Here is the ComboFix:
- 2007-06-06 18:06:40 Service Pack 2 NTFS
ComboFix 07-06-3B - Running from: "C:\Documents and Settings\Desktop\"
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\Program Files\install.log
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\nm
((((((((((((((((((((((((( Files Created from 2007-05-06 to 2007-06-06 )))))))))))))))))))))))))))))))
2007-06-02 15:40 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2007-06-02 15:36 548,864 --a------ C:\WINDOWS\system32\CNQW30.DLL
2007-06-02 15:36 389,180 --a------ C:\WINDOWS\system32\UCS32P.DLL
2007-06-02 15:36 339,968 --a------ C:\WINDOWS\system32\N124UFW.DLL
2007-06-02 15:36 167,936 --a------ C:\WINDOWS\system32\N124WIMG.DLL
2007-06-02 14:54 <DIR> d--h----- C:\CanoScan
2007-05-30 21:44 <DIR> d-------- C:\WINDOWS\SHELLNEW
2007-05-30 21:38 <DIR> d-------- C:\Program Files\Microsoft ActiveSync
2007-05-27 10:05 <DIR> d-------- C:\Program Files\Mozilla Thunderbird
2007-05-26 18:41 <DIR> d-------- C:\DOCUME~1\CATHER~1\APPLIC~1\Thunderbird
2007-05-26 18:41 <DIR> d-------- C:\DOCUME~1\CATHER~1\APPLIC~1\Talkback
2007-05-22 17:29 <DIR> d-------- C:\DOCUME~1\CATHER~1\APPLIC~1\Skype
2007-05-22 17:27 <DIR> d-------- C:\Program Files\Skype
2007-05-22 17:27 <DIR> d-------- C:\Program Files\Common Files\Skype
2007-05-22 17:27 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skype
2007-05-15 14:35 90,112 --a------ C:\WINDOWS\unvise32.exe
2007-05-15 14:32 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\grey soft 1 beep
2007-05-15 14:31 <DIR> d-------- C:\Program Files\Trans Road
2007-05-15 14:31 <DIR> d-------- C:\DOCUME~1\CATHER~1\APPLIC~1\Trans Road
2007-05-15 14:28 <DIR> d-------- C:\DOCUME~1\CATHER~1\Shared
2007-05-15 14:28 <DIR> d-------- C:\DOCUME~1\CATHER~1\Incomplete
2007-05-15 14:27 <DIR> d-------- C:\DOCUME~1\CATHER~1\APPLIC~1\LimeWire
2007-05-15 09:57 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2007-05-15 09:56 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2007-05-12 10:56 <DIR> d-------- C:\DOCUME~1\CATHER~1\APPLIC~1\Google
2007-05-12 10:56 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
2007-05-11 18:18 28 --a------ C:\WINDOWS\popcinfo.dat
2007-05-11 18:17 96,256 --a------ C:\Program Files\UnGins.exe
2007-05-11 18:17 <DIR> d-------- C:\Program Files\Bejeweled
2007-05-11 18:17 <DIR> d-------- C:\Program Files\Alchemy
2007-05-09 23:16 <DIR> d-------- C:\WINDOWS\system32\IOSUBSYS
2007-05-09 23:16 <DIR> d-------- C:\Program Files\Picasa2
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
2007-06-02 18:45:34 5,741 ----a-w C:\WINDOWS\mozver.dat
2007-06-02 18:35:36 -------- d-----w C:\Program Files\EarthLink TotalAccess
2007-06-02 14:30:40 664 ----a-w C:\WINDOWS\system32\d3d9caps.dat
2007-05-31 01:38:23 -------- d-----w C:\Program Files\Common Files\L&H
2007-05-12 14

02 -------- d-----w C:\Program Files\Google
2007-05-10 19:27:59 -------- d--h--w C:\Program Files\InstallShield Installation Information
2007-05-10 02:57:55 -------- d-----w C:\Program Files\ReadPlease 2003
2007-05-10 02:57:45 -------- d-----w C:\Program Files\Quest Atlantis
2007-05-10 02:57:21 -------- d-----w C:\Program Files\Games
2007-05-10 02:55:15 -------- d-----w C:\Program Files\Vox Proxy
2007-05-10 02:54:45 -------- d-----w C:\Program Files\Look Media
2007-05-04 00:16:09 -------- d-----w C:\Program Files\iTunes
2007-05-04 00:15:55 -------- d-----w C:\Program Files\iPod
2007-05-04 00:14:55 -------- d-----w C:\Program Files\QuickTime
2007-05-04 00:11:19 -------- d-----w C:\Program Files\Apple Software Update
2007-05-03 03:15:11 -------- d-----w C:\DOCUME~1\CATHER~1\APPLIC~1\WebRD
2007-05-03 03:13:27 -------- d-----w C:\Program Files\ViaVoiceTTS
2007-05-03 03:12:16 -------- d-----w C:\Program Files\IBM
2007-05-03 02:05:45 37 ----a-w C:\WINDOWS\system32\KB043uts.dat
2007-05-03 01:38:00 -------- d-----w C:\Program Files\Dolphin
2007-05-03 01:26:01 -------- d-----w C:\Program Files\Deskshare
2007-05-03 01:15:52 6,688 ----a-w C:\WINDOWS\movexe.exe
2007-04-30 15:34:32 -------- d-----w C:\Program Files\Common Files\Scanner
2007-04-29 23:58:03 -------- d-----w C:\DOCUME~1\CATHER~1\APPLIC~1\Netscape
2007-04-29 21:17:50 -------- d-----w C:\Program Files\Netscape
2007-04-29 20:07:00 0 ----a-w C:\WINDOWS\nsreg.dat
2007-04-27 21:31:33 -------- d-----w C:\DOCUME~1\CATHER~1\APPLIC~1\SSH
2007-04-27 14:48:46 -------- d-----w C:\DOCUME~1\CATHER~1\APPLIC~1\ScamBlocker
2007-04-25 23

16 -------- d-----w C:\DOCUME~1\CATHER~1\APPLIC~1\Earthlink
2007-04-23 16:12:40 126,976 ----a-w C:\WINDOWS\system32\unzdll.dll
2007-04-23 16:12:37 -------- d-----w C:\Program Files\Gateway
2007-04-23 14:58:05 -------- d-----w C:\Program Files\Common Files\EarthLink
2007-04-21 17:18:12 -------- d-----w C:\DOCUME~1\CATHER~1\APPLIC~1\Sonic
2007-04-21 17:18:08 -------- d-----w C:\DOCUME~1\CATHER~1\APPLIC~1\Leadertech
2007-04-21 16:31:54 -------- d-----w C:\Program Files\Audacity
2007-04-17 02:47:36 33,624 ----a-w C:\WINDOWS\system32\wups.dll
2007-04-17 02:45:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-17 02:45:48 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-04-17 02:45:42 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-04-17 02:45:36 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-04-17 02:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-04-17 02:45:20 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-17 02:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
2007-04-15 02:49:38 -------- d-----w C:\DOCUME~1\CATHER~1\APPLIC~1\Inspiration Software
2007-04-04 04:16:12 11,759 ----a-w C:\WINDOWS\system32\nvModes.dat
2007-03-27 07:55:23 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2007-03-27 07:55:23 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2007-03-22 20:47:35 46,344 ----a-w C:\WINDOWS\NSSetDefaultBrowser.EXE
2007-03-21 01:28:14 552 ----a-w C:\WINDOWS\system32\d3d8caps.dat
2007-03-20 03:08:56 50,784 ----a-w C:\WINDOWS\system32\csvidcap.dll
2007-03-17 13:43:01 292,864 ----a-w C:\WINDOWS\system32\winsrv.dll
2007-03-13 15:20:57 417,792 ----a-w C:\WINDOWS\iwexec.exe
2007-03-08 15:36:28 577,536 ----a-w C:\WINDOWS\system32\user32.dll
2007-03-08 15:36:28 40,960 ----a-w C:\WINDOWS\system32\mf3216.dll
2007-03-08 15:36:28 281,600 ----a-w C:\WINDOWS\system32\gdi32.dll
2007-03-08 13:47:48 1,843,584 ----a-w C:\WINDOWS\system32\win32k.sys
2007-03-06 01:04:11 37,956 ----a-w C:\WINDOWS\system32\emptyregdb.dat
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\Browser Helper Objects]
{00000000-0000-0000-0000-000000000002}=C:\Program Files\EarthLink TotalAccess\Toolbar\EScamBlk.dll [2007-04-27 10:33]
{00C6482D-C502-44C8-8409-FCE54AD9C208}=C:\Program Files\TechSmith\SnagIt 7\SnagItBHO.dll [2004-10-01 08:12]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}=C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2004-12-14 02:56]
{15F4D456-5BAA-4076-8486-EECB38CD3E57}=C:\Program Files\EarthLink TotalAccess\Toolbar\EScamBlk.dll [2007-04-27 10:33]
{22BF413B-C6D2-4d91-82A9-A0F997BA588C}=C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2007-05-18 13:14]
{512ACF1B-64D9-4928-B382-A80556F28DB4}=C:\Program Files\EarthLink TotalAccess\Toolbar\ElnkPuB.dll [2007-04-27 10:33]
{53707962-6F74-2D53-2644-206D7942484F}=C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2004-05-12 02:03]
{5CA3D70E-1895-11CF-8E15-001234567890}=C:\WINDOWS\system32\dla\tfswshx.dll [2005-03-16 06:33]
{9579D574-D4D8-4335-9560-FE8641A013BD}=C:\Program Files\EarthLink TotalAccess\Toolbar\ProtctIE.dll [2007-04-27 10:33]
{AA58ED58-01DD-4d91-8333-CF10577473F7}=c:\program files\google\googletoolbar1.dll [2007-05-12 10:55]
{AE7CD045-E861-484f-8273-0445EE161910}=C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll [2004-12-14 03:13]
{E713904C-DF05-4C79-BBAD-02DB923253BE}=C:\Program Files\EarthLink TotalAccess\Toolbar\uninsttb.dll [2007-04-27 10:33]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\I SUSPM.exe" [2004-07-27 17:50]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2004-08-09 07:03]
"ShStatEXE"="C:\Program Files\Network Associates\VirusScan\SHSTAT.exe" [2003-09-29 08:10]
"McAfeeUpdaterUI"="C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" [2003-09-10 04:11]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-10-18 19:04]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-10-18 18:58]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2004-09-13 12:33]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe" [2005-04-13 03:48]
"MsmqIntCert"="regsvr32 /s mqrt.dll" []
"Acrobat Assistant 7.0"="C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2004-12-14 03:12]
"@"="" []
"Active Web Reader"="C:\Program Files\Deskshare\Active Web Reader\Active Web Reader.exe" []
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-04-27 11:25]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-05-12 10:54]
"1beepthatooze"="C:\Documents and Settings\All Users\Application Data\grey soft 1 beep\tray ref.exe" [2007-05-15 14:32]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 07:00]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\G oogleToolbarNotifier.exe" [2007-05-12 10:56]
"DateBook"="C:\DOCUME~1\CATHER~1\APPLIC~1\TRANSR~1 \newplay.exe" []
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2007-05-18 13:14]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\R oyale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale. theme
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~ 1.DLL
[HKEY_LOCAL_MACHINE\system\currentcontrolset\contro l\lsa]
Authentication Packages msv1_0 nwprovau
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs*
Contents of the 'Scheduled Tasks' folder
2007-05-31 18:46:00 C:\WINDOWS\tasks\AppleSoftwareUpdate.job
2007-06-06 23:00:00 C:\WINDOWS\tasks\B73E1BB691E58EAE.job
************************************************** ************************
catchme 0.3.692 W2K/XP/Vista - userland rootkit detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-06-06 19:18:09
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
Completion time: 2007-06-06 19:19:26 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-06-06 19:19
--- E O F ---