OK, did that. A few virus warnings popped up in the process, like Smitfraud (it thought one of the ComboFix files was a virus).
Anyhow, here's the log:
----------
"Ollie Wright" - 2007-06-07 11:22:29 Service Pack 2 NTFS
ComboFix 07-06-3B - Running from: "F:\Documents and Settings\Ollie Wright\Desktop\Installed Progs\"
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
F:\DOCUME~1\OLLIEW~1\Desktop.\internet explorer.lnk
((((((((((((((((((((((((( Files Created from 2007-05-06 to 2007-06-06 )))))))))))))))))))))))))))))))
2007-06-06 10:13 30 --a------ F:\WINDOWS\INTURS.DAT
2007-06-05 19:50 1,699,913 --a------ F:\WINDOWS\system32\InetClnt.dll
2007-06-05 19:50 <DIR> d-------- F:\Program Files\Common Files\AnswerWorks 4.0
2007-06-05 19:49 339,968 --a------ F:\WINDOWS\system32\cdintf.dll
2007-06-05 19:49 <DIR> d-------- F:\Program Files\Common Files\Intuit
2007-06-05 19:48 974,848 --a------ F:\WINDOWS\system32\mfc70.dll
2007-06-05 19:48 737,280 --a------ F:\WINDOWS\system32\spr32d30.dll
2007-06-05 19:48 54,784 --a------ F:\WINDOWS\system32\msvci70.dll
2007-06-05 19:48 487,424 --a------ F:\WINDOWS\system32\msvcp70.dll
2007-06-05 19:48 1,694,992 --a------ F:\WINDOWS\system32\vba6.dll
2007-06-05 19:48 <DIR> d-------- F:\Program Files\Intuit
2007-06-05 19:43 <DIR> d-------- F:\Program Files\Common Files\SWF Studio
2007-06-05 19:18 5,856 --a------ F:\WINDOWS\system32\INET16.DLL
2007-06-05 19:18 5,776 --a------ F:\WINDOWS\icoadb32.dat
2007-06-05 19:18 40,448 --a------ F:\WINDOWS\ICG32.DLL
2007-06-05 19:17 73,728 --a------ F:\WINDOWS\system32\Q_ENCLIB.DLL
2007-06-05 19:17 41,472 --a------ F:\WINDOWS\system32\IPROF32.DLL
2007-06-05 19:17 40,960 --a------ F:\WINDOWS\system32\Q_ENCUTL.DLL
2007-06-05 19:17 393,728 --a------ F:\WINDOWS\system32\MSVCRTD.DLL
2007-06-05 19:17 258,560 --a------ F:\WINDOWS\system32\Qcon32.dll
2007-06-05 19:17 196,848 --a------ F:\WINDOWS\system32\QCONNECT.DLL
2007-06-05 19:17 193,024 --a------ F:\WINDOWS\system32\Qcon3216.exe
2007-06-05 19:17 1,393,152 --a------ F:\WINDOWS\system32\MFC42D.DLL
2007-06-05 19:17 <DIR> d-------- F:\WINDOWS\Intuit
2007-06-05 19:17 <DIR> d-------- F:\QUICKENW
2007-05-28 22:16 <DIR> d-------- F:\HijackThis
2007-05-28 18:53 <DIR> d-------- F:\VundoFix Backups
2007-05-28 18:52 <DIR> d-------- F:\DOCUME~1\OLLIEW~1\APPLIC~1\TrojanHunter
2007-05-28 18:03 <DIR> d-------- F:\Program Files\TrojanHunter 4.6
2007-05-28 14:18 <DIR> d-------- F:\WINDOWS\Prefetch
2007-05-28 09:02 <DIR> d-------- F:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-05-28 00:06 <DIR> d-------- F:\DOCUME~1\OLLIEW~1\.housecall6.6
2007-05-27 23:42 6,144 --a------ F:\WINDOWS\system32\csrss original.exe
2007-05-26 20:42 <DIR> d-------- F:\Program Files\PDF Editor 2
2007-05-26 18:36 <DIR> d-------- F:\WINDOWS\system32\appmgmt
2007-05-26 18:35 336 --a------ F:\Program Files\temp995.bat
2007-05-26 17:48 51,716 --a------ F:\WINDOWS\system32\pdf995mon.dll
2007-05-26 17:48 249,856 --a------ F:\WINDOWS\system32\pdfmona.dll
2007-05-26 17:48 <DIR> d-------- F:\DOCUME~1\ALLUSE~1\APPLIC~1\pdf995
2007-05-25 17:41 <DIR> d-------- F:\WINDOWS\system32\The Economist dir
2007-05-25 12:30 60,457 --a------ F:\WINDOWS\system32\EBPMON3.DLL
2007-05-25 12:30 57,344 --a------ F:\WINDOWS\system32\ECBTEG.DLL
2007-05-25 12:30 34,304 --a------ F:\WINDOWS\system32\EBPCHP.DLL
2007-05-25 12:30 166,400 --a------ F:\WINDOWS\system32\EBAPI3.DLL
2007-05-25 12:30 145 --a------ F:\WINDOWS\system32\EBPPORT3.DAT
2007-05-25 12:30 <DIR> d-------- F:\Program Files\EPSON
2007-05-25 12:29 <DIR> d-------- F:\EPSON
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-06-06 10:51:35 24 ----a-w F:\WINDOWS\system32\DVCStateBkp-{00000000-00000000-00000009-00001102-00000002-80271102}.dat
2007-06-06 10:51:35 24 ----a-w F:\WINDOWS\system32\DVCState-{00000000-00000000-00000009-00001102-00000002-80271102}.dat
2007-06-05 07:50:51 -------- d--h--w F:\Program Files\InstallShield Installation Information
2007-05-01 04:21:02 -------- d-----w F:\Program Files\GlobalSCAPE
2007-05-01 04:10:13 -------- d-----w F:\DOCUME~1\OLLIEW~1\APPLIC~1\GlobalSCAPE
2007-04-18 16:12:23 2,854,400 ----a-w F:\WINDOWS\system32\msi.dll
2007-03-22 18:07:56 1,683,280 ------w F:\WINDOWS\system32\XpsSvcs.dll
2007-03-22 18:07:54 583,504 ------w F:\WINDOWS\system32\XPSSHHDR.dll
2007-03-22 08:25:02 124,928 ------w F:\WINDOWS\system32\prntvpt.dll
2007-03-17 13:43:01 292,864 ----a-w F:\WINDOWS\system32\winsrv.dll
2007-03-08 15:36:28 577,536 ----a-w F:\WINDOWS\system32\user32.dll
2007-03-08 15:36:28 40,960 ----a-w F:\WINDOWS\system32\mf3216.dll
2007-03-08 15:36:28 281,600 ----a-w F:\WINDOWS\system32\gdi32.dll
2007-03-08 13:47:48 1,843,584 ----a-w F:\WINDOWS\system32\win32k.sys
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"pccguide.exe"="F:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe" [2006-12-29 13:52]
"MULTIMEDIA KEYBOARD"="F:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe" [2001-12-05 08:13]
"CoolSwitch"="F:\WINDOWS\system32\taskswitch.exe" [2002-03-19 16:30]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="F:\WINDOWS\system32\ctfmon.exe" [2004-08-05 00:00]
"SpybotSD TeaTimer"="F:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2005-05-31 01:04]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\F:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=F:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=F:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\F:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
path=F:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk
backup=F:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\F:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=F:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=F:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\F:^Documents and Settings^All Users^Start Menu^Programs^Startup^Symantec Fax Starter Edition Port.lnk]
path=F:\Documents and Settings\All Users\Start Menu\Programs\Startup\Symantec Fax Starter Edition Port.lnk
backup=F:\WINDOWS\pss\Symantec Fax Starter Edition Port.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AudioHQ]
F:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CardBus-PCI]
"F:\Program Files\DSE\CardBus-PCI\CardBus-PCI.exe" -nogui
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDElbyCDFL]
"F:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDTray]
"F:\Program Files\Elaborate Bytes\CloneCD\CloneCDTray.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Creative Launcher]
F:\Program Files\Creative\Launcher\CTLauncher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dlmMgr]
"F:\Program Files\Common Files\Adobe\ESD\AdobeDownloadManager.exe" restart=1
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelliPoint]
"f:\Program Files\Microsoft IntelliPoint\ipoint.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Jet Detection]
"F:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
%systemroot%\system32\dumprep 0 -k
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"F:\Program Files\Messenger\msmsgs.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
F:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
RUNDLL32.EXE F:\WINDOWS\system32\NvCpl.dll,NvStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
RUNDLL32.EXE F:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"F:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\setup]
rundll32.exe "F:\WINDOWS\system32\oqbrtdyw.dll",realset
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"F:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
F:\WINDOWS\UpdReg.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
"F:\Program Files\Winamp\Winampa.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WINDVDPatch]
CTHELPER.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WZCSVC"=2 (0x2)
"nhksrv"=2 (0x2)
"idsvc"=3 (0x3)
"gusvc"=3 (0x3)
"RasMan"=3 (0x3)
"RasAuto"=3 (0x3)
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs*
**************************************************************************
catchme 0.3.692 W2K/XP/Vista - userland rootkit detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-06-07 11:32:16
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
Completion time: 2007-06-07 11:33:50
F:\ComboFix-quarantined-files.txt ... 2007-06-07 11:33
--- E O F ---