Thanks.
I removed the combofix and the C:\combofix folder and started fresh with a new dled version.
here's the report:
ComboFix 07-12-15.5 - intelmic 2007-12-15 16:58:39.5 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.493 [GMT -5:00]
Running from: C:\Documents and Settings\intelmic\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\Documents and Settings\intelmic\Application Data\macromedia\Flash Player\#SharedObjects\4XH8DWPG\iforex.com
C:\Documents and Settings\intelmic\Application Data\macromedia\Flash Player\#SharedObjects\4XH8DWPG\iforex.com\Emerp\Events\flash_object.swf\user_data.sol
C:\Documents and Settings\intelmic\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#iforex.com
C:\Documents and Settings\intelmic\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#iforex.com\settings.sol
C:\Program Files\WinBudget
C:\Program Files\WinBudget\bin\matrix.dat
C:\Program Files\WinBudget\bin\matrix.dll
C:\Program Files\WinBudget\bin\matrix.dll.1192461388.old
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\Temp\bkR11
C:\Temp\bkR11\ftCa.log
C:\WINDOWS\msettings.ini
C:\WINDOWS\system32\awtsr.dll
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\rstwa.ini
C:\WINDOWS\system32\rstwa.ini2
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_DOMAINSERVICE
((((((((((((((((((((((((( Files Created from 2007-11-15 to 2007-12-15 )))))))))))))))))))))))))))))))
.
2007-12-14 21:24 . 2007-12-14 21:24 <DIR> d-------- C:\Program Files\Trend Micro
2007-12-14 18:25 . 2007-12-14 18:25 <DIR> d-------- C:\Program Files\Kaspersky Lab
2007-12-14 18:23 . 2007-12-14 18:23 <DIR> d-------- C:\KAV
2007-12-14 15:27 . 2007-12-14 15:27 250 --a------ C:\WINDOWS\gmer.ini
2007-12-14 15:03 . 2007-12-14 15:03 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-12-14 15:03 . 2007-12-15 10:53 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-12-14 13:14 . 2007-12-14 13:14 <DIR> d-------- C:\VundoFix Backups
2007-12-14 11:56 . 2007-12-14 12:03 952,263 --ahs---- C:\WINDOWS\system32\orkcvkje.ini
2007-12-12 11:46 . 2007-12-12 11:46 <DIR> d-------- C:\WINDOWS\system32\su2
2007-12-12 11:46 . 2007-12-14 20:36 <DIR> d-------- C:\WINDOWS\system32\pi3
2007-12-12 11:45 . 2007-12-12 11:46 <DIR> d-------- C:\WINDOWS\system32\eu1
2007-12-12 11:45 . 2007-12-12 11:45 <DIR> d-------- C:\WINDOWS\system32\daSgo01
2007-12-12 11:45 . 2007-12-15 11:34 <DIR> d-------- C:\Temp
2007-12-06 21:07 . 2007-12-09 22:58 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2007-12-06 21:07 . 2007-12-06 21:07 1,409 --a------ C:\WINDOWS\QTFont.for
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-14 18:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-14 09:36 --------- d-----w C:\Documents and Settings\intelmic\Application Data\uTorrent
2007-12-12 18:10 --------- d-----w C:\Program Files\Avast4
2007-12-12 17:13 --------- d-----w C:\Program Files\Winamp
2007-12-10 03:59 --------- d-----w C:\Documents and Settings\intelmic\Application Data\LimeWire
2007-12-07 17:44 --------- d-----w C:\Documents and Settings\intelmic\Application Data\mIRC
2007-12-07 17:42 --------- d-----w C:\Program Files\mIRC
2007-12-04 14:56 93,264 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
2007-12-04 14:55 94,544 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
2007-12-04 14:53 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
2007-12-04 14:51 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
2007-12-04 14:49 26,624 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
2007-12-04 13:04 837,496 ----a-w C:\WINDOWS\system32\aswBoot.exe
2007-12-04 12:54 95,608 ----a-w C:\WINDOWS\system32\AvastSS.scr
2007-11-12 00:09 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-11-12 00:06 --------- d-----w C:\Program Files\Microsoft Visual Studio 8
2007-11-11 23:49 --------- d-----w C:\Program Files\MSN Messenger
2007-11-06 12:49 --------- d-----w C:\Program Files\XoftSpySE
2007-10-25 23:15 --------- d-----w C:\Program Files\Jasc Software Inc
2007-10-20 16:49 --------- d-----w C:\Program Files\PDF Merger
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
----a-w 1,388,544 2004-06-30 17:33:04 C:\Program Files\Analog Devices\SoundMAX\bak\SMax4PNP.exe
----a-w 1,388,544 2004-06-30 17:33:04 C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
----a-w 847,872 2004-07-07 18:56:34 C:\Program Files\Analog Devices\SoundMAX\bak\bak\Smax4.exe
----a-w 847,872 2004-07-07 18:56:34 C:\Program Files\Analog Devices\SoundMAX\bak\bak\Smax4.exe
----a-w 335,872 2004-05-16 01:00:00 C:\Program Files\ATI Technologies\ATI Control Panel\bak\atiptaxx.exe
----a-w 79,224 2007-09-06 10:06:09 C:\Program Files\Avast4\bak\ashDisp.exe
----a-w 79,224 2007-12-04 13:00:23 C:\Program Files\Avast4\ashDisp.exe
----a-w 290,816 2004-12-03 17:24:20 C:\Program Files\HPQ\Quick Launch Buttons\bak\EabServr.exe
----a-w 290,816 2004-12-03 17:24:20 C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
----a-w 132,496 2007-07-12 08:00:36 C:\Program Files\Java\jre1.6.0_02\bin\bak\jusched.exe
----a-w 132,496 2007-07-12 08:00:36 C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
----a-w 35,328 2007-05-14 22:22:22 C:\Program Files\Winamp\bak\winampa.exe
----a-w 35,328 2007-05-14 22:22:22 C:\Program Files\Winamp\winampa.exe
----a-w 13,312 2003-03-31 19:00:00 C:\WINDOWS\system32\bak\ctfmon.exe
----a-w 15,360 2004-08-04 05:56:50 C:\WINDOWS\system32\ctfmon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-08-26 15:59]
"Gestionnaire Antidote.exe"="C:\PROGRA~1\Druide\Antidote\Antidote\Gestionnaire Antidote.exe" [2005-06-22 16:12]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager UI"="C:\WINDOWS\System32\bcmntray" []
"AGRSMMSG"="AGRSMMSG.exe" [2005-04-19 09:05 C:\WINDOWS\AGRSMMSG.exe]
"eabconfg.cpl"="C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" [2004-12-03 12:24]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2007-05-14 17:22]
"avast!"="C:\PROGRA~1\Avast4\ashDisp.exe" [2007-12-04 08:00]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 00:56]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\585e0725]
rundll32.exe C:\WINDOWS\system32\ejkvckro.dll,b
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAX]
C:\Program Files\Analog Devices\SoundMAX\bak\Smax4.exe /tray
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
2004-06-30 12:33 1388544 --a------ C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2007-07-12 03:00 132496 --a------ C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
R0 atiide;atiide;C:\WINDOWS\system32\DRIVERS\atiide.sys
S3 NPF;NetGroup Packet Filter Driver;C:\WINDOWS\system32\drivers\npf.sys
.
Contents of the 'Scheduled Tasks' folder
"2007-12-13 01:49:44 C:\WINDOWS\Tasks\Critical Battery Alarm Program.job"
- C:\Documents and Settings\intelmic\Desktop\alarme.exe
"2007-12-13 01:49:43 C:\WINDOWS\Tasks\Low Battery Alarm Program.job"
- C:\Documents and Settings\intelmic\Desktop\alarme.exe
"2007-11-06 12:49:20 C:\WINDOWS\Tasks\XoftSpySE.job"
- C:\Program Files\XoftSpySE\XoftSpy.exe
.
**************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-12-15 17:00:23
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-15 17:01:17