This is the last part
2009-05-31 17:36 . 2006-02-17 00:08 65536 ----a-w- c:\windows\system32\Planet Quest.dll
2009-05-31 17:36 . 2005-01-11 02:51 40960 ----a-w- c:\windows\system32\Planet Quest.scr
2009-05-26 05:23 . 2001-08-17 19:12 23070 -c--a-w- c:\windows\system32\dllcache\rtl8139.sys
2009-05-26 05:23 . 2001-08-17 19:12 23070 ----a-w- c:\windows\system32\drivers\RTL8139.sys
2009-05-26 05:18 . 2009-05-26 05:18 -------- d--h--w- C:\$AVG8.VAULT$
2009-05-25 15:35 . 2003-04-26 07:08 152576 ----a-w- c:\documents and settings\admin\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-05-21 01:01 . 2009-05-21 01:01 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-06 05:08 . 2008-11-29 05:45 -------- d-----w- c:\program files\BitComet
2009-06-06 03:24 . 2003-04-26 07:23 -------- d-----w- c:\documents and settings\All Users\Application Data\Avg7
2009-06-05 17:48 . 2003-04-27 03:41 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-06-05 17:06 . 2009-01-18 19:48 -------- d-----w- c:\documents and settings\admin\Application Data\GetRightToGo
2009-05-27 02:27 . 2008-12-23 01:40 -------- d-----w- c:\program files\Common Files\Adobe
2009-05-06 23:00 . 2009-05-06 23:00 -------- d-----w- c:\documents and settings\admin\Application Data\vlc
2009-05-06 22:56 . 2009-05-06 22:56 -------- d-----w- c:\documents and settings\admin\Application Data\dvdcss
2009-05-01 00:48 . 2008-11-15 18:36 42168 ----a-w- c:\documents and settings\Zara\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-29 03:48 . 2009-04-29 03:48 -------- d-----w- c:\program files\Activision
2009-04-28 22:50 . 2009-04-28 22:50 -------- d-----w- c:\documents and settings\admin\Application Data\The Creative Assembly
2009-04-28 01:16 . 2009-04-28 01:16 42168 ----a-w- c:\documents and settings\admin\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-25 18:26 . 2008-12-21 18:59 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo!
2009-04-25 18:26 . 2008-12-21 18:59 -------- d-----w- c:\program files\Yahoo!
2009-04-25 18:25 . 2009-02-20 01:42 -------- d-----w- c:\program files\Common Files\AVSMedia
2009-04-25 18:25 . 2009-02-20 01:42 -------- d-----w- c:\program files\AVS4YOU
2009-04-20 03:03 . 2009-04-20 03:03 -------- d-----w- c:\program files\Dell AIO Printer A920
2009-04-20 03:03 . 2009-04-20 03:03 -------- d-----w- c:\program files\Dell A920
2009-04-18 14:59 . 2009-01-11 17:48 34 ----a-w- c:\documents and settings\Zara\jagex_runescape_preferences.dat
2009-04-09 18:19 . 2008-11-15 06:16 -------- d-----w- c:\documents and settings\Zara\Application Data\dvdcss
2009-03-25 01:33 . 2009-03-25 01:33 237264 ----a-w- c:\documents and settings\Zara\Application Data\Mozilla\plugins\npgoogletalk.dll
2009-01-01 18:16 . 2009-01-01 18:16 181760 ----a-w- c:\program files\Common Files\Ndm353a2rL.exe
2009-01-01 18:16 . 2009-01-01 18:16 110592 ----a-w- c:\program files\Common Files\dRp6PJ53WU.exe
2004-04-19 09:54 . 2007-09-17 18:23 139264 ----a-w- c:\program files\MSI20Wiz.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"Dell AIO Printer A920"="c:\program files\Dell AIO Printer A920\dlbkbmgr.exe" [2003-05-12 270336]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2006-10-22 7700480]
"NvMediaCenter"="c:\windows\System32\NvMcTray.dll" [2006-10-22 86016]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-28 35696]
"PCTVOICE"="pctspk.exe" - c:\windows\system32\pctspk.exe [2002-06-05 167936]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2006-10-22 1622016]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
office.exe [2009-4-26 24455]
SMC2802W 54 Mbps WLAN Utility.lnk - c:\program files\SMC\SMC2802W 54 Mbps WLAN Utility\SMCUTIL.exe [2008-11-10 557056]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableChangePassword"= 1 (0x1)
"DisableLockWorkstation"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
S0 xvjc;xvjc;c:\windows\System32\drivers\qtnqh.sys --> c:\windows\System32\drivers\qtnqh.sys [?]
S3 Bulk503;Chameleon Mega Digital Camera;c:\windows\system32\drivers\Bulk503.sys [10/15/2001 12:45 PM 10599]
S3 ISO503;Chameleon Mega Video Camera;c:\windows\system32\drivers\ISO503.SYS [4/9/2002 10:49 AM 526885]
S3 PRISM_ICB;SMC2802W 2.4GHz 54Mbps Wireless PCI Card;c:\windows\system32\drivers\smc2802w.sys [11/10/2008 5:26 AM 57752]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - FUQKVEIT
*Deregistered* - fuqkveit
.
Contents of the 'Scheduled Tasks' folder
2009-05-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1004336348-484763869-1060284298-1004.job
- c:\documents and settings\Zara\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-11-13 00:09]
2009-06-03 c:\windows\Tasks\NSSstub.job
- c:\windows\System32\Adobe\Shockwave 11\nssstub.exe [2008-12-07 18:36]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-SNM - c:\program files\SpyNoMore\SNM.exe
HKLM-Run-Cmaudio - cmicnfg.cpl
SafeBoot-procexp90.Sys
SafeBoot-Winqv26.sys
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.google.com/mStart Page =
hxxp://www.yahoo.comuSearchURL,(Default) =
hxxp://www.google.com/search?q=%sIE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: {{c95fe080-8f5d-11d2-a20b-00aa003c157a} - %SystemRoot%\web\related.htm
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
DPF: DirectAnimation Java Classes -
file://c:\windows\Java\classes\dajava.cabDPF: Microsoft XML Parser for Java -
file://c:\windows\Java\classes\xmldso.cabDPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} -
hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cabFF - ProfilePath - c:\documents and settings\admin\Application Data\Mozilla\Firefox\Profiles\ujihy2ny.default\
FF - prefs.js: browser.search.defaulturl -
hxxp://www10.yoog.com/search.php?q=FF - prefs.js: browser.search.selectedEngine - Yoog Search
FF - prefs.js: browser.startup.homepage -
hxxp://google.comFF - prefs.js: keyword.URL -
hxxp://www10.yoog.com/search.php?q=FF - component: c:\documents and settings\admin\Application Data\Mozilla\Firefox\Profiles\ujihy2ny.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
FF - plugin: c:\program files\javasoft\jre1.4\1.4.2\bin\NPJava11.dll
FF - plugin: c:\program files\javasoft\jre1.4\1.4.2\bin\NPJava12.dll
FF - plugin: c:\program files\javasoft\jre1.4\1.4.2\bin\NPJava13.dll
FF - plugin: c:\program files\javasoft\jre1.4\1.4.2\bin\NPJava14.dll
FF - plugin: c:\program files\javasoft\jre1.4\1.4.2\bin\NPJava32.dll
FF - plugin: c:\program files\javasoft\jre1.4\1.4.2\bin\NPJPI142.dll
FF - plugin: c:\program files\javasoft\jre1.4\1.4.2\bin\NPOJI610.dll
---- FIREFOX POLICIES ----
FF - user.js: browser.search.selectedEngine - Yoog Search
FF - user.js: keyword.URL -
hxxp://www10.yoog.com/search.php?q=FF - user.js: keyword.enabled - true
FF - user.js: browser.search.defaultenginename - Yoog Search
FF - user.js: browser.search.defaulturl -
hxxp://www10.yoog.com/search.php?q=.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-06-05 22:42
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(536)
c:\windows\system32\ODBC32.dll
- - - - - - - > 'lsass.exe'(592)
c:\windows\System32\dssenh.dll
- - - - - - - > 'explorer.exe'(3224)
c:\progra~1\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
c:\progra~1\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\System32\mlang.dll
c:\windows\System32\msimtf.dll
c:\windows\System32\MSCTF.dll
c:\windows\System32\MSLS31.DLL
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\windows\system32\nvsvc32.exe
c:\windows\system32\rundll32.exe
c:\program files\Dell AIO Printer A920\dlbkbmon.exe
.
**************************************************************************
.
Completion time: 2009-06-06 22:47 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-06 05:47
Pre-Run: 4,926,259,200 bytes free
Post-Run: 8,966,873,088 bytes free
946 --- E O F --- 2009-06-05 14:45