This is the combofix log.
ComboFix 08-03-29.1 - Kellie Burns 2008-03-30 19:37:31.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.735 [GMT -5:00]
Running from: C:\Documents and Settings\Kellie Burns\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-02-28 to 2008-03-31 )))))))))))))))))))))))))))))))
.
2008-03-27 21:54 . 2008-03-27 21:54 <DIR> d-------- C:\Program Files\Trend Micro
2008-03-27 01:01 . 2008-03-27 02:57 <DIR> d-------- C:\Documents and Settings\Kellie Burns\Application Data\AVGTOOLBAR
2008-03-27 01:00 . 2008-03-27 01:00 <DIR> d-------- C:\Program Files\AVG
2008-03-27 01:00 . 2008-03-27 22:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-03-27 00:02 . 2008-03-27 00:02 16 --a------ C:\WINDOWS\system\cmicnfg.ini
2008-03-25 02:48 . 2008-03-26 20:36 <DIR> d-------- C:\Program Files\Razor
2008-03-21 00:38 . 2008-03-21 00:38 <DIR> d-------- C:\Program Files\CCleaner
2008-03-06 13:44 . 2008-03-26 20:11 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-03-06 13:44 . 2008-03-06 13:44 1,409 --a------ C:\WINDOWS\QTFont.for
2008-02-20 22:11 . 2008-02-20 22:11 <DIR> d-------- C:\Documents and Settings\Kellie Burns\Application Data\eBay
2008-02-20 22:11 . 2008-02-20 22:11 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\eBay
2008-02-14 16:27 . 2008-02-14 16:27 <DIR> d-------- C:\Program Files\Ventrilo
2008-02-14 16:27 . 2008-02-14 16:28 <DIR> d-------- C:\Documents and Settings\Kellie Burns\Application Data\Ventrilo
2008-02-14 16:27 . 2008-02-14 16:27 <DIR> d-------- C:\Documents and Settings\Kellie Burns\Application Data\ICQ Toolbar
2008-02-14 16:26 . 2008-02-14 16:26 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-02-13 11:22 . 2008-02-20 22:09 <DIR> d-------- C:\Program Files\ICQToolbar
2008-02-13 11:09 . 2008-02-13 15:10 <DIR> d-------- C:\Program Files\ICQ6
2008-02-01 11:32 . 2008-02-01 11:56 19,558 --a------ C:\WINDOWS\hpoins01.dat
2008-02-01 11:32 . 2003-04-22 11:24 16,606 --------- C:\WINDOWS\hpomdl01.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2008-03-28 02:45 --------- d-----w C:\Program Files\Apple Software Update
2008-03-28 02:44 --------- d-----w C:\Program Files\UOAM
2008-03-27 08:10 --------- d-----w C:\Program Files\Common Files\EasyInfo
2008-03-27 07:00 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-27 05:43 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-03-27 05:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-03-27 01:36 --------- d-----w C:\Program Files\Bejeweled 2 Deluxe
2008-03-21 06:08 --------- d-----w C:\Program Files\Google
2008-03-21 05:46 --------- d-----w C:\Program Files\eBay
2007-12-07 02:21 824,832 ----a-w C:\WINDOWS\system32\wininet.dll
2007-12-04 18:38 550,912 ----a-w C:\WINDOWS\system32\oleaut32.dll
2002-09-26 19:06 6,787 -c--a-r C:\Program Files\viaehcx1.cat
2002-09-10 16:07 1,405 ----a-r C:\Program Files\VIAEHCX1.INF
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56 15360]
"H/PC Connection Agent"="C:\PROGRA~1\MI3AA1~1\wcescomm.exe" [2005-11-15 19:44 1200128]
"Mobipocket Web Companion"="C:\PROGRA~1\COMMON~1\MOBIPO~1\webcomp. exe" [2005-01-05 11:13 1601536]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2004-10-29 19:50 4620288]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 02:11 132496]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-11-22 15:26 180269]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41 282624]
"nwiz"="nwiz.exe" [2004-10-29 19:50 921600 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\System32\NvMcTray. dll" [2004-10-29 19:50 86016]
"Dekart Logon for Citrix ICA Client"="C:\PROGRA~1\Dekart\LOGONF~1\ICALogon.exe" [2005-05-04 06:33 1017496]
"Cmaudio"="cmicnfg.cpl" []
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-05-26 12:45 257088]
"UserFaultCheck"="C:\WINDOWS\system32\dumprep 0 -u" [ ]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-04-12 20:47:22 113664]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 23:05:26 29696]
DataViz Inc Messenger.lnk - C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe [2005-10-02 17:45:15 28672]
HotSync Manager.lnk - C:\Program Files\palmOne\Hotsync.exe [2004-06-09 14:16:08 471040]
hp psc 2000 Series.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe [2003-04-09 18:41:38 323646]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"gusvc"=3 (0x3)
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\FreshGames\\Word Mojo Gold\\WordMojoGold.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"C:\\Program Files\\EA Games\\Ultima Online 9th Anniversary Collection\\client.exe"=
"C:\\Program Files\\ICQ6\\ICQ.exe"=
"C:\\WINDOWS\\system32\\LEXPPS.EXE"=
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
.
************************************************** ************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-03-30 19:41:35
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
.
Completion time: 2008-03-30 19:43:30
ComboFix-quarantined-files.txt 2008-03-31 00:43:19
ComboFix2.txt 2008-03-30 01:37:44
Pre-Run: 86,235,967,488 bytes free
Post-Run: 86,225,985,536 bytes free
.
2008-03-12 08:03:43 --- E O F ---