----a-w- C:\Program Files\NVIDIA Corporation\nView\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2006-12-19 10:12:24 16062464 ----a-w- C:\WINDOWS\RTHDCPL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
2006-05-16 17:04:26 2879488 ----a-w- C:\WINDOWS\SkyTel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-02-18 10:43:18 248040 ----a-w- C:\Program Files\Common Files\Java\Java Update\jusched.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"C:\\Program Files\\Steam\\Steam.exe"=
"C:\\Program Files\\Sports Interactive\\Football Manager 2010\\fm.exe"=
"C:\\Documents and Settings\\User\\My Documents\\Age Of Empires II\\Age Of Empires II The Conquerors\\age2_x1.exe"=
"C:\\Program Files\\Steam\\SteamApps\\common\\football manager 2011\\fm.exe"=
"C:\\Program Files\\Spotify\\spotify.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
R0 RapportKELL;RapportKELL;C:\WINDOWS\system32\drivers\RapportKELL.sys [03/10/2010 23:43:44 59240]
R1 RapportCerberus_25973;RapportCerberus_25973;C:\Documents and Settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportCerberus\25973\RapportCerberus_25973.sys [13/04/2011 12:17:06 57144]
R1 RapportPG;RapportPG;C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys [03/10/2010 23:43:44 169320]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;C:\Program Files\Avira\AntiVir Desktop\sched.exe [23/04/2011 01:55:54 135336]
R2 FsUsbExService;FsUsbExService;C:\WINDOWS\system32\FsUsbExService.Exe [27/01/2011 19:03:01 233472]
R3 FsUsbExDisk;FsUsbExDisk;C:\WINDOWS\system32\FsUsbExDisk.Sys [27/01/2011 19:03:01 36608]
S2 gupdate;Google Update Service (gupdate);C:\Program Files\Google\Update\GoogleUpdate.exe [23/04/2011 03:53:14 135664]
S3 W35UND;IS89C35 802.11bg WLAN USB Adapter Driver;C:\WINDOWS\system32\drivers\W35UND.SYS [08/10/2010 12:18:03 117632]
S4 AVGIDSShim;AVGIDSShim;C:\WINDOWS\system32\DRIVERS\AVGIDSShim.Sys --> C:\WINDOWS\system32\DRIVERS\AVGIDSShim.Sys [?]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - FSUSBEXDISK
Contents of the 'Scheduled Tasks' folder
2011-04-23 C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
- C:\Program Files\Google\Update\GoogleUpdate.exe [2011-04-23 02:53:14 . 2011-04-23 02:53:12]
2011-04-23 C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
- C:\Program Files\Google\Update\GoogleUpdate.exe [2011-04-23 02:53:14 . 2011-04-23 02:53:12]
------- Supplementary Scan -------
uStart Page = hxxp://www.google.co.uk/
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-04-23 23:45:35
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...