Here's the Combofix log:
ComboFix 08-11-18.04 - Dennis 2008-11-18 23:13:25.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.1.1252.1.1033.18.657 [GMT -8:00]
Running from: c:\documents and settings\Dennis\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Dennis\Desktop\cfscript.txt
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80 . . . . failed to delete
c:\windows\Downloaded Program Files\TriJinx.1.0.0.67 . . . . failed to delete
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ALERTERRASAUTOATICLR_OPTIMIZATION_V2.0.50727_32
-------\Legacy_ALERTERRPCSS
-------\Legacy_APPMGMTCISVC
-------\Legacy_APPMGMTCISVCFASTUSERSWITCHINGCOMPATIBILITY
-------\Legacy_APPMGMTFASTUSERSWITCHINGCOMPATIBILITY
-------\Legacy_APPMGMTFASTUSERSWITCHINGCOMPATIBILITYTRKWKSIMAPISERVICE
-------\Legacy_APPMGMTFASTUSERSWITCHINGCOMPATIBILITYTRKWKSIMAPISERVICEMESSENGERRSVP
-------\Legacy_APPMGMTFASTUSERSWITCHINGCOMPATIBILITYTRKWKSIMAPISERVICENETMAN
-------\Legacy_APPMGMTFASTUSERSWITCHINGCOMPATIBILITYTRKWKSIMAPISERVICE_PMSP_SERVICE
-------\Legacy_ASPNET_STATELMHOSTS
-------\Legacy_ATICLR_OPTIMIZATION_V2.0.50727_32
-------\Legacy_ATICLR_OPTIMIZATION_V2.0.50727_32APPMGMTFASTUSERSWITCHINGCOMPATIBILITYTRKWKSIMAPISERVICE
-------\Legacy_AUDIOSRVRDSESSMGR
-------\Legacy_BITSDCOMLAUNCH
-------\Legacy_BROWSERASPNET_STATELMHOSTS
-------\Legacy_BROWSERWUAUSERV
-------\Legacy_BROWSERWUAUSERVALG
-------\Legacy_BROWSERWUAUSERVW32TIMESPOOLERNVSVC
-------\Legacy_CLIPSRVSSDPSRVEVENTSYSTEMWUAUSERVEVENTLOGIMAPISERVICEGUSVC
-------\Legacy_CLR_OPTIMIZATION_V2.0.50727_32RASMAN
-------\Legacy_COMSYSAPPFASTUSERSWITCHINGCOMPATIBILITY
-------\Legacy_COMSYSAPPFASTUSERSWITCHINGCOMPATIBILITYWMPNETWORKSVCWEBCLIENT
-------\Legacy_DHCPNETMAN
-------\Legacy_DMADMINEVENTLOG
-------\Legacy_DNSCACHEGUSVC
-------\Legacy_EVENTSYSTEMGUSVC
-------\Legacy_EVENTSYSTEMGUSVCWMPNETWORKSVC
-------\Legacy_GUSVCSTISVC
-------\Legacy_HIDSERVASPNET_STATE
-------\Legacy_LMHOSTSNTLMSSP
-------\Legacy_MESSENGERRSVP
-------\Legacy_MSDTCWZCSVC
-------\Legacy_MSDTCWZCSVCAPPMGMTCISVCFASTUSERSWITCHINGCOMPATIBILITY
-------\Legacy_MSDTCWZCSVCAPPMGMTCISVCFASTUSERSWITCHINGCOMPATIBILITY_SMART
-------\Legacy_MSISERVERTRKWKSALG
-------\Legacy_NETDDECLR_OPTIMIZATION_V2.0.50727_32
-------\Legacy_NETDDEDSDMGUSVCSTISVC
-------\Legacy_NETDDEDSDM_SMART
-------\Legacy_NETMANSAMSS
-------\Legacy_NETMANWMPNETWORKSVCNTMSSVC
-------\Legacy_NLASENS
-------\Legacy_NVSVCHKMSVC
-------\Legacy_NVSVCREMOTEACCESS
-------\Legacy_NVSVCREMOTEACCESSDHCPNETMAN
-------\Legacy_POLICYAGENTWEBCLIENT
-------\Legacy_POLICYAGENTWEBCLIENTWMIAPSRV
-------\Legacy_RASAUTOATICLR_OPTIMIZATION_V2.0.50727_32
-------\Legacy_REMOTEACCESSNTLMSSP
-------\Legacy_REMOTEACCESSPOLICYAGENTWEBCLIENT
-------\Legacy_RPCLOCATORREMOTEACCESSNTLMSSP
-------\Legacy_SCARDSVRTHEMES
-------\Legacy_SECLOGONALG
-------\Legacy_SHAREDACCESSWMPNETWORKSVCNTMSSVC
-------\Legacy_SHELLHWDETECTIONIDRIVERT
-------\Legacy_SHELLHWDETECTIONIDRIVERTPLUGPLAY
-------\Legacy_SHELLHWDETECTIONIDRIVERTPLUGPLAYNVSVCREMOTEACCESS
-------\Legacy_SHELLHWDETECTIONIDRIVERTPLUGPLAYRPCLOCATORREMOTEACCESSNTLMSSP
-------\Legacy_SHELLHWDETECTION_SERVICE_FOR_CDROM_ACCESS
-------\Legacy_SPOOLERAUDIOSRVRDSESSMGR
-------\Legacy_SPOOLERAUDIOSRVRDSESSMGRTRKWKSALGSSDPSRVEVENTSYSTEMWUAUSERVEVENTLOGIMAPISERVICEGUSVC
-------\Legacy_SPOOLERNVSVC
-------\Legacy_SPOOLER_SMART
-------\Legacy_SSDPSRVEVENTSYSTEM
-------\Legacy_SSDPSRVEVENTSYSTEMWUAUSERVEVENTLOGIMAPISERVICEGUSVC
-------\Legacy_SWPRVSHAREDACCESS
-------\Legacy_SYSMONLOGAPPMGMTCISVCFASTUSERSWITCHINGCOMPATIBILITY
-------\Legacy_TRKWKSALG
-------\Legacy_TRKWKSALGSSDPSRVEVENTSYSTEMWUAUSERVEVENTLOGIMAPISERVICEGUSVC
-------\Legacy_TRKWKSIMAPISERVICE
-------\Legacy_TRKWKSLANMANSERVER
-------\Legacy_TRKWKSNETMANSAMSS
-------\Legacy_UPSAUDIOSRVRDSESSMGR
-------\Legacy_W32TIMESPOOLERNVSVC
-------\Legacy_WINMGMTWMDMPMSNASPNET_STATELMHOSTS
-------\Legacy_WMDMPMSNASPNET_STATELMHOSTS
-------\Legacy_WMIAPSRVAPPMGMTCISVCFASTUSERSWITCHINGCOMPATIBILITY
-------\Legacy_WMIAPSRVREMOTEACCESSNTLMSSP
-------\Legacy_WMPNETWORKSVCNTMSSVC
-------\Legacy_WMPNETWORKSVCNTMSSVCTERMSERVICE
-------\Legacy_WMPNETWORKSVCWEBCLIENT
-------\Legacy_WMPNETWORKSVCWEBCLIENTDHCP
-------\Legacy_WSCSVCDHCP
-------\Legacy_WUAUSERVDHCP
-------\Legacy_WUAUSERVEVENTLOG
-------\Legacy_WUAUSERVEVENTLOGIMAPISERVICE
-------\Legacy_WUAUSERVEVENTLOGIMAPISERVICEGUSVC
-------\Service_AlerterRasAutoAticlr_optimization_v2.0.50727_32
-------\Service_AlerterRpcSs
-------\Service_AppMgmtCiSvc
-------\Service_AppMgmtCiSvcFastUserSwitchingCompatibility
-------\Service_AppMgmtFastUserSwitchingCompatibility
-------\Service_AppMgmtFastUserSwitchingCompatibilityTrkWksImapiService
-------\Service_AppMgmtFastUserSwitchingCompatibilityTrkWksImapiService PMSP Service
-------\Service_AppMgmtFastUserSwitchingCompatibilityTrkWksImapiServiceMessengerRSVP
-------\Service_AppMgmtFastUserSwitchingCompatibilityTrkWksImapiServiceNetman
-------\Service_aspnet_stateLmHosts
-------\Service_Aticlr_optimization_v2.0.50727_32
-------\Service_Aticlr_optimization_v2.0.50727_32AppMgmtFastUserSwitchingCompatibilityTrkWksImapiService
-------\Service_AudioSrvRDSessMgr
-------\Service_BITSDcomLaunch
-------\Service_Browseraspnet_stateLmHosts
-------\Service_Browserwuauserv
-------\Service_BrowserwuauservALG
-------\Service_BrowserwuauservW32TimeSpoolerNVSvc
-------\Service_ClipSrvSSDPSRVEventSystemwuauservEventlogImapiServicegusvc
-------\Service_clr_optimization_v2.0.50727_32RasMan
-------\Service_COMSysAppFastUserSwitchingCompatibility
-------\Service_COMSysAppFastUserSwitchingCompatibilityWMPNetworkSvcWebClient
-------\Service_DhcpNetman
-------\Service_dmadminEventlog
-------\Service_Dnscachegusvc
-------\Service_EventSystemgusvc
-------\Service_EventSystemgusvcWMPNetworkSvc
-------\Service_gusvcstisvc
-------\Service_HidServaspnet_state
-------\Service_LmHostsNtLmSsp
-------\Service_MessengerRSVP
-------\Service_MSDTCWZCSVC
-------\Service_MSDTCWZCSVCAppMgmtCiSvcFastUserSwitchingCompatibility
-------\Service_MSDTCWZCSVCAppMgmtCiSvcFastUserSwitchingCompatibility Smart
-------\Service_MSIServerTrkWksALG
-------\Service_NetDDEclr_optimization_v2.0.50727_32
-------\Service_NetDDEdsdm Smart
-------\Service_NetDDEdsdmgusvcstisvc
-------\Service_NetmanSamSs
-------\Service_NetmanWMPNetworkSvcNtmsSvc
-------\Service_NlaSENS
-------\Service_NVSvchkmsvc
-------\Service_NVSvcRemoteAccess
-------\Service_NVSvcRemoteAccessDhcpNetman
-------\Service_PolicyAgentWebClient
-------\Service_PolicyAgentWebClientWmiApSrv
-------\Service_RasAutoAticlr_optimization_v2.0.50727_32
-------\Service_RemoteAccessNtLmSsp
-------\Service_RemoteAccessPolicyAgentWebClient
-------\Service_RpcLocatorRemoteAccessNtLmSsp
-------\Service_SCardSvrThemes
-------\Service_seclogonALG
-------\Service_SharedAccessWMPNetworkSvcNtmsSvc
-------\Service_ShellHWDetection Service for CDROM Access
-------\Service_ShellHWDetectionIDriverT
-------\Service_ShellHWDetectionIDriverTPlugPlay
-------\Service_ShellHWDetectionIDriverTPlugPlayNVSvcRemoteAccess
-------\Service_ShellHWDetectionIDriverTPlugPlayRpcLocatorRemoteAccessNtLmSsp
-------\Service_Spooler Smart
-------\Service_SpoolerAudioSrvRDSessMgr
-------\Service_SpoolerAudioSrvRDSessMgrTrkWksALGSSDPSRVEventSystemwuauservEventlogImapiServicegusvc
-------\Service_SpoolerNVSvc
-------\Service_SSDPSRVEventSystem
-------\Service_SSDPSRVEventSystemwuauservEventlogImapiServicegusvc
-------\Service_SwPrvSharedAccess
-------\Service_SysmonLogAppMgmtCiSvcFastUserSwitchingCompatibility
-------\Service_TrkWksALG
-------\Service_TrkWksALGSSDPSRVEventSystemwuauservEventlogImapiServicegusvc
-------\Service_TrkWksImapiService
-------\Service_TrkWkslanmanserver
-------\Service_TrkWksNetmanSamSs
-------\Service_UPSAudioSrvRDSessMgr
-------\Service_W32TimeSpoolerNVSvc
-------\Service_winmgmtWmdmPmSNaspnet_stateLmHosts
-------\Service_WmdmPmSNaspnet_stateLmHosts
-------\Service_WmiApSrvAppMgmtCiSvcFastUserSwitchingCompatibility
-------\Service_WmiApSrvRemoteAccessNtLmSsp
-------\Service_WMPNetworkSvcNtmsSvc
-------\Service_WMPNetworkSvcNtmsSvcTermService
-------\Service_WMPNetworkSvcWebClient
-------\Service_WMPNetworkSvcWebClientDhcp
-------\Service_wscsvcDhcp
-------\Service_wuauservDhcp
-------\Service_wuauservEventlog
-------\Service_wuauservEventlogImapiService
-------\Service_wuauservEventlogImapiServicegusvc
((((((((((((((((((((((((( Files Created from 2008-10-19 to 2008-11-19 )))))))))))))))))))))))))))))))
.
2008-11-14 15:14 . 2008-11-14 15:14 250 --a------ c:\windows\gmer.ini
2008-11-10 20:00 . 2008-11-10 21:22 <DIR> d-------- c:\documents and settings\Dennis\DoctorWeb
2008-11-08 17:57 . 2008-11-08 17:57 801,610 --a------ C:\QDATA02.IDX
2008-11-08 16:12 . 2008-11-08 16:12 <DIR> d-------- c:\documents and settings\All Users\Application Data\NVIDIA
2008-11-08 13:39 . 2002-12-04 20:01 820,864 -ra------ c:\windows\system32\drivers\nvmcp.sys
2008-11-08 13:39 . 2002-12-04 20:01 241,664 -ra------ c:\windows\system32\drivers\nvapu.sys
2008-11-08 13:39 . 2002-12-04 20:01 62,336 -ra------ c:\windows\system32\drivers\nvarm.sys
2008-11-08 13:39 . 2002-12-04 20:01 44,032 -ra------ c:\windows\system32\OpenAL32.dll
2008-11-08 13:39 . 2002-12-04 20:01 44,032 -ra------ c:\windows\system32\nvopenal.dll
2008-11-08 13:39 . 2002-12-04 20:01 30,720 -ra------ c:\windows\system32\nvasio.dll
2008-11-08 13:39 . 2002-12-04 20:01 13,056 -ra------ c:\windows\system32\drivers\nvax.sys
2008-11-08 13:39 . 2002-12-04 20:01 5,120 -ra------ c:\windows\system32\ALut.dll
2008-11-08 13:39 . 2002-12-04 20:01 4,096 -ra------ c:\windows\system32\nvack.dll
2008-11-08 13:37 . 2002-08-29 02:01 134,272 --a------ c:\windows\system32\drivers\portcls.sys
2008-11-08 13:37 . 2002-08-29 02:01 134,272 --a--c--- c:\windows\system32\dllcache\portcls.sys
2008-11-08 13:37 . 2002-08-29 01:32 57,856 --a------ c:\windows\system32\drivers\drmk.sys
2008-11-08 13:37 . 2002-08-29 01:32 57,856 --a--c--- c:\windows\system32\dllcache\drmk.sys
2008-11-08 13:37 . 2001-08-17 22:37 22,016 --a------ c:\windows\system32\wdmaud.drv
2008-11-08 13:02 . 2002-10-03 23:23 80,896 -ra------ c:\windows\system32\drivers\NVENET.sys
2008-11-08 13:02 . 2002-10-03 23:23 1,024 -ra------ c:\windows\system32\drivers\jedih2rx.bin
2008-11-08 13:02 . 2002-10-03 23:23 122 -ra------ c:\windows\system32\drivers\ramsed.bin
2008-11-08 13:02 . 2002-10-03 23:23 42 -ra------ c:\windows\system32\drivers\jedireg.pat
2008-11-08 12:55 . 2008-11-08 12:55 3,813 --a------ c:\windows\Ascd_tmp.ini
2008-11-08 12:23 . 2008-11-08 13:04 <DIR> d-------- c:\windows\LastGood.Tmp
2008-11-08 09:59 . 2008-11-08 09:59 <DIR> d-------- c:\documents and settings\All Users\Application Data\nView_Profiles
2008-11-08 09:35 . 2006-10-22 12:22 208,896 --a------ c:\windows\system32\nvudisp.exe
2008-11-08 09:35 . 2008-11-18 23:19 88,566 --a------ c:\windows\system32\nvapps.xml
2008-11-08 09:35 . 2006-10-22 12:22 17,056 --a------ c:\windows\system32\nvdisp.nvu
2008-11-08 09:33 . 2006-10-22 15:06 208,896 --a------ c:\windows\system32\NVUNINST.EXE
2008-11-06 14:28 . 2008-11-06 14:28 <DIR> d-------- c:\documents and settings\Administrator\WINDOWS
2008-11-06 14:28 . 2008-11-06 14:28 <DIR> d-------- c:\documents and settings\Administrator\Application Data\Leadertech
2008-11-04 20:56 . 2008-11-04 21:12 3,484 --a------ c:\windows\system32\PerfStringBackup.TMP
2008-11-04 20:38 . 2002-08-29 04:00 13,463,552 --a--c--- c:\windows\system32\dllcache\hwxjpn.dll
2008-11-04 20:37 . 2001-08-17 22:36 2,134,528 --a--c--- c:\windows\system32\dllcache\EXCH_smtpsnap.dll
2008-11-04 20:36 . 2008-11-04 20:36 23,392 --a------ c:\windows\system32\nscompat.tlb
2008-11-04 20:36 . 2008-11-04 20:36 16,832 --a------ c:\windows\system32\amcompat.tlb
2008-11-04 20:34 . 2002-08-29 04:00 106,562 --a--c--- c:\windows\system32\dllcache\srchctls.dll
2008-11-04 20:34 . 2008-11-04 20:34 749 -rah----- c:\windows\WindowsShell.Manifest
2008-11-04 20:34 . 2008-11-04 20:34 749 -rah----- c:\windows\system32\wuaucpl.cpl.manifest
2008-11-04 20:34 . 2008-11-04 20:34 749 -rah----- c:\windows\system32\sapi.cpl.manifest
2008-11-04 20:34 . 2008-11-04 20:34 749 -rah----- c:\windows\system32\ncpa.cpl.manifest
2008-11-04 20:34 . 2008-11-04 20:34 488 -rah----- c:\windows\system32\logonui.exe.manifest
2008-11-04 20:31 . 2002-08-29 04:00 1,267,712 --a--c--- c:\windows\system32\dllcache\cimwin32.dll
2008-11-04 20:26 . 2001-08-17 13:59 50,048 --a------ c:\windows\system32\drivers\DMusic.sys
2008-11-04 20:26 . 2002-08-29 01:32 5,888 --a------ c:\windows\system32\drivers\splitter.sys
2008-11-04 20:11 . 2002-08-29 04:00 24,661 --a------ c:\windows\system32\spxcoins.dll
2008-11-04 20:11 . 2002-08-29 04:00 24,661 --a--c--- c:\windows\system32\dllcache\spxcoins.dll
2008-11-04 20:11 . 2002-08-29 04:00 13,312 --a------ c:\windows\system32\irclass.dll
2008-11-04 20:11 . 2002-08-29 04:00 13,312 --a--c--- c:\windows\system32\dllcache\irclass.dll
2008-11-04 20:10 . 2002-08-29 04:00 1,086,182 -ra------ c:\windows\SET60.tmp
2008-11-04 20:10 . 2002-08-29 04:00 13,608 -ra------ c:\windows\SET75.tmp
2008-11-04 12:36 . 2002-08-29 01:27 56,576 --a------ c:\windows\system32\drivers\redbook.sys
2008-11-04 12:32 . 2002-08-29 03:46 38,024 --a------ c:\windows\system32\drivers\termdd.sys
2008-11-04 12:31 . 2002-08-29 04:00 696,320 --a--c--- c:\windows\system32\dllcache\sapi.dll
2008-11-04 12:31 . 2002-08-29 04:00 147,456 --a--c--- c:\windows\system32\dllcache\sapi.cpl
2008-11-04 12:31 . 2002-08-29 04:00 132,096 --a------ c:\windows\system\WINSPOOL.DRV
2008-11-04 12:31 . 2002-08-29 03:41 71,168 --a------ c:\windows\system32\storprop.dll
2008-11-04 12:31 . 2002-08-29 04:00 22,016 --a--c--- c:\windows\system32\dllcache\agt0408.dll
2008-11-04 12:31 . 2002-08-29 04:00 19,968 --a--c--- c:\windows\system32\dllcache\agt040e.dll
2008-11-04 12:31 . 2002-08-29 04:00 19,456 --a--c--- c:\windows\system32\dllcache\agt041f.dll
2008-11-04 12:31 . 2002-08-29 04:00 19,456 --a--c--- c:\windows\system32\dllcache\agt0419.dll
2008-11-04 12:31 . 2002-08-29 04:00 19,456 --a--c--- c:\windows\system32\dllcache\agt0415.dll
2008-11-04 12:31 . 2002-08-29 04:00 19,456 --a--c--- c:\windows\system32\dllcache\agt0405.dll
2008-11-04 12:31 . 2002-08-29 04:00 10,496 --a------ c:\windows\system32\drivers\irenum.sys
2008-11-04 12:31 . 2002-08-29 04:00 10,496 --a--c--- c:\windows\system32\dllcache\irenum.sys
2008-10-29 19:10 . 2008-10-29 19:10 20,992 --ahs---- c:\windows\system32\accwizh.dll
2008-10-28 19:41 . 2008-10-28 19:41 <DIR> d-------- c:\program files\ERUNT
2008-10-24 21:34 . 2008-10-24 21:34 <DIR> d-------- C:\New Folder
2008-10-24 21:28 . 2008-10-24 21:28 <DIR> d-------- C:\backups
2008-10-20 17:17 . 2008-10-20 17:17 <DIR> d-------- c:\documents and settings\Guest\Application Data\MX
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-09 18:39 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2008-11-09 18:02 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2008-11-09 18:02 --------- d-----w c:\program files\ThreatFire
2008-11-08 18:49 --------- d-----w c:\documents and settings\Dennis\Application Data\MSN6
2008-11-06 23:04 --------- d-----w c:\program files\MSN Messenger
2008-11-03 02:35 --------- d-----w c:\program files\Spybot - Search & Destroy
2008-10-25 03:59 --------- d-----w c:\program files\Trend Micro
2008-10-19 17:37 --------- d-----w c:\program files\EA GAMES
2008-10-05 09:38 --------- d-----w c:\program files\Microsoft Silverlight
2008-09-30 04:45 --------- d-----w c:\program files\Palm
2008-09-30 04:44 --------- d-----w c:\program files\Common Files\Skyscape
2008-09-25 03:28 134,992 ----a-w C:\QDATA02OFXLOG.DAT
2008-09-19 21:20 --------- d-----w c:\program files\Lavasoft
2008-09-19 21:20 --------- d-----w c:\documents and settings\All Users\Application Data\Lavasoft
2008-09-14 20:42 92,672 ----a-w c:\documents and settings\Administrator\KillBox.exe
2006-11-24 21:28 807,624 ----a-w c:\program files\DF_BHD_Pinger_5_0_BHD_TS_v1_5_0_5_-_Creator_Dstructr.zip
2006-07-11 23:00 5,632 --sha-w c:\program files\Thumbs.db
2005-02-10 07:01 79,068,001 ----a-w c:\program files\Blackopsv1.0.zip
2004-03-15 21:29 299,624 ----a-w c:\program files\dxwebsetup.exe
2003-10-16 00:07 2,245 ----a-w c:\program files\_FILES.PFF
2003-10-14 22:49 84 ----a-w c:\program files\UPDATE.WIZ
2003-10-13 22:31 403 ----a-w c:\program files\STARTUP.HTM
2003-10-06 20:29 4,244 ----a-w c:\program files\Gameerr.bin
2003-10-02 17:18 95,377 ----a-w c:\program files\dfvgame.LWF
2003-09-26 22:21 74,534 ----a-w c:\program files\MogSlm04.3di
2003-09-25 23:44 51,529 ----a-w c:\program files\Gametext.bin
2003-09-25 23:04 353,399 ----a-w c:\program files\FAH6b.3di
2003-09-25 23:03 399,366 ----a-w c:\program files\FAH6a.3di
2003-09-25 22:51 644,422 ----a-w c:\program files\fblkhawk.3di
2003-09-25 22:50 668,018 ----a-w c:\program files\fblkhawf.3di
2003-09-25 22:42 649,693 ----a-w c:\program files\fblkhawd.3di
2003-09-24 22:07 116,841 ----a-w c:\program files\ammo.def
2003-09-23 23:55 81,705 ----a-w c:\program files\weapon.def
2003-09-18 21:27 30,647 ----a-w c:\program files\menutxt.bin
2003-09-17 01:29 29,731 ----a-w c:\program files\EMOTE13.bad
2003-09-16 21:46 8,286 ----a-w c:\program files\DELTA01.ADM
2003-09-16 18:04 1,194,796 ----a-w c:\program files\RE_Bsmt.3di
2003-09-16 16:56 49,566 ----a-w c:\program files\MogSlm01.3di
2003-09-15 20:37 73,497 ----a-w c:\program files\dfvmenus.mnu
2003-07-10 21:35 10,538 ----a-w c:\program files\airexp2.ptl
2003-07-10 21:35 1,614 ----a-w c:\program files\bcasings.ptl
2003-07-10 21:35 1,573 ----a-w c:\program files\casings.ptl
2003-07-08 20:47 18,629 ----a-w c:\program files\bird1.pcx
2003-05-30 21:38 4,553 ----a-w c:\program files\ADP_11B.til
2003-05-30 21:38 4,553 ----a-w c:\program files\ADP_11A.til
2003-05-30 21:38 25,647 ----a-w c:\program files\ADP_11B.bms
2003-05-30 21:38 25,647 ----a-w c:\program files\ADP_11A.bms
2003-05-20 21:11 9,173 ----a-w c:\program files\KYLE.WAC
2003-05-07 17:28 225,045 ----a-w c:\program files\Btn_ign.tga
2003-04-17 23:47 185,371 ----a-w c:\program files\FHum50N.3di
2003-04-17 23:32 190,602 ----a-w c:\program files\FHum50X.3di
2003-04-17 23:18 167,321 ----a-w c:\program files\FHum50P.3di
2003-04-17 23:04 167,156 ----a-w c:\program files\FHum50.3di
2003-04-14 23:16 28,805 ----a-w c:\program files\FBK_03a.bms
2003-04-14 23:16 28,793 ----a-w c:\program files\FBK_03b.bms
2003-04-14 23:16 1,540 ----a-w c:\program files\FBK_03b.til
2003-04-14 23:16 1,540 ----a-w c:\program files\FBK_03a.til
2003-04-10 21:58 1,486,671 ----a-w c:\program files\BHD_ups2.tga
2003-04-09 20:47 64,693 ----a-w c:\program files\SPBHD_14.bms
2003-04-09 20:47 2,233 ----a-w c:\program files\SPBHD_14.til
2003-04-04 22:49 242,110 ----a-w c:\program files\Btn_gmdm.tga
2003-04-04 22:33 254,761 ----a-w c:\program files\Btn_zila.tga
2003-04-04 22:27 102,727 ----a-w c:\program files\Btn_lnk2.tga
2003-04-04 22:23 59,374 ----a-w c:\program files\Btn_ext2.tga
2003-03-26 18:43 28,122 ----a-w c:\program files\SDK_01b.bms
2003-03-26 18:43 10,401 ----a-w c:\program files\SDK_01b.til
2003-03-26 18:41 5,140 ----a-w c:\program files\ADK_02b.til
2003-03-26 18:41 30,835 ----a-w c:\program files\ADK_02b.bms
2003-03-26 18:40 30,101 ----a-w c:\program files\ADK_01b.bms
2003-03-26 18:40 10,429 ----a-w c:\program files\ADK_01b.til
2003-03-25 23:32 32,592 ----a-w c:\program files\CTFK_02b.bms
2003-03-25 23:32 10,455 ----a-w c:\program files\CTFK_02b.til
2003-03-25 23:28 30,106 ----a-w c:\program files\ADK_01a.bms
2003-03-25 23:28 10,429 ----a-w c:\program files\ADK_01a.til
2003-03-25 22:21 13,774 ----a-w c:\program files\dfvdbgov.mnu
2003-03-25 18:52 73,378 ----a-w c:\program files\MogBlk07.3DI
2003-03-25 18:16 31,569 ----a-w c:\program files\SDM_01b.bms
2003-03-25 18:15 31,551 ----a-w c:\program files\SDM_01a.bms
2003-03-25 18:09 6,396 ----a-w c:\program files\DMM_01h.til
2003-03-25 18:09 39,417 ----a-w c:\program files\DMM_01h.bms
2003-03-25 18:03 6,396 ----a-w c:\program files\CTFK_03a.til
2003-03-25 18:03 41,222 ----a-w c:\program files\CTFK_03a.bms
2003-03-25 17:59 6,396 ----a-w c:\program files\CTFK_03b.til
2003-03-25 17:59 41,225 ----a-w c:\program files\CTFK_03b.bms
2003-03-24 22:44 6,569 ----a-w c:\program files\zboard.key
2003-03-24 21:13 31,939 ----a-w c:\program files\SDM_02b.bms
2003-03-24 21:01 20,403 ----a-w c:\program files\SDP_01B.bms
2003-03-24 20:52 19,433 ----a-w c:\program files\SDM_01f.bms
2003-03-24 18:54 55,788 ----a-w c:\program files\CTFM_05B.bms
2003-03-24 18:50 55,998 ----a-w c:\program files\CTFM_05A.bms
2003-03-21 23:15 44,500 ----a-w c:\program files\SPBHD_13.bms
2003-03-21 23:15 10,567 ----a-w c:\program files\SPBHD_13.til
2003-03-21 17:18 31,450 ----a-w c:\program files\TKHM_02b.bms
2003-03-21 17:16 31,424 ----a-w c:\program files\TKHM_02a.bms
2003-03-21 17:15 31,537 ----a-w c:\program files\TDMM_02b.bms
2003-03-21 17:13 31,527 ----a-w c:\program files\TDMM_02a.bms
2003-03-21 17:12 3,025 ----a-w c:\program files\SDM_02b.til
2003-03-21 17:10 31,921 ----a-w c:\program files\SDM_02a.bms
2003-03-21 17:10 3,025 ----a-w c:\program files\SDM_02a.til
2003-03-21 17:09 31,625 ----a-w c:\program files\FBM_02b.bms
.
((((((((((((((((((((((((((((( snapshot@2008-11-09_10.03.26.56 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-10-20 19:02:28 163,328 ----a-w c:\windows\ERDNT\11-10-2008\ERDNT.EXE
+ 2008-11-11 03:55:42 7,118,848 ----a-w c:\windows\ERDNT\11-10-2008\Users\
00000001\ntuser.dat
+ 2008-11-11 03:55:42 184,320 ----a-w c:\windows\ERDNT\11-10-2008\Users\
00000002\UsrClass.dat
+ 2005-10-20 19:02:28 163,328 ----a-w c:\windows\ERDNT\11-17-2008\ERDNT.EXE
+ 2008-11-18 02:20:50 7,118,848 ----a-w c:\windows\ERDNT\11-17-2008\Users\
00000001\ntuser.dat
+ 2008-11-18 02:20:50 184,320 ----a-w c:\windows\ERDNT\11-17-2008\Users\
00000002\UsrClass.dat
+ 2008-11-14 23:14:13 884,736 ----a-w c:\windows\gmer.dll
+ 2008-04-18 05:13:02 811,008 ----a-w c:\windows\gmer.exe
- 2008-11-09 17:44:14 233,472 ----a-w c:\windows\system32\config\systemprofile\ntuser.dat
+ 2008-11-19 07:13:17 233,472 ----a-w c:\windows\system32\config\systemprofile\ntuser.dat
+ 2008-11-14 23:14:13 85,969 ----a-w c:\windows\system32\drivers\gmer.sys
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\WCESCOMM.EXE" [2004-02-03 401491]
"ctfmon.exe"="c:\windows\System32\ctfmon.exe" [2002-08-29 13312]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-11-18 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OneTouch Monitor"="c:\progra~1\VISION~1\ONETOU~2.EXE" [2001-10-16 86016]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2005-08-12 45056]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2006-10-22 7700480]
"NvMediaCenter"="c:\windows\System32\NvMcTray.dll" [2006-10-22 86016]
"nForce Tray Options"="sstray.exe" [2002-11-12 c:\windows\system32\sstray.exe]
"nwiz"="nwiz.exe" [2006-10-22 c:\windows\system32\nwiz.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]
ATI CATALYST System Tray.lnk - c:\program files\ATI Technologies\ATI.ACE\CLI.exe [2005-08-12 45056]
DataViz Inc Messenger.lnk - c:\program files\Common Files\DataViz\DvzIncMsgr.exe [2007-12-25 28672]
HOTSYNCSHORTCUTNAME.lnk - c:\program files\Palm\Hotsync.exe [2004-06-09 471040]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 288472]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableCAD"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.ctmp3"= c:\windows\system32\ctmp3.acm
"MSACM.CEGSM"= mobilev.acm
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft ActiveSync\\WCESMGR.EXE"=
"c:\\Program Files\\Microsoft ActiveSync\\WCESCOMM.EXE"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Documents and Settings\\Dennis\\Local Settings\\Application Data\\Abacast\\Abaclient.exe"=
"c:\\Documents and Settings\\Dennis\\Local Settings\\Application Data\\Abacast\\Abaclient2.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1723:TCP"= 1723:TCP

xpsp2res.dll,-22015
"1701:UDP"= 1701:UDP

xpsp2res.dll,-22016
"500:UDP"= 500:UDP

xpsp2res.dll,-22017
R0 Si3112r;Silicon Image SiI 3112 SATARaid Controller;c:\windows\System32\DRIVERS\si3112r.sys [2003-05-08 102400]
S2 wscsvc Service for CDROM Access;Security Center wscsvc Service for CDROM Access;ð%€|x srv []
.
Contents of the 'Scheduled Tasks' folder
2008-11-19 c:\windows\Tasks\User_Feed_Synchronization-{41111FB6-E87B-4712-9635-90034B0CC9F3}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 18:36]
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-11-18 23:18:55
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\wscsvc Service for CDROM Access]
"ImagePath"="ð%€|x\
01\
09 srv"
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\CTSVCCDA.EXE
c:\windows\system32\nvsvc32.exe
c:\windows\system32\WgaTray.exe
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
c:\windows\system32\imapi.exe
.
**************************************************************************
.
Completion time: 2008-11-18 23:28:01 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-19 07:27:56
ComboFix2.txt 2008-11-11 03:48:42
ComboFix3.txt 2008-11-09 18:04:04
Pre-Run: 59,305,562,112 bytes free
Post-Run: 59,285,487,616 bytes free
464 --- E O F --- 2008-09-27 04:11:43