this is the log from combofix
ComboFix 08-03-08.2 - LOVE 2008-03-10 0:44:33.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.480 [GMT 11:00]
Running from: C:\Documents and Settings\LOVE\Desktop\ComboFix.exe
* Created a new restore point
[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
.
((((((((((((((((((((((((( Files Created from 2008-02-09 to 2008-03-09 )))))))))))))))))))))))))))))))
.
2008-02-27 20:52 . 2008-02-27 20:52 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-02-27 20:25 . 2008-02-27 18:47 691,545 --a------ C:\WINDOWS\unins000.exe
2008-02-27 20:25 . 2008-02-27 20:25 2,538 --a------ C:\WINDOWS\unins000.dat
2008-02-22 23:31 . 2008-02-27 18:30 <DIR> d-------- C:\Program Files\s300
2008-02-20 22:20 . 2008-02-20 22:21 <DIR> d-------- C:\Documents and Settings\LOVE\.assistant
2008-02-20 22:05 . 2008-02-20 22:05 <DIR> d-------- C:\Program Files\Common Files\Accelrys
2008-02-17 14:03 . 2008-02-17 14:03 <DIR> d-------- C:\Documents and Settings\LOVE\Application Data\Samsung
2008-02-17 14:02 . 2006-05-03 22:53 174,592 --a------ C:\WINDOWS\system32\framedyn.dll
2008-02-17 14:00 . 2006-07-24 16:05 5,632 --a------ C:\WINDOWS\system32\drivers\StarOpen.sys
2008-02-17 13:52 . 2005-12-22 12:24 137,884 --a------ C:\WINDOWS\system32\drivers\sscdmdm.sys
2008-02-17 13:52 . 2005-12-22 12:24 80,272 --a------ C:\WINDOWS\system32\drivers\sscdbus.sys
2008-02-17 13:52 . 2005-12-22 12:24 11,877 --a------ C:\WINDOWS\system32\drivers\sscdcmnt.sys
2008-02-17 13:52 . 2005-12-22 12:24 11,877 --a------ C:\WINDOWS\system32\drivers\sscdcm.sys
2008-02-17 13:52 . 2005-12-22 12:24 11,188 --a------ C:\WINDOWS\system32\drivers\sscdwhnt.sys
2008-02-17 13:52 . 2005-12-22 12:24 11,188 --a------ C:\WINDOWS\system32\drivers\sscdwh.sys
2008-02-17 13:52 . 2005-12-22 12:24 10,864 --a------ C:\WINDOWS\system32\drivers\sscdmdfl.sys
2008-02-17 13:51 . 2008-02-17 14:01 <DIR> d-------- C:\WINDOWS\system32\Samsung_USB_Drivers
2008-02-17 13:51 . 2008-02-17 13:51 <DIR> d-------- C:\Program Files\Samsung
2008-02-17 13:51 . 2005-08-28 20:51 766 --a------ C:\WINDOWS\system32\Uninstall.ico
2008-02-12 22:11 . 2008-02-20 22:10 <DIR> d-------- C:\Documents and Settings\LOVE\Application Data\Accelrys
2008-02-12 22:09 . 2008-02-20 22:06 <DIR> d-------- C:\Program Files\Accelrys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-09 06:53 --------- d-----w C:\Documents and Settings\LOVE\Application Data\Azureus
2008-03-09 02:51 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-03-08 23:50 --------- d-----w C:\Documents and Settings\LOVE\Application Data\Internode
2008-03-07 20:13 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-03-07 04:00 --------- d-----w C:\Program Files\Norton Security Scan
2008-03-05 12:22 --------- d-----w C:\Program Files\Diablo II
2008-02-28 12:14 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-02-28 10:26 --------- d-----w C:\Program Files\Spyware Doctor
2008-02-27 10:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-26 10:31 --------- d-----w C:\Program Files\MSN Messenger
2008-02-26 10:31 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-02-25 03:36 3,532 ----a-w C:\drmHeader.bin
2008-02-24 02:34 --------- d-----w C:\Program Files\LimeWire
2008-02-17 03:00 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-15 06:55 --------- d-----w C:\Documents and Settings\LOVE\Application Data\Screenshot Sender
2008-02-13 05:36 --------- d-----w C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-02-01 21:49 --------- d-----w C:\Documents and Settings\LOVE\Application Data\Nokia Multimedia Player
2008-01-27 06:15 --------- d-----w C:\Program Files\Bethesda Softworks
2008-01-25 06:29 --------- d-----w C:\Program Files\DIGStream
2008-01-15 12:02 --------- d-----w C:\Program Files\StuffPlug3
2008-01-12 12:31 85,400 ----a-w C:\Documents and Settings\LOVE\Application Data\GDIPFONTCACHEV1.DAT
2008-01-11 05:53 44,544 ----a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
2008-01-09 21:09 4 --sh--r C:\WINOS.SYS
2007-12-19 23:01 347,136 ----a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll
2007-12-18 09:51 179,584 ------w C:\WINDOWS\system32\dllcache\mrxdav.sys
2007-04-21 14:00 24 ----a-w C:\Documents and Settings\LOVE\calib.dat
2005-05-12 05:36 12,288 ----a-w C:\WINDOWS\Fonts\RandFont.dll
2006-10-17 01:02 56 --sh--r C:\WINDOWS\system32\A5EFFC90CE.sys
2007-03-11 07:14 88 --sh--r C:\WINDOWS\system32\B001B7E055.sys
2006-05-03 09:06 163,328 --sh--r C:\WINDOWS\system32\flvDX.dll
2007-03-11 07:14 4,860 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
2007-02-21 10:47 31,232 --sh--r C:\WINDOWS\system32\msfDX.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ACD587E9-0E47-4CBE-ABCD-7DD20B86F310}]
2008-02-27 18:30 12800 --a------ C:\Program Files\s300\s300_1204097431.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Creative Detector"="C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-03 10:23 102400]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 21:00 15360]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
"InternodeUsage"="D:\MUM\INTERN~1\mum.exe" [2008-03-09 10:50 1334272]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 12:09 460784]
"ParetoLogic Anti-Spyware"="C:\Program Files\ParetoLogic\Anti-Spyware\Pareto_AS.exe" [2007-08-01 14:56 2643312]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-09-26 16:51 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-09-30 06:01 67584]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-12-29 03:55 667718]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-12-29 03:56 602182]
"SigmatelSysTrayApp"="stsystra.exe" [2006-03-25 08:30 282624 C:\WINDOWS\stsystra.exe]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-09 03:48 761947]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2005-08-13 06:43 45056]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-10 12:29 49152]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-11 02:44 249856]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-11 02:44 81920]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 04:43 83608]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-12-14 14:06 282624]
"MSKDetectorExe"="C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" [2006-11-08 07:49 1121280]
"avast!"="C:\DOCUME~1\LOVE\Desktop\Avast\NEWFOL~1\ashDisp.exe" [2007-12-05 00:00 79224]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-01-19 16:27 185896]
"NeroCheck"="C:\WINDOWS\system32\\NeroCheck.exe" [2001-07-09 21:50 155648]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-12 16:12 49152]
"PCSuiteTrayApplication"="C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.exe" [2006-06-15 13:36 229376]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
"Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2007-05-10 23:46 624248]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-02-09 09:23 29744]
"tempreg"="regsvr32 /s C:\Program Files\s300\s300_1204097431.dll" [ ]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.exe.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-03-10 14:06:58 113664]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-07-05 06:29:34 24576]
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-09-26 16:51:02 126136]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-12 16:23:26 282624]
HP Image Zone Fast Start.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2005-05-12 17:49:24 73728]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"D:\\Azureus\\Azureus.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Diablo II\\Diablo II\\Game_crk.exe"=
"C:\\Program Files\\Diablo II\\Game_crk.exe"=
"C:\\Program Files\\Sony\\Station\\LaunchPad\\LaunchPad.exe"=
"C:\\Program Files\\Diablo II\\Diablo II.exe"=
"D:\\Microsoft Games\\Age of Empires III\\age3.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
S3 AngelUsb;Angel USB MPEG Device;C:\WINDOWS\system32\DRIVERS\AngelUsb.sys [2006-02-04 11:25]
S3 GoogleDesktopManager-093007-112848;Google Desktop Manager 5.5.709.30344;"C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-02-09 09:23]
.
Contents of the 'Scheduled Tasks' folder
"2008-03-07 05:29:44 C:\WINDOWS\Tasks\Norton Security Scan.job"
- C:\Program Files\Norton Security Scan\Nss.exe
"2008-02-26 07:00:00 C:\WINDOWS\Tasks\Pareto UNS.job"
- C:\Program Files\Common Files\ParetoLogic\UUS\UUS.dll\Pareto_Update.exe
"2008-03-07 11:00:00 C:\WINDOWS\Tasks\ParetoLogic Anti-Spyware.job"
- C:\Program Files\ParetoLogic\Anti-Spyware\Pareto_AS.exe
"2007-12-12 21:48:06 C:\WINDOWS\Tasks\ParetoLogic Update.job"
- C:\Program Files\Common Files\ParetoLogic\UUS\Pareto_Update.exe
"2007-02-12 23:42:20 C:\WINDOWS\Tasks\XoftSpy.job"
- D:\Xoftspy\old\xOFTSPY\XoftSpy.exe
"2008-03-09 06:00:05 C:\WINDOWS\Tasks\XoftSpySE 2.job"
- D:\Xoftspy\XoftSpySE\XoftSpy.exe
"2008-03-04 10:03:58 C:\WINDOWS\Tasks\XoftSpySE.job"
- D:\Xoftspy\XoftSpySE\XoftSpy.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-10 00:48:10
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-03-10 0:48:55
.
2008-02-13 18:56:25 --- E O F ---