Ken, you get to be as picky as you want to be. Here is the Combofix log.
Thanks, Doug
ComboFix 08-10-29.06 - Douglas K. Haralson 2008-10-29 8:33:56.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.242 [GMT -8:00]
Running from: C:\Documents and Settings\Douglas K. Haralson\Desktop\Doug's uitilities\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\mdm.exe
C:\WINDOWS\system32\skinboxer43.dll
C:\WINDOWS\wiaservv.log
.
((((((((((((((((((((((((( Files Created from 2008-09-28 to 2008-10-29 )))))))))))))))))))))))))))))))
.
2008-10-28 13:47 . 2008-10-28 13:47 <DIR> d-------- C:\Documents and Settings\Douglas K. Haralson\Application Data\Malwarebytes
2008-10-28 13:47 . 2008-10-28 13:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-28 13:47 . 2008-10-22 16:10 38,496 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-28 13:47 . 2008-10-22 16:10 15,504 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-10-28 13:27 . 2008-10-28 13:27 <DIR> d-------- C:\_OTMoveIt
2008-10-27 21:51 . 2008-10-27 21:51 <DIR> d-------- C:\Program Files\Trend Micro
2008-10-27 15:21 . 2008-10-27 15:21 <DIR> d-------- C:\Program Files\TeaTimer (Spybot - Search & Destroy)
2008-10-27 15:21 . 2008-10-27 15:21 <DIR> d-------- C:\Program Files\SDHelper (Spybot - Search & Destroy)
2008-10-27 14:55 . 2008-10-27 15:21 <DIR> d-------- C:\WINDOWS\system32\CatRoot_bak
2008-10-27 14:48 . 2008-10-27 14:48 <DIR> d-------- C:\Documents and Settings\Douglas K. Haralson\Application Data\ESET
2008-10-27 13:25 . 2008-10-27 14:55 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-10-27 10:28 . 2008-10-27 10:28 <DIR> d-------- C:\WINDOWS\system32\scripting
2008-10-27 10:27 . 2008-10-27 10:27 <DIR> d-------- C:\WINDOWS\l2schemas
2008-10-25 16:47 . 2008-10-25 16:47 <DIR> d-------- C:\Documents and Settings\Ian\Application Data\ESET
2008-10-25 16:44 . 2008-10-25 16:44 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ESET
2008-10-25 15:57 . 2008-10-25 15:57 164 --a------ C:\WINDOWS\system32\TDSSmtve.dat
2008-10-04 20:35 . 2008-10-04 20:35 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Age of Empires 3 XPack Trial
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-28 03:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-10-28 00:30 --------- d-----w C:\Documents and Settings\All Users\Application Data\AVG7
2008-10-27 22:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-10-27 21:17 --------- d-----w C:\Documents and Settings\Douglas K. Haralson\Application Data\AVG7
2008-10-24 18:10 30 ----a-w C:\Documents and Settings\Douglas K. Haralson\jagex_runescape_preferences.dat
2008-10-24 04:00 --------- d-----w C:\Documents and Settings\Douglas K. Haralson\Application Data\U3
2008-10-19 23:19 30 ----a-w C:\Documents and Settings\Ian\jagex_runescape_preferences.dat
2008-10-17 00:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\Retrospect
2008-10-16 01:22 30 ----a-w C:\Documents and Settings\Connor\jagex_runescape_preferences.dat
2008-10-15 16:57 332,800 ----a-w C:\WINDOWS\system32\netapi32(4).dll
2008-10-15 16:57 332,800 ----a-w C:\WINDOWS\system32\netapi32(3).dll
2008-10-05 04:33 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-10-05 04:26 --------- d-----w C:\Program Files\Microsoft Games
2008-09-15 11:57 1,846,016 ----a-w C:\WINDOWS\system32\win32k.sys
2008-08-28 10:04 333,056 ----a-w C:\WINDOWS\system32\drivers\srv.sys
2008-08-25 22:40 24 ----a-w C:\Documents and Settings\Logan\jagex_runescape_preferences.dat
2008-08-20 05:33 667,648 ----a-w C:\WINDOWS\system32\wininet.dll
2008-08-20 05:33 667,648 ----a-w C:\WINDOWS\system32\wininet(6).dll
2008-08-20 05:33 667,648 ----a-w C:\WINDOWS\system32\wininet(5).dll
2008-08-20 05:33 667,648 ----a-w C:\WINDOWS\system32\wininet(4).dll
2008-08-20 05:33 667,648 ----a-w C:\WINDOWS\system32\wininet(3).dll
2008-08-20 05:33 619,008 ----a-w C:\WINDOWS\system32\urlmon(5).dll
2008-08-20 05:33 619,008 ----a-w C:\WINDOWS\system32\urlmon(4).dll
2008-08-20 05:33 619,008 ----a-w C:\WINDOWS\system32\urlmon(3).dll
2008-08-20 05:33 474,112 ----a-w C:\WINDOWS\system32\shlwapi(3).dll
2008-08-20 05:33 146,432 ----a-w C:\WINDOWS\system32\msrating(2).dll
2008-08-20 05:33 1,024,000 ----a-w C:\WINDOWS\system32\browseui(2).dll
2008-08-14 09:58 2,136,064 ----a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-08-14 09:22 2,015,744 ----a-w C:\WINDOWS\system32\ntkrnlpa.exe
2006-05-31 23:49 603 ----a-w C:\Documents and Settings\Douglas K. Haralson\.jadeFileMgr.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-05 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-12-10 7311360]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-02-28 315392]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2003-03-11 155648]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2003-03-11 114688]
"ezShieldProtector for Px"="C:\WINDOWS\System32\ezSP_Px.exe" [2002-08-20 40960]
"ZTgServerSwitch"="c:\program files\support.com\client\lserver\server.vbs" [2002-07-14 11406]
"StorageGuard"="C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" [2002-06-18 155648]
"VAIO Recovery"="C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe" [2003-04-19 28672]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2008-10-16 590848]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 132496]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-01-23 155648]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2005-12-10 86016]
"HPHUPD08"="C:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-01 49152]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 49152]
"Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2002-07-24 28672]
"nwiz"="nwiz.exe" [2005-12-10 C:\WINDOWS\system32\nwiz.exe]
"ATIModeChange"="Ati2mdxx.exe" [2001-09-04 C:\WINDOWS\system32\Ati2mdxx.exe]
"AGRSMMSG"="AGRSMMSG.exe" [2003-02-14 C:\WINDOWS\AGRSMMSG.exe]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-11 282624]
HP Image Zone Fast Start.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2005-05-12 73728]
Microsoft Office.lnk - C:\My Program Files\Microsoft Office\Office\OSA9.EXE [2002-06-04 65588]
WinZip Quick Pick.lnk - D:\My Program Files\WinZip\WZQKPICK.EXE [2006-11-06 122880]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.mjpg"= mcmjpg32.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Billminder.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Billminder.lnk
backup=C:\WINDOWS\pss\Billminder.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Scheduled Updates.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk
backup=C:\WINDOWS\pss\Quicken Scheduled Updates.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Startup.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Startup.lnk
backup=C:\WINDOWS\pss\Quicken Startup.lnkCommon Startup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\WINDOWS\\system32\\dplaysvr.exe"=
"C:\\Program Files\\support.com\\client\\bin\\tgcmd.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\Dynamix\\Tribes2\\GameData\\Tribes2.exe"=
"C:\\Program Files\\QuickTime\\QuickTimePlayer.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe"=
"D:\\My Program Files\\Xfire\\Xfire.exe"=
"C:\\Program Files\\Microsoft Games\\Age of Empires II The Conquerors Expansion Trial\\age2_x1t.exe"=
"C:\\Program Files\\Microsoft Games\\Age of Empires III\\age3.exe"=
"C:\\Program Files\\Microsoft Games\\Age of Empires Trial\\empires.exe"=
"C:\\Program Files\\Microsoft Games\\Age of Empires III\\age3y.exe"=
"C:\\Unreal Anthology\\UnrealTournament\\System\\UnrealTournament.exe"=
"D:\\Starcraft\\StarCraft.exe"=
"C:\\Program Files\\Microsoft Games\\Age of Empires II Trial\\EMPIRES2.EXE"=
"C:\\Documents and Settings\\Douglas K. Haralson\\Local Settings\\Application Data\\Abacast\\Abaclient.exe"=
"C:\\Unreal Anthology\\UT2004\\System\\UT2004.exe"=
"C:\\Program Files\\Microsoft Games\\Age of Empires III - The WarChiefs Trial\\age3x.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"2485:UDP"= 2485:UDP:Windows Media Format SDK (iexplore.exe)
"2484:UDP"= 2484:UDP:Windows Media Format SDK (iexplore.exe)
"2486:UDP"= 2486:UDP:Windows Media Format SDK (iexplore.exe)
S3 ldiskl;ldiskl;C:\DOCUME~1\DOUGLA~1.HAR\LOCALS~1\Temp\ldiskl.sys [ ]
S3 OlCamudp;OLYMPUS Digital Camera;C:\WINDOWS\system32\Drivers\olcamudp.sys [2000-02-08 10379]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
\Shell\AutoRun\command - H:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{70d7a282-93ad-11da-b6f3-000c6e93aa8f}]
\Shell\AutoRun\command - G:\JDSecure\Windows\JDSecure31.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{70d7a2a7-93ad-11da-b6f3-000c6e93aa8f}]
\Shell\AutoRun\command - H:\JDSecure\Windows\JDSecure31.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a31e39be-0df1-11dc-b77f-000c6e93aa8f}]
\Shell\AutoRun\command - H:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f6a4bc41-7f76-11d9-b682-000c6e93aa8f}]
\Shell\AutoRun\command - G:\JDSecure\Windows\JDSecure31.exe
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder
2008-10-28 C:\WINDOWS\Tasks\MP Scheduled Scan.job
- C:\Program Files\Windows Defender\MpCmdRun.exe [2006-04-03 18:12]
2003-12-20 C:\WINDOWS\Tasks\Registration reminder 1.job
- C:\WINDOWS\System32\OOBE\oobebaln.exe [2004-08-03 23:56]
2003-12-20 C:\WINDOWS\Tasks\Registration reminder 2.job
- C:\WINDOWS\System32\OOBE\oobebaln.exe [2004-08-03 23:56]
2003-12-20 C:\WINDOWS\Tasks\Registration reminder 3.job
- C:\WINDOWS\System32\OOBE\oobebaln.exe [2004-08-03 23:56]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-POINTER - point32.exe
MSConfigStartUp-Mozilla Quick Launch - C:\Program Files\Netscape\Netscape\Netscp.exe
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Douglas K. Haralson\Application Data\Mozilla\Firefox\Profiles\msskhj5p.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://en-us.start.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-US

fficial
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-10-29 08:36:23
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\DOCUME~1\DOUGLA~1.HAR\LOCALS~1\Temp\RGI43.tmp 7075 bytes
scan completed successfully
hidden files: 1
**************************************************************************
.
Completion time: 2008-10-29 8:40:05
ComboFix-quarantined-files.txt 2008-10-29 16:39:18
Pre-Run: 14,309,031,936 bytes free
Post-Run: 14,661,505,024 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
192 --- E O F --- 2008-10-28 11:02:25