Thanks....
Here is the combofix log....
ComboFix 07-10-07.2 - Jerry Rathke 2007-10-08 12:14:16.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.484 [GMT -5:00]
Running from: C:\Documents and Settings\Jerry Rathke\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2007-09-08 to 2007-10-08 )))))))))))))))))))))))))))))))
.
2007-10-08 12:13 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-10-08 10:33 <DIR> d-------- C:\Program Files\Trend Micro
2007-10-01 14:55 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-10-01 14:54 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-09-27 14:08 <DIR> d-------- C:\Documents and Settings\Jerry Rathke\Application Data\WinRAR
2007-09-20 18:33 81,920 --a------ C:\Documents and Settings\Jerry Rathke\Application Data\ezpinst.exe
2007-09-20 18:33 47,360 --a------ C:\WINDOWS\system32\drivers\pcouffin.sys
2007-09-20 18:33 47,360 --a------ C:\Documents and Settings\Jerry Rathke\Application Data\pcouffin.sys
2007-09-20 18:33 14 --a------ C:\WINDOWS\system32\systeminfo3.dll
2007-09-20 18:33 <DIR> d-------- C:\Program Files\CloneDVD
2007-09-20 18:33 <DIR> d-------- C:\Documents and Settings\Jerry Rathke\Application Data\Vso
2007-09-20 18:33 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\DVDXStudio
2007-09-19 20:10 <DIR> d-------- C:\Program Files\F5
2007-09-15 09:44 <DIR> d-------- C:\Documents and Settings\Jerry Rathke\Application Data\Printer Info Cache
2007-09-15 09:44 <DIR> d-------- C:\Documents and Settings\Jerry Rathke\Application Data\Image Zone Express
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-06 16:35 --------- d-------- C:\Documents and Settings\Jerry Rathke\Application Data\AdobeUM
2007-10-05 14:39 --------- d-------- C:\Program Files\SpywareBlaster
2007-10-01 14:56 --------- d-------- C:\Program Files\Lavasoft
2007-10-01 14:55 --------- d-------- C:\Documents and Settings\Jerry Rathke\Application Data\Lavasoft
2007-09-30 09:54 43520 --a------ C:\WINDOWS\system32\CmdLineExt03.dll
2007-09-29 14:44 --------- d-------- C:\Documents and Settings\Jerry Rathke\Application Data\HP
2007-09-22 07:49 --------- d-------- C:\Documents and Settings\All Users\Application Data\DVD Shrink
2007-09-19 06:31 --------- d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-09-14 19:04 --------- d-------- C:\Program Files\Common Files\HP
2007-09-05 21:09 --------- d-------- C:\Documents and Settings\All Users\Application Data\AntiVir PersonalEdition Classic
2007-09-05 10:34 --------- d-------- C:\Program Files\QuickTime
2007-09-05 10:18 --------- d-------- C:\Documents and Settings\Jerry Rathke\Application Data\DivX
2007-09-05 10:15 --------- d-------- C:\Program Files\DivX
2007-09-02 14:52 --------- d--h----- C:\Program Files\InstallShield Installation Information
2007-09-02 14:52 --------- d-------- C:\Program Files\Linksys
2007-09-02 09:01 --------- d-------- C:\Program Files\BitComet
2007-09-01 18:50 --------- d-------- C:\Documents and Settings\Jerry Rathke\Application Data\Atari
2007-09-01 18:49 --------- d-------- C:\Program Files\Common Files\PocketSoft
2007-09-01 18:49 --------- d-------- C:\Documents and Settings\Jerry Rathke\Application Data\Leadertech
2007-09-01 18:44 --------- d-------- C:\Program Files\Atari
2007-09-01 12:22 --------- d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-09-01 09:09 359808 --a------ C:\WINDOWS\system32\drivers\tcpip.sys
2007-09-01 09:06 --------- d-------- C:\Program Files\Google
2007-08-29 07:23 --------- d-------- C:\Documents and Settings\All Users\Application Data\Google
2007-08-29 07:20 --------- d-------- C:\Documents and Settings\Jerry Rathke\Application Data\Google
2007-08-27 19:57 --------- d-------- C:\Program Files\MSN Messenger
2007-08-27 17:24 --------- d-------- C:\Program Files\HP
2007-08-26 18:21 --------- d-------- C:\Program Files\Common Files\Adobe Systems Shared
2007-08-26 18:21 --------- d-------- C:\Documents and Settings\All Users\Application Data\Adobe Systems
2007-08-26 17:21 --------- d-------- C:\Program Files\iTunes
2007-08-26 17:21 --------- d-------- C:\Program Files\iPod
2007-08-26 17:21 --------- d-------- C:\Documents and Settings\Jerry Rathke\Application Data\Apple Computer
2007-08-26 17:21 --------- d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-08-26 17:19 --------- d-------- C:\Program Files\Apple Software Update
2007-08-26 17:18 --------- d-------- C:\Program Files\Common Files\Apple
2007-08-26 17:18 --------- d-------- C:\Documents and Settings\All Users\Application Data\Apple
2007-08-26 16:54 --------- d-------- C:\Program Files\Stardock
2007-08-26 16:26 --------- d-------- C:\Documents and Settings\Jerry Rathke\Application Data\Windows Desktop Search
2007-08-26 16:25 --------- d-------- C:\Program Files\Windows Desktop Search
2007-08-26 16:12 --------- d-------- C:\Program Files\MSBuild
2007-08-26 16:12 --------- d-------- C:\Program Files\Microsoft Works
2007-08-26 16:10 --------- d-------- C:\Program Files\Microsoft.NET
2007-08-26 16:08 --------- d-------- C:\Program Files\Microsoft Visual Studio 8
2007-08-26 15:59 --------- d-------- C:\Program Files\Linksys Wireless-G Music Bridge
2007-08-26 15:50 --------- d-------- C:\Program Files\Sonic
2007-08-26 15:49 --------- d-------- C:\Program Files\Napster
2007-08-26 15:49 --------- d-------- C:\Documents and Settings\All Users\Application Data\Napster
2007-08-26 15:48 --------- d-------- C:\Program Files\Quicken
2007-08-26 15:47 --------- d-------- C:\Program Files\Notebook Maximizer
2007-08-26 15:46 --------- d-------- C:\Program Files\Symantec
2007-08-26 15:46 --------- d-------- C:\Documents and Settings\All Users\Application Data\Symantec
2007-08-26 15:35 --------- d-------- C:\Program Files\Pure Networks
2007-08-26 15:33 --------- d-------- C:\Program Files\Common Files\AOL
2007-08-26 15:31 --------- d-------- C:\Program Files\DVD Shrink
2007-08-26 15:31 --------- d-------- C:\Program Files\DVD Decrypter
2007-08-26 15:28 --------- d-------- C:\Documents and Settings\All Users\Application Data\AOL
2007-08-26 15:27 --------- d-------- C:\Documents and Settings\Jerry Rathke\Application Data\AOL
2007-08-26 15:25 --------- d-------- C:\Program Files\MSXML 4.0
2007-08-26 15:23 --------- d-------- C:\Program Files\MSXML 6.0
2007-08-26 15:17 --------- d-------- C:\Program Files\Reference Assemblies
2007-08-26 15:16 --------- d-------- C:\Program Files\Windows Media Connect 2
2007-08-26 15:10 --------- d-------- C:\Program Files\ArcSoft
2007-08-26 14:37 --------- d-------- C:\Documents and Settings\All Users\Application Data\HP
2007-08-26 14:32 --------- d-------- C:\Program Files\Hewlett-Packard
2007-08-26 14:32 --------- d-------- C:\Program Files\Common Files\Hewlett-Packard
2007-07-30 21:19 92504 --a------ C:\WINDOWS\system32\cdm.dll
2007-07-30 21:19 549720 --a------ C:\WINDOWS\system32\wuapi.dll
2007-07-30 21:19 53080 --a------ C:\WINDOWS\system32\wuauclt.exe
2007-07-30 21:19 43352 --a------ C:\WINDOWS\system32\wups2.dll
2007-07-30 21:19 325976 --a------ C:\WINDOWS\system32\wucltui.dll
2007-07-30 21:19 271224 --a------ C:\WINDOWS\system32\mucltui.dll
2007-07-30 21:19 207736 --a------ C:\WINDOWS\system32\muweb.dll
2007-07-30 21:19 203096 --a------ C:\WINDOWS\system32\wuweb.dll
2007-07-30 21:19 1712984 --a------ C:\WINDOWS\system32\wuaueng.dll
2007-07-30 21:18 33624 --a------ C:\WINDOWS\system32\wups.dll
2007-07-26 18:06 524288 --a------ C:\WINDOWS\system32\DivXsm.exe
2007-07-26 18:06 3596288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2007-07-26 18:06 200704 --a------ C:\WINDOWS\system32\ssldivx.dll
2007-07-26 18:06 144704 --a------ C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2007-07-26 18:06 129784 --------- C:\WINDOWS\system32\pxafs.dll
2007-07-26 18:06 120056 --------- C:\WINDOWS\system32\pxcpyi64.exe
2007-07-26 18:06 118520 --------- C:\WINDOWS\system32\pxinsi64.exe
2007-07-26 18:06 1044480 --a------ C:\WINDOWS\system32\libdivx.dll
2007-07-26 18:03 823296 --a------ C:\WINDOWS\system32\divx_xx0c.dll
2007-07-26 18:03 823296 --a------ C:\WINDOWS\system32\divx_xx07.dll
2007-07-26 18:03 81920 --a------ C:\WINDOWS\system32\dpl100.dll
2007-07-26 18:03 802816 --a------ C:\WINDOWS\system32\divx_xx11.dll
2007-07-26 18:03 740442 --a------ C:\WINDOWS\system32\DivX.dll
2007-07-26 18:03 593920 --a------ C:\WINDOWS\system32\dpuGUI11.dll
2007-07-26 18:03 57344 --a------ C:\WINDOWS\system32\dpv11.dll
2007-07-26 18:03 53248 --a------ C:\WINDOWS\system32\dpuGUI10.dll
2007-07-26 18:03 344064 --a------ C:\WINDOWS\system32\dpus11.dll
2007-07-26 18:03 294912 --a------ C:\WINDOWS\system32\dpu11.dll
2007-07-26 18:03 294912 --a------ C:\WINDOWS\system32\dpu10.dll
2007-07-26 18:03 196608 --a------ C:\WINDOWS\system32\dtu100.dll
2007-07-26 18:03 12288 --a------ C:\WINDOWS\system32\DivXWMPExtType.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CeEKEY"="C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe" [2004-06-14 07:00]
"CeEPOWER"="C:\Program Files\TOSHIBA\Power Management\CePMTray.exe" [2004-08-19 20:14]
"TPNF"="C:\Program Files\TOSHIBA\TouchPad\TPTray.exe" [2004-03-14 22:17]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-07-20 03:04]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-04-21 23:10]
"LtMoh"="C:\Program Files\ltmoh\Ltmoh.exe" [2003-09-26 17:43]
"AGRSMMSG"="AGRSMMSG.exe" [2004-02-20 17:00 C:\WINDOWS\agrsmmsg.exe]
"Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [2003-10-30 18:46]
"EzButton"="C:\Program Files\EzButton\EzButton.EXE" [2004-05-14 12:29]
"PadTouch"="C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe" [2004-02-03 16:47]
"NDSTray.exe"="NDSTray.exe" []
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 04:41]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 02:47]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 08:24]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-08-15 22:15]
"avgnt"="C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" [2007-09-05 18:46]
"Acrobat Assistant 7.0"="C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2006-01-12 20:52]
"CmFlywav"="C:\WINDOWS\system\CmFlywav.exe" [2006-05-19 15:44]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2003-09-05 05:24]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:00]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe [2007-08-26 18:21:18]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 06:21:22]
RAMASST.lnk - C:\WINDOWS\system32\RAMASST.exe [2004-08-10 16:15:20]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2007-02-05 17:39 294400]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\wbsrv.dll 2007-03-13 12:57 221184 C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\WbSrv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=wbsys.dll
R1 SrvcEKIOMngr;SrvcEKIOMngr;C:\WINDOWS\system32\Drivers\EKIoMngr.sys
R1 SrvcEPECioctl;SrvcEPECioctl;C:\WINDOWS\system32\Drivers\ECioctl.sys
R1 SrvcEPIOMngr;SrvcEPIOMngr;C:\WINDOWS\system32\Drivers\EPIoMngr.sys
R1 SrvcSSIOMngr;SrvcSSIOMngr;C:\WINDOWS\system32\Drivers\SSIoMngr.sys
R1 SrvcTPIOMngr;SrvcTPIOMngr;C:\WINDOWS\system32\Drivers\TPIoMngr.sys
R2 DgiVecp;Team MFP Comm Driver;C:\WINDOWS\system32\Drivers\DgiVecp.sys
R3 cmvad;Linksys Wireless-G Music Bridge Interface;C:\WINDOWS\system32\drivers\cmudaxv.sys
R3 DKbFltr;Dritek HotKey Keyboard Filter Driver;C:\WINDOWS\system32\Drivers\DKbFltr.sys
R3 EPOWER;Compal E-POWER Driver;C:\WINDOWS\system32\Drivers\hkdrv.sys
R3 PCASp50;PCASp50 NDIS Protocol Driver;C:\WINDOWS\system32\Drivers\PCASp50.sys
S3 EMSCR;EMSCR;C:\WINDOWS\system32\DRIVERS\EMS7SK.sys
S3 ESDCR;ESDCR;C:\WINDOWS\system32\DRIVERS\ESD7SK.sys
S3 ESMCR;ESMCR;C:\WINDOWS\system32\DRIVERS\ESM7SK.sys
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2007-08-26 22:19:24 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2007-10-08 12:16:48
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-10-08 12:17:23
.
--- E O F ---