OK...here's the new ComboFix log:
ComboFix 07-12-02.6 - Pacosaff 2007-12-08 23:51:58.6 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.1.1252.1.1033.18.141 [GMT 0:00]
Running from: C:\Documents and Settings\Pacosaff\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Pacosaff\Desktop\CFScript.txt
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Pacosaff\Application Data\dach100.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_AAUDSTUM
-------\aaudstum
((((((((((((((((((((((((( Files Created from 2007-11-09 to 2007-12-09 )))))))))))))))))))))))))))))))
.
2007-12-02 20:36 . 2007-12-02 20:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-12-02 14:14 . 2002-08-29 12:00 102,448 --a------ C:\WINDOWS\system32\wshom.ocx
2007-12-02 14:14 . 2002-08-29 12:00 102,448 --a--c--- C:\WINDOWS\system32\dllcache\wshom.ocx
2007-11-30 23:57 . 2007-11-30 23:57 317,616 --a------ C:\WINDOWS\system32\drivers\srtspl.sys
2007-11-30 23:57 . 2007-11-30 23:57 279,088 --a------ C:\WINDOWS\system32\drivers\srtsp.sys
2007-11-30 23:57 . 2007-11-30 23:57 43,696 --a------ C:\WINDOWS\system32\drivers\srtspx.sys
2007-11-30 23:57 . 2007-11-30 23:57 10,549 --a------ C:\WINDOWS\system32\drivers\srtspx.cat
2007-11-30 23:57 . 2007-11-30 23:57 10,549 --a------ C:\WINDOWS\system32\drivers\srtspl.cat
2007-11-30 23:57 . 2007-11-30 23:57 10,545 --a------ C:\WINDOWS\system32\drivers\srtsp.cat
2007-11-30 23:57 . 2007-11-30 23:57 1,430 --a------ C:\WINDOWS\system32\drivers\srtspl.inf
2007-11-30 23:57 . 2007-11-30 23:57 1,421 --a------ C:\WINDOWS\system32\drivers\srtspx.inf
2007-11-30 23:57 . 2007-11-30 23:57 1,415 --a------ C:\WINDOWS\system32\drivers\srtsp.inf
2007-11-29 00:27 . 2007-05-29 13:55 22,112 -ra------ C:\WINDOWS\system32\drivers\COH_Mon.sys
2007-11-29 00:27 . 2007-05-29 13:55 10,592 -ra------ C:\WINDOWS\system32\drivers\COH_Mon.cat
2007-11-29 00:27 . 2007-05-29 13:55 705 -ra------ C:\WINDOWS\system32\drivers\COH_Mon.inf
2007-11-28 23:56 . 2007-03-21 20:39 1,060,864 --a------ C:\WINDOWS\system32\MFC71.DLL
2007-11-28 23:56 . 2007-03-21 20:33 503,808 --a------ C:\WINDOWS\system32\MSVCP71.DLL
2007-11-28 23:56 . 2007-03-21 20:33 348,160 --a------ C:\WINDOWS\system32\MSVCR71.DLL
2007-11-28 23:51 . 2007-07-17 12:21 186,256 --a------ C:\WINDOWS\system32\SymNPPWA.dll
2007-11-28 23:10 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2007-11-28 23:10 . 2007-07-30 19:19 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2007-11-26 23:58 . 2007-11-26 23:58 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avg7
2007-11-26 23:04 . 2007-11-26 23:04 16 --a------ C:\WINDOWS\system32\coh.cache
2007-11-26 19:42 . 2007-11-29 19:01 <DIR> d-------- C:\Program Files\Norton 360
2007-11-26 19:40 . 2007-12-05 08:57 10,740 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2007-11-26 19:40 . 2007-12-05 08:57 805 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.INF
2007-11-26 19:39 . 2007-12-05 08:57 <DIR> d-------- C:\Program Files\Symantec
2007-11-26 19:39 . 2007-12-07 08:41 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Symantec
2007-11-26 19:38 . 2007-11-30 08:22 <DIR> d-------- C:\Program Files\Common Files\Symantec Shared
2007-11-22 22:41 . 2007-12-08 23:48 <DIR> d-------- C:\Paul's Repair Kit
2007-11-20 08:13 . 2007-11-20 08:13 <DIR> d-------- C:\WINDOWS\system32\re3
2007-11-11 23:21 . 2007-11-11 23:21 <DIR> d-------- C:\Documents and Settings\Pacosaff\Application Data\AquaSoft
2007-11-11 23:19 . 2007-11-11 23:19 <DIR> d--h----- C:\Documents and Settings\All Users\Application Data\{080C77D8-6A24-4B5E-89CF-240D0E56A59E}
2007-11-11 23:18 . 2007-11-11 23:18 <DIR> d-------- C:\Program Files\AquaSoft
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-05 08:57 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-12-02 21:08 --------- d-----w C:\Program Files\PTGui
2007-12-02 20:36 --------- d-----w C:\Program Files\Lavasoft
2007-12-02 20:33 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-12-02 11:28 20 ----a-w C:\sccfg.sys
2007-12-02 10:38 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-02 10:37 --------- d-----w C:\Program Files\Fake Webcam
2007-12-01 08:49 --------- d-----w C:\Program Files\FlashGet
2007-11-29 00:51 --------- d-----w C:\Documents and Settings\Pacosaff\Application Data\uTorrent
2007-11-28 00:08 --------- d-----w C:\Documents and Settings\Pacosaff\Application Data\Symantec
2007-11-19 23:50 --------- d-----w C:\Program Files\3D-brush-2
2007-11-17 21:31 --------- d-----w C:\Program Files\GameHouse
2007-11-17 15:08 --------- d-----w C:\Program Files\PopCap Games
2007-11-15 23:45 --------- d-----w C:\Program Files\Ubisoft
2007-11-14 20:37 --------- d-----w C:\Documents and Settings\Pacosaff\Application Data\LimeWire
2007-11-06 22:24 --------- d-----w C:\Documents and Settings\Pacosaff\Application Data\MilkShape 3D 1.x.x
2007-11-06 22:14 --------- d-----w C:\Program Files\MilkShape 3D 1.8.2
2007-11-05 23:31 --------- d-----w C:\Program Files\Torrent Harvester
2007-11-05 23:01 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-10-30 20:51 --------- d-----w C:\Program Files\SecondLife
2007-10-29 19:03 --------- d-----w C:\Program Files\Pixarra
2007-10-27 14:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Digital Anarchy
2007-10-20 13:47 --------- d-----w C:\Program Files\Act-3D
2007-10-18 18:13 --------- d-----w C:\Program Files\Dark Egypt
2007-10-14 19:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\FLEXnet
2007-10-14 19:49 --------- d-----w C:\Program Files\Common Files\Macrovision Shared
2007-10-14 19:46 --------- d-----w C:\Program Files\Common Files\Adobe
2007-10-14 09:12 --------- d-----w C:\Program Files\FXhome VisionLab Studio
2007-10-12 08:08 --------- d-----w C:\Documents and Settings\Pacosaff\Application Data\MediaMan
2007-01-11 00:08 0 ----a-w C:\Documents and Settings\All Users\Application Data\PKP_DLbz.DAT
2006-09-23 14:57 81,920 ----a-w C:\Documents and Settings\Pacosaff\Application Data\ezpinst.exe
2006-09-23 14:57 47,360 ----a-w C:\Documents and Settings\Pacosaff\Application Data\pcouffin.sys
2005-07-02 16:12 774,144 ----a-w C:\Program Files\RngInterstitial.dll
2007-01-10 22:39 88 --sh--r C:\WINDOWS\system32\668E944800.sys
2007-01-10 22:44 3,454 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((( snapshot@2007-12-06_19.42.52.71 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-03-13 10:57:10 163,328 ----a-w C:\WINDOWS\erdnt\subs\ERDNT.EXE
- 2007-12-05 08:50:29 16,384 -c--a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2007-12-08 08:50:32 16,384 -c--a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2007-12-05 08:50:29 32,768 -c--a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2007-12-08 08:50:32 32,768 -c--a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2007-12-05 08:50:29 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2007-12-08 08:50:32 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2007-12-09 00:14:56 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_6cc.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-11-19 11:33]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe" [2006-10-12 03:10]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-10 05:59]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 18:30]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2002-08-29 12:00]
"NvMediaCenter"="RUNDLL32.exe" [2002-08-29 12:00 C:\WINDOWS\system32\rundll32.exe]
"ALUAlert"="c:\program files\symantec\liveupdate\alunotify.exe" [2007-09-12 18:27]
C:\Documents and Settings\Pacosaff\Start Menu\Programs\Startup\
AntiCrash.lnk - C:\Program Files\Dachshund Software\AntiCrash\AntiCrash.exe [2002-12-17 12:00:44]
BHODemon 2.0.lnk - C:\Program Files\BHODemon 2\BHODemon.exe [2005-06-19 11:59:30]
ICONDESK.lnk - C:\Program Files\ICONDESK\IconDesk.exe [2001-12-02 22:22:03]
MagicDisc.lnk - C:\Program Files\MagicDisc\MagicDisc.exe [2006-09-29 21:22:37]
Registration-INSDVD.lnk - C:\Program Files\Pinnacle\InstantCDDVD\SharedFiles\Pixie\RegTool.exe [2002-09-26 12:18:00]
Stickies.lnk - C:\Program Files\stickies\stickies.exe [2003-06-19 20:06:39]
Yahoo! Widget Engine.lnk - C:\Program Files\Yahoo!\WidgetEngine\YahooWidgetEngine.exe [2005-12-19 11:59:28]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
InterVideo WinCinema Manager.lnk - C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe [2003-10-23 15:31:21]
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2004-07-14 21:16:45]
R0 gxc108b;gxc108b;C:\WINDOWS\System32\DRIVERS\gxc108b.sys
R0 gxc108p;gxc108p;C:\WINDOWS\System32\Drivers\gxc108p.sys
R0 sonyhcb;Sony Digital Imaging Base;C:\WINDOWS\System32\DRIVERS\sonyhcb.sys
R0 VOBID;VOBID;C:\WINDOWS\System32\DRIVERS\vobid.sys
R1 gcvcd;gcvcd;C:\WINDOWS\System32\drivers\gcvcd.sys
R1 sdpiosys;sdpiosys;C:\WINDOWS\System32\drivers\sdpiosys.sys
R1 vobcom;vobcom;C:\WINDOWS\System32\drivers\vobcom.sys
R1 vobiw;vobiw;C:\WINDOWS\System32\drivers\vobiw.sys
R2 aliasdocserver;Alias Documentation Server;"C:\Program Files\Alias\Maya6.0\docs\Wrapper.exe" -s "C:\Program Files\Alias\Maya6.0\docs/Wrapper.conf"
R2 CamthWDM;WebcamMax, WDM Video Capture;C:\WINDOWS\System32\DRIVERS\CamthWDM.sys
R2 CatnHat;CatnHat;C:\WINDOWS\System32\drivers\CatnHat.sys
R2 nvcap;nVidia WDM Video Capture (universal);C:\WINDOWS\System32\DRIVERS\nvcap.sys
R2 nvTUNEP;nVidia WDM TVTuner;C:\WINDOWS\System32\DRIVERS\nvtunep.sys
R2 nvtvSND;nVidia WDM TVAudio Crossbar;C:\WINDOWS\System32\DRIVERS\nvtvsnd.sys
R2 NVXBAR;nVidia WDM A/V Crossbar;C:\WINDOWS\System32\DRIVERS\NVxbar.sys
R2 SentinelKeysServer;Sentinel Keys Server;"C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Keys Server\sntlkeyssrvr.exe"
R3 cdrdrv;Cdrdrv;C:\WINDOWS\System32\Drivers\Cdrdrv.sys
S0 ElbyVCD;ElbyVCD;C:\WINDOWS\System32\DRIVERS\ElbyVCD.sys
S2 CADopia License Manager;CADopia License Manager;C:\PROGRA~1\Cadopia\INTELL~1\LicenseManager\lmgrd.exe
S2 lmgrd;Flexlm;C:\Program Files\Cadopia\IntelliCAD 4\LicenseManager\lmgrd.exe
S2 windrvNT;windrvNT;\??\C:\WINDOWS\System32\windrvNT.sys
S3 Aliasiilace;Aliasiilace;C:\WINDOWS\System32\drivers\drmkaud.sys
S3 C-Dilla;C-Dilla;\??\C:\WINDOWS\System32\drivers\CDANT.SYS
S3 ICAM5USB;Intel(r) PC Camera CS110;C:\WINDOWS\System32\Drivers\ICAM5D2.sys
S3 pmxscan;USB USB FlatBed Scanner Driver;C:\WINDOWS\System32\DRIVERS\usbscan.sys
S3 sonyhcs;Sony Digital Imaging Video;C:\WINDOWS\System32\DRIVERS\sonyhcs.sys
S3 USBVSP;USBVSP;C:\WINDOWS\System32\drivers\Usbvsp.sys
*Newly Created Service* - COMHOST
.
**************************************************************************
catchme 0.3.1318 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-12-09 00:15:44
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
Completion time: 2007-12-09 0:18:25 - machine was rebooted
C:\ComboFix2.txt ... 2007-12-06 19:43
C:\ComboFix3.txt ... 2007-11-25 10:04
.
--- E O F ---