this is the HiJackThis log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:14:50, on 01/07/2008
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 SP4 (5.00.2920.0000)
Boot mode: Normal
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\Program Files\WatchGuard\Mobile User VPN\IreIKE.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\msdtc.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\WatchGuard\Mobile User VPN\IPSecMon.exe
C:\WINNT\System32\llssrv.exe
C:\Program Files\Tiny Personal Firewall\persfw.exe
C:\WINNT\system32\regsvc.exe
C:\Program Files\UltraVNC\WinVNC.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\UltraVNC\WinVNC.exe
C:\WINNT\system32\inetsrv\inetinfo.exe
C:\WINNT\system32\Dfssvc.exe
C:\WINNT\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
D:\apache\ApacheOld\Aude.exe
D:\apache\ApacheOld\finedata.exe
D:\apache\ApacheOld\finedata.exe
D:\apache\ApacheOld\Aude.exe
C:\WINNT\System32\SCardSvr.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\mdm.exe
C:\APPS\DocElite\docelite.exe
C:\APPS\WEBELITE-WEB01\WebElite.EXE
C:\APPS\DEPOTWATCH\DepotWatch.EXE
C:\APPS\WEBELITE-WEB04\WebElite.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O4 - HKLM\..\Run: [AVG7_CC] "C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" /STARTUP
O4 - HKUS\.DEFAULT\..\Run: [internat.exe] internat.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Startup: Aude.lnk = D:\apache\ApacheOld\Aude.exe
O4 - Startup: depotwatch.lnk = C:\APPS\depotwatch\depotwatch.exe
O4 - Startup: docelite.exe.lnk = C:\APPS\DocElite\docelite.exe
O4 - Startup: finedata.lnk = D:\apache\ApacheOld\finedata.exe
O4 - Startup: web01.lnk = C:\APPS\WebElite-web01\webelite.exe
O4 - Startup: web04.lnk = C:\APPS\WebElite-web04\webelite.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{587F2C33-089B-41FA-AD18-1C3AD1434429}: NameServer = 80.84.160.226,80.84.160.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{587F2C33-089B-41FA-AD18-1C3AD1434429}: NameServer = 80.84.160.226,80.84.160.1
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Tiny Personal Firewall (PersFw) - Tiny Software - C:\Program Files\Tiny Personal Firewall\persfw.exe
O23 - Service: uvnc_service - UltraVNC - C:\Program Files\UltraVNC\WinVNC.exe
--
End of file - 3117 bytes
Regards
Griff
Keep [Smile]ing