You were correct about the snapshot section:
here is the comboFix file with the section removed:
ComboFix 07-11-02.3 - MIA-KITTY 2007-11-04 8:17:12.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.590 [GMT -8:00]
Running from: C:\Documents and Settings\MIA-KITTY\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\MIA-KITTY\Desktop\CFScript.txt
FILE::
C:\WINDOWS\b149.exe.bin
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\{000030F4-0000-0000-3F72-D2B213869782}
C:\{000030F4-0000-0000-3F72-D2B213869782}\DATA.CAB
C:\{000030F4-0000-0000-3F72-D2B213869782}\Manifest.ini
C:\{000030F4-0000-0000-3F72-D2B213869782}\Manifest.qrm
C:\WINDOWS\b149.exe.bin
.
((((((((((((((((((((((((( Files Created from 2007-10-04 to 2007-11-04 )))))))))))))))))))))))))))))))
.
2007-11-03 17:55 <DIR> d-------- C:\Program Files\ToniArts
2007-11-03 17:53 <DIR> d-------- C:\Program Files\Virtual Mechanics
2007-11-03 17:53 <DIR> d-------- C:\Program Files\Common Files\Wintertree
2007-11-03 17:53 155,648 --a------ C:\WINDOWS\system32\SSCE5232.dll
2007-11-03 12:27 <DIR> d-------- C:\Program Files\MSXML 6.0
2007-11-02 18:37 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-11-02 14:30 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-11-02 14:29 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2007-11-02 14:29 <DIR> d-------- C:\Documents and Settings\MIA-KITTY\Application Data\SUPERAntiSpyware.com
2007-11-02 13:01 <DIR> d-------- C:\VundoFix Backups
2007-11-01 23:47 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-11-01 23:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-11-01 16:58 <DIR> d-------- C:\TEMPCRAP
2007-11-01 10:03 <DIR> d-------- C:\Program Files\Windows Live Safety Center
2007-10-31 21:10 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-10-31 21:00 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-10-31 09:41 4,476 --a------ C:\WINDOWS\system32\tmp.reg
2007-10-28 13:17 <DIR> d-------- C:\Program Files\Chami
2007-10-24 20:23 <DIR> d-------- C:\Program Files\Evrsoft First Page 2006
2007-10-23 22:52 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\espionServerData
2007-10-23 22:31 109,568 --a------ C:\WINDOWS\system32\pxinsi64.exe
2007-10-23 22:31 108,544 --a------ C:\WINDOWS\system32\pxcpyi64.exe
2007-10-23 21:57 <DIR> d-------- C:\Program Files\MagicISO
2007-10-23 19:30 <DIR> d-------- C:\Program Files\uTorrent
2007-10-23 19:30 <DIR> d-------- C:\Documents and Settings\MIA-KITTY\Application Data\uTorrent
2007-10-23 17:42 <DIR> d-------- C:\Documents and Settings\MIA-KITTY\Application Data\Shareaza
2007-10-19 12:16 2,109,976 --a------ C:\WINDOWS\system32\drivers\Lvckap.sys
2007-10-17 06:46 <DIR> d-------- C:\Documents and Settings\MIA-KITTY\Application Data\Nero
2007-10-17 06:28 <DIR> d-------- C:\Program Files\Nero
2007-10-17 06:28 <DIR> d-------- C:\Program Files\Common Files\Nero
2007-10-17 06:28 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Nero
2007-10-14 15:35 <DIR> d-------- C:\WINDOWS\Intuit
2007-10-12 00:57 195,096 --a------ C:\WINDOWS\system32\lvci1150.dll
2007-10-12 00:56 1,279,000 --a------ C:\WINDOWS\system32\drivers\LV302V32.SYS
2007-10-11 17:59 2,142,488 --a------ C:\WINDOWS\system32\drivers\LVMVdrv.sys
2007-10-11 17:59 25,624 --a------ C:\WINDOWS\system32\drivers\LVPr2Mon.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-04 08:23 --------- d-----w C:\Documents and Settings\MIA-KITTY\Application Data\SSH
2007-11-04 07:00 --------- d-----w C:\Program Files\DynDNS Updater
2007-11-04 01:55 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-11-03 21:55 --------- d-----w C:\Program Files\Logitech
2007-11-03 21:55 --------- d-----w C:\Program Files\Common Files\LogiShrd
2007-11-03 21:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\Logishrd
2007-11-03 20:00 --------- d-----w C:\Program Files\SecureCRT
2007-11-03 03:30 --------- d-----w C:\Program Files\Norton AntiVirus
2007-11-02 20:48 --------- d-----w C:\Program Files\Trend Micro
2007-11-01 05:12 --------- d-----w C:\Program Files\Lavasoft
2007-11-01 05:12 --------- d-----w C:\Documents and Settings\MIA-KITTY\Application Data\Lavasoft
2007-10-31 18:56 --------- d-----w C:\Documents and Settings\MIA-KITTY\Application Data\Vidalia
2007-10-24 06:38 --------- d-----w C:\Program Files\Common Files\Adobe
2007-10-24 01:42 --------- d-----w C:\Program Files\Shareaza
2007-10-23 18:49 --------- d-----w C:\Program Files\Kazaa Lite
2007-10-23 16:14 --------- d-----w C:\Program Files\Common Files\HP
2007-10-23 16:09 --------- d-----w C:\Program Files\NCH Swift Sound
2007-10-23 15:56 --------- d-----w C:\Program Files\Canon
2007-10-20 16:47 --------- d-----w C:\Program Files\HP
2007-10-17 14:34 106,592 ----a-w C:\Documents and Settings\MIA-KITTY\Application Data\GDIPFONTCACHEV1.DAT
2007-10-17 14:04 --------- d-----w C:\Program Files\Ahead
2007-10-15 00:02 --------- d-----w C:\Program Files\Intuit
2007-10-14 23:49 --------- d-----w C:\Program Files\Common Files\Intuit
2007-10-14 23:45 --------- d-----w C:\Program Files\Common Files\AnswerWorks 4.0
2007-10-13 16:08 --------- d-----w C:\Program Files\Java
2007-10-12 09:00 490,008 ----a-w C:\WINDOWS\system32\LVUI2.dll
2007-10-12 09:00 465,432 ----a-w C:\WINDOWS\system32\LVUI2RC.dll
2007-10-12 09:00 41,752 ----a-w C:\WINDOWS\system32\drivers\LVUSBSta.sys
2007-10-12 08:57 416,280 ----a-w C:\WINDOWS\system32\lvcodec2.dll
2007-10-12 08:56 13,848 ----a-w C:\WINDOWS\system32\drivers\lv302af.sys
2007-10-12 08:18 21,138 ----a-w C:\WINDOWS\system32\Repository.reg
2007-09-04 00:06 --------- d-----w C:\Program Files\Print Workshop 2007 LE
2007-08-21 06:15 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-08-04 17:40 972,072 ----a-w C:\WINDOWS\UNRecode.exe
2007-08-04 17:10 95,600 ----a-w C:\WINDOWS\system32\NeroCo.dll
.
((((((((((((((((((((((((((((( snapshot@2007-11-02_20.15.33.23 )))))))))))))))))))))))))))))))))))))))))
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SiSUSBRG"="C:\WINDOWS\SiSUSBrg.exe" [2002-04-26 17:17]
"LTSMMSG"="LTSMMSG.exe" [2002-07-20 08:22 C:\WINDOWS\LTSMMSG.exe]
"ezShieldProtector for Px"="C:\WINDOWS\System32\ezSP_Px.exe" [2002-07-03 16:17]
"AGRSMMSG"="AGRSMMSG.exe" [2003-02-14 11:59 C:\WINDOWS\AGRSMMSG.exe]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2005-12-21 12:54]
"NAV CfgWiz"="C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe" [2003-08-15 10:24]
"SiS Tray"="C:\WINDOWS\System32\sistray.EXE" [2003-06-26 10:35]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11]
"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2004-08-04 04:00]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 02:06]
"NeroFilterCheck"="C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 14:57]
"LogitechCommunicationsManager"="C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-10-25 15:33]
"LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam\Quickcam.exe" [2007-10-25 15:37]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DynDNS Updater"="C:\Program Files\DynDNS Updater\DynDNS.exe" [2006-09-17 09:32]
"Vidalia"="C:\Program Files\Vidalia\vidalia.exe" [2006-07-07 11:58]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 04:00]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 13:06]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - C:\Program Files\adobe\acrobat 5.0\Distillr\AcroTray.exe [2003-01-21 00:35:28]
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2002-11-22 04:55:24]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04]
Privoxy.lnk - C:\Program Files\Privoxy\privoxy.exe [2004-03-05 02:47:30]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PCANotify]
PCANotify.dll 2002-02-15 09:51 24638 C:\WINDOWS\system32\PCANotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Cisco Systems VPN Client.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Cisco Systems VPN Client.lnk
backup=C:\WINDOWS\pss\Cisco Systems VPN Client.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
backup=C:\WINDOWS\pss\QuickBooks Update Agent.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
"C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
"C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wscsvc"=2 (0x2)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Symantec NetDriver Monitor"=C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
"SiS KHooker"=C:\WINDOWS\System32\khooker.exe
"NvCplDaemon"=RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
"Advanced Tools Check"=C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
R2 FLEXlm License Manager;FLEXlm License Manager;c:\ads2002c\licenses\bin\lmgrd.exe
R2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3;C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
R2 SMTPSVC;Simple Mail Transfer Protocol (SMTP);C:\WINDOWS\System32\inetsrv\inetinfo.exe
R3 NPDriver;Norton Unerase Protection Driver;\??\C:\WINDOWS\System32\Drivers\NPDRIVER.SYS
R3 pctvvbi;PCTVVBI;C:\WINDOWS\system32\DRIVERS\pctvvbi.sys
R3 WBMS;Winbond Memory Stick Storage (MS) Device Driver;C:\WINDOWS\system32\Drivers\WBMS.SYS
R3 WDM_YAMAHAAC97;YAMAHA AC-XG Audio Device;C:\WINDOWS\system32\drivers\yacxgc.sys
S2 BT848;FusionHDTV, WDM Video Capture;C:\WINDOWS\system32\drivers\ZuluVcap.sys
S2 BT878;FusionHDTV, BDA Receiver Component (ATSC-A);C:\WINDOWS\system32\drivers\ZuluTcap.sys
S2 sshd;CYGWIN sshd;C:\cygwin\bin\cygrunsrv.exe
S3 LucentSoftModem;Lucent Technologies Soft Modem;C:\WINDOWS\system32\DRIVERS\LTSM.sys
S3 soma;SOMA Service;C:\WINDOWS\system32\DRIVERS\soma.sys
S3 SONYWBMS;Sony Memory Stick controller(WB);C:\WINDOWS\system32\DRIVERS\SonyWBMS.SYS
S3 SQLWriter;SQL Server VSS Writer;"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
S4 msvsmon80;Visual Studio 2005 Remote Debugger;"C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe" /service msvsmon80
.
Contents of the 'Scheduled Tasks' folder
"2003-07-08 07:57:25 C:\WINDOWS\Tasks\HotFax MessageCenter.job"
- C:\PROGRA~1\HOTFAX~1\HFMC.exe
"2007-10-31 17:45:15 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer - MIA-KITTY.job"
"2007-11-03 03:04:07 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer.job"
- C:\PROGRA~1\NORTON~1\Navw32.exe
.
**************************************************************************
catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-11-04 08:34:50
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
Completion time: 2007-11-04 8:37:13
C:\ComboFix2.txt ... 2007-11-02 19:52
.
--- E O F ---