Here is a combofix log in advance:
ComboFix 08-01-05.8 - Todd 2008-01-05 11:03:30.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.381 [GMT -5:00]
Running from: C:\Users\Todd\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Windows\Downloaded Program Files\Temp
C:\Windows\system32\x64
.
((((((((((((((((((((((((( Files Created from 2007-12-05 to 2008-01-05 )))))))))))))))))))))))))))))))
.
2008-01-05 11:02 . 2000-08-31 08:00 51,200 --a------ C:\Windows\NirCmd.exe
2008-01-05 10:47 . 2008-01-05 10:47 <DIR> d-------- C:\Program Files\Trend Micro
2008-01-04 20:35 . 2008-01-04 20:35 107,888 --a------ C:\Windows\System32\CmdLineExt.dll
2008-01-01 16:08 . 2008-01-01 16:08 <DIR> dr-h----- C:\Users\Todd\AppData\Roaming\SecuROM
2008-01-01 16:06 . 2008-01-01 16:06 <DIR> d-------- C:\Program Files\Games A Go-Go
2007-12-25 19:09 . 2007-12-25 19:09 <DIR> d-------- C:\Users\Todd\AppData\Roaming\acccore
2007-12-25 19:07 . 2007-12-25 19:07 <DIR> d-------- C:\Users\All Users\Viewpoint
2007-12-25 19:07 . 2007-12-25 19:07 <DIR> d-------- C:\ProgramData\Viewpoint
2007-12-25 19:07 . 2007-12-25 19:08 <DIR> d-------- C:\Program Files\Viewpoint
2007-12-25 19:06 . 2007-12-25 19:10 <DIR> d-------- C:\Users\All Users\AOL OCP
2007-12-25 19:06 . 2007-12-25 19:06 <DIR> d-------- C:\Users\All Users\AOL
2007-12-25 19:06 . 2007-12-25 19:10 <DIR> d-------- C:\ProgramData\AOL OCP
2007-12-25 19:06 . 2007-12-25 19:06 <DIR> d-------- C:\ProgramData\AOL
2007-12-25 19:06 . 2007-12-25 19:06 <DIR> d-------- C:\Program Files\Common Files\AOL
2007-12-25 19:06 . 2007-12-25 19:09 <DIR> d-------- C:\Program Files\AIM6
2007-12-25 19:06 . 2007-12-25 19:09 430 --ah----- C:\IPH.PH
2007-12-25 09:22 . 2007-12-25 09:22 416 --a------ C:\Windows\MVPWORD.INI
2007-12-25 08:41 . 1999-05-07 07:24 244,232 --a------ C:\Windows\System32\msflxgrd.ocx
2007-12-25 08:39 . 1999-12-07 12:00 1,384,448 --a------ C:\Windows\System32\temp.007
2007-12-25 08:39 . 2000-01-05 15:10 614,672 --a------ C:\Windows\System32\temp.006
2007-12-25 08:39 . 2000-01-05 15:10 164,112 --a------ C:\Windows\System32\temp.005
2007-12-25 08:39 . 2000-01-05 15:10 143,632 --a------ C:\Windows\System32\temp.008
2007-12-25 08:39 . 2000-03-21 00:55 118,784 --a------ C:\Windows\System32\vbalNCSM6.dll
2007-12-25 08:39 . 1999-02-19 08:54 40,960 --a------ C:\Windows\System32\SSubTmr6.dll
2007-12-25 08:39 . 1998-05-31 00:00 22,288 --a------ C:\Windows\System32\temp.009
2007-12-25 08:39 . 2000-01-05 15:10 16,896 --a------ C:\Windows\System32\temp.004
2007-12-25 08:38 . 2007-12-25 21:53 <DIR> d-------- C:\Program Files\eGames
2007-12-25 08:38 . 1999-12-07 12:00 1,384,448 --a------ C:\Windows\System32\temp.003
2007-12-25 08:38 . 2000-01-05 15:10 614,672 --a------ C:\Windows\System32\temp.002
2007-12-25 08:38 . 2000-01-05 15:10 164,112 --a------ C:\Windows\System32\temp.001
2007-12-25 08:38 . 1999-03-25 23:00 101,888 --a------ C:\Windows\System32\Vb6stkit.dll
2007-12-25 08:38 . 2000-07-17 13:41 70,088 --a------ C:\Windows\System32\Project2-1.ocx
2007-12-25 08:38 . 2000-01-05 15:10 16,896 --a------ C:\Windows\System32\temp.000
2007-12-25 08:38 . 2000-03-21 15:37 1,760 --a------ C:\Windows\System32\objsafe.tlb
2007-12-25 08:38 . 2000-04-06 14:58 1,453 --a------ C:\Windows\System32\Project2.INF
2007-12-14 12:55 . 2007-12-14 12:55 <DIR> d-------- C:\Users\Todd\AppData\Roaming\Yahoo!
2007-12-14 12:54 . 2007-12-14 12:54 <DIR> d-------- C:\Windows\cache
2007-12-14 12:10 . 2007-12-14 12:10 <DIR> d-------- C:\Program Files\Common Files\Avery
2007-12-14 12:10 . 2007-12-14 12:16 <DIR> d-------- C:\Program Files\Avery Wizard 3.1
2007-12-13 08:59 . 2007-12-13 08:59 16,080 --a------ C:\Windows\System32\results.xml
2007-12-13 03:07 . 2007-12-13 03:07 1,327,104 --a------ C:\Windows\System32\quartz.dll
2007-12-13 03:06 . 2007-12-13 03:06 223,232 --a------ C:\Windows\System32\WMASF.DLL
2007-12-13 03:06 . 2007-12-13 03:06 9,728 --a------ C:\Windows\System32\LAPRXY.DLL
2007-12-13 03:06 . 2007-12-13 03:06 2,048 --a------ C:\Windows\System32\asferror.dll
2007-12-13 03:03 . 2007-12-13 03:03 3,504,824 --a------ C:\Windows\System32\ntkrnlpa.exe
2007-12-13 03:03 . 2007-12-13 03:03 3,470,520 --a------ C:\Windows\System32\ntoskrnl.exe
2007-12-13 03:02 . 2007-12-13 03:02 2,048 --a------ C:\Windows\System32\tzres.dll
2007-12-12 08:49 . 2007-12-12 08:49 <DIR> d-------- C:\Windows\System32\Lang
2007-12-12 08:49 . 2007-12-13 08:59 <DIR> d-------- C:\Intel
2007-12-09 19:23 . 2007-12-09 19:23 <DIR> d-------- C:\Users\All Users\WLInstaller
2007-12-09 19:23 . 2007-12-09 19:23 <DIR> d-------- C:\ProgramData\WLInstaller
2007-12-09 19:23 . 2007-12-09 19:23 <DIR> d-------- C:\Program Files\Windows Live
2007-12-09 19:23 . 2007-12-09 19:26 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-05 02:31 --------- d---a-w C:\ProgramData\TEMP
2008-01-02 16:38 --------- d-----w C:\ProgramData\GamesBar
2007-12-21 00:37 --------- d-----w C:\Program Files\Comcast Play Games
2007-12-18 09:21 --------- d-----w C:\Program Files\McAfee
2007-12-14 17:57 --------- d-----w C:\ProgramData\Yahoo! Companion
2007-12-14 17:13 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-14 17:09 --------- d-----w C:\Program Files\Common Files\InstallShield
2007-12-13 08:05 84,992 ----a-w C:\Windows\system32\drivers\srvnet.sys
2007-12-13 08:05 58,368 ----a-w C:\Windows\system32\drivers\mrxsmb20.sys
2007-12-13 08:05 56,320 ----a-w C:\Windows\System32\iesetup.dll
2007-12-13 08:05 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2007-12-13 08:05 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2007-12-13 08:05 130,048 ----a-w C:\Windows\system32\drivers\srv2.sys
2007-12-13 08:05 101,888 ----a-w C:\Windows\system32\drivers\mrxsmb.sys
2007-12-12 23:26 --------- d-----w C:\Users\Todd\AppData\Roaming\iWin
2007-12-06 22:52 --------- d-----w C:\Program Files\iWin Games
2007-12-02 21:18 --------- d-----w C:\ProgramData\PopCap Games
2007-11-20 00:59 --------- d-----w C:\Program Files\iWin.com
2007-11-19 23:25 --------- d-----w C:\Program Files\GamesBar
2007-11-19 23:25 --------- d-----w C:\Program Files\Common Files\Oberon Media
2007-11-18 08:01 1,244,672 ----a-w C:\Windows\System32\mcmde.dll
2007-11-14 21:36 704,000 ----a-w C:\Windows\System32\PhotoScreensaver.scr
2007-11-14 21:36 67,584 ----a-w C:\Windows\System32\wlanhlp.dll
2007-11-14 21:36 542,720 ----a-w C:\Windows\System32\sysmain.dll
2007-11-14 21:36 502,784 ----a-w C:\Windows\System32\wlansvc.dll
2007-11-14 21:36 47,104 ----a-w C:\Windows\System32\wlanapi.dll
2007-11-14 21:36 297,984 ----a-w C:\Windows\System32\wlansec.dll
2007-11-14 21:36 290,816 ----a-w C:\Windows\System32\wlanmsm.dll
2007-11-14 21:36 28,344 ----a-w C:\Windows\system32\drivers\battc.sys
2007-11-14 21:36 258,232 ----a-w C:\Windows\system32\drivers\acpi.sys
2007-11-14 21:36 24,064 ----a-w C:\Windows\System32\wtsapi32.dll
2007-11-14 21:36 20,920 ----a-w C:\Windows\system32\drivers\compbatt.sys
2007-11-14 21:36 2,923,520 ----a-w C:\Windows\explorer.exe
2007-11-14 21:36 2,027,008 ----a-w C:\Windows\System32\win32k.sys
2007-11-14 21:36 14,208 ----a-w C:\Windows\system32\drivers\CmBatt.sys
2007-11-14 21:36 11,264 ----a-w C:\Windows\system32\drivers\wmiacpi.sys
2007-11-14 20:31 8,704 ----a-w C:\Windows\System32\hcrstco.dll
2007-11-14 20:31 8,704 ----a-w C:\Windows\System32\hccoin.dll
2007-11-14 20:31 5,888 ----a-w C:\Windows\system32\drivers\usbd.sys
2007-11-14 20:31 38,400 ----a-w C:\Windows\system32\drivers\usbehci.sys
2007-11-14 20:31 23,040 ----a-w C:\Windows\system32\drivers\usbuhci.sys
2007-11-14 20:31 224,768 ----a-w C:\Windows\system32\drivers\usbport.sys
2007-11-14 20:31 192,000 ----a-w C:\Windows\system32\drivers\usbhub.sys
2007-11-14 20:31 --------- d-----w C:\Program Files\Windows Mail
2007-11-06 18:36 29,952 ----a-w C:\Windows\Help\OEM\scripts\HPScript.exe
2007-10-31 18:03 245,408 ----a-w C:\Windows\System32\unicows.dll
2007-10-19 13:10 21,760 ----a-w C:\Windows\Help\OEM\scripts\HCNetworkTest.exe
2007-10-13 23:58 8,147,968 ----a-w C:\Windows\System32\wmploc.DLL
2007-10-13 23:58 7,680 ----a-w C:\Windows\System32\spwmp.dll
2007-10-13 23:58 4,096 ----a-w C:\Windows\System32\dxmasf.dll
2007-10-13 23:58 356,864 ----a-w C:\Windows\System32\MediaMetadataHandler.dll
2007-10-13 23:55 84,480 ----a-w C:\Windows\System32\INETRES.dll
2007-10-13 23:55 737,792 ----a-w C:\Windows\System32\inetcomm.dll
2007-10-13 23:54 788,992 ----a-w C:\Windows\System32\rpcrt4.dll
2007-08-30 07:11 174 --sha-w C:\Program Files\desktop.ini
2007-08-09 00:42 956 ----a-w C:\Users\Todd\AppData\Roaming\wklnhst.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6F282B65-56BF-4BD1-A8B2-A4449A05863D}]
2007-06-19 10:09 380928 --a------ C:\Program Files\GamesBar\oberontb.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8CA5ED52-F3FB-4414-A105-2E3491156990}]
2007-02-13 11:58 78848 --a------ C:\PROGRA~1\IWINGA~1\IWINGA~1.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EF99BD32-C1FB-11D2-892F-0090271D4F88}
{6F282B65-56BF-4BD1-A8B2-A4449A05863D}
{2318C2B1-4965-11D4-9B18-009027A5CD4F}
{DE9C389F-3316-41A7-809B-AA305ED9D922}
[HKEY_CLASSES_ROOT\clsid\{6f282b65-56bf-4bd1-a8b2-a4449a05863d}]
[HKEY_CLASSES_ROOT\Oberontb.Band.1]
[HKEY_CLASSES_ROOT\TypeLib\{AD76633E-E50D-4844-9E7F-4DFBC7C18467}]
[HKEY_CLASSES_ROOT\Oberontb.Band]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2006-11-02 07:35 1196032]
"HPAdvisor"="C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2006-11-21 19:36 1474560]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2007-08-30 14:59 171448]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2007-12-18 14:04 50528]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 07:35 125440]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-04-15 07:39 1006264]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-15 00:02 815104]
"QPService"="C:\Program Files\HP\QuickPlay\QPService.exe" [2006-11-24 18:33 167936]
"HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-17 02:11 49152]
"QlbCtrl"="C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-11-06 13:58 159744]
"HP Health Check Scheduler"="C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2007-06-05 08:12 71176]
"WAWifiMessage"="C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2006-10-18 12:56 317152]
"hpWirelessAssistant"="C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2006-10-18 12:32 472800]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0\bin\jusched.exe" [2006-12-06 23:36 77824]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 18:51 39792]
"IgfxTray"="C:\Windows\system32\igfxtray.exe" [2007-02-26 18:54 131072]
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2007-02-26 18:54 151552]
"Persistence"="C:\Windows\system32\igfxpers.exe" [2007-02-26 18:54 126976]
"408809432"="C:\PROGRA~1\eGames\WORDIS~1\Register\EGAMES~1.exe" [2004-06-29 18:12 53322]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="%WINDIR%\SMINST\launcher.exe" [ ]
C:\Users\Todd\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 23:24:54]
TrueAssistant.lnk - C:\Program Files\TrueSwitchComcast\TrueWizard.exe [2007-07-02 04:16:26]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
HP Connections.lnk - C:\Program Files\HP Connections\6811507\Program\HP Connections.exe [2006-12-06 23:17:24]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=0 (0x0)
R2 XAudio;XAudio;C:\Windows\system32\DRIVERS\xaudio.sys [2006-08-04 12:39]
R3 igfx;igfx;C:\Windows\system32\DRIVERS\igdkmd32.sys [2007-02-26 18:54]
R3 NETw3v32;Intel® PRO/Wireless 3945ABG Adapter Driver for Windows Vista 32 Bit;C:\Windows\system32\DRIVERS\NETw3v32.sys [2006-11-09 04:02]
S3 BCM43XV;Broadcom Extensible 802.11 Network Adapter Driver;C:\Windows\system32\DRIVERS\bcmwl6.sys [2006-11-02 02:30]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalSystemNetworkRestricted REG_MULTI_SZ hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc EMDMgmt TabletInputService wlansvc WPDBusEnum
bthsvcs REG_MULTI_SZ BthServ
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3e22ce3b-bda4-11db-b994-806e6f6e6963}]
\shell\AutoRun\command - E:\Setup.exe
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder
"2007-07-18 20:01:16 C:\Windows\Tasks\McDefragTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe'
"2007-07-18 20:01:16 C:\Windows\Tasks\McQcTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe
"2008-01-04 19:51:32 C:\Windows\Tasks\User_Feed_Synchronization-{A1F043E3-32A8-482F-83B3-A5E3EDE190BD}.job"
- C:\Windows\system32\msfeedssync.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-01-05 11:09:21
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-05 11:10:29
.
2008-01-04 01:06:36 --- E O F ---