Here's the log for Combofix:
PART 1
ComboFix 09-07-01.04 - HP_Owner 07/02/2009 14:38.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1470.1133 [GMT -4:00]
Running from: c:\documents and settings\HP_Owner\Desktop\ComboFix.exe
FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\16553434
c:\documents and settings\All Users\Application Data\16553434\16553434
c:\documents and settings\All Users\Application Data\16553434\16553434.exe
c:\documents and settings\HP_Owner\Application Data\WeatherDPA
c:\documents and settings\HP_Owner\Application Data\WeatherDPA\Weather\WeatherStartup.xml
c:\documents and settings\HP_Owner\Local Settings\Application Data\{A6B4328E-BACD-4443-8BA0-21674ED05918}
c:\documents and settings\HP_Owner\Local Settings\Application Data\{A6B4328E-BACD-4443-8BA0-21674ED05918}\chrome.manifest
c:\documents and settings\HP_Owner\Local Settings\Application Data\{A6B4328E-BACD-4443-8BA0-21674ED05918}\chrome\content\_cfg.js
c:\documents and settings\HP_Owner\Local Settings\Application Data\{A6B4328E-BACD-4443-8BA0-21674ED05918}\chrome\content\c.js
c:\documents and settings\HP_Owner\Local Settings\Application Data\{A6B4328E-BACD-4443-8BA0-21674ED05918}\chrome\content\overlay.xul
c:\documents and settings\HP_Owner\Local Settings\Application Data\{A6B4328E-BACD-4443-8BA0-21674ED05918}\install.rdf
c:\documents and settings\LocalService\Application Data\twain_32
c:\documents and settings\LocalService\Application Data\twain_32\user.ds
c:\documents and settings\NetworkService\Application Data\twain_32
c:\documents and settings\NetworkService\Application Data\twain_32\user.ds
c:\program files\Mozilla Firefox\plugins\npclntax_ZangoSA.dll
c:\windows\system32\config\systemprofile\Desktop\System Security 2009.lnk
c:\windows\system32\config\systemprofile\Start Menu\Programs\System Security
c:\windows\system32\config\systemprofile\Start Menu\Programs\System Security\System Security
c:\windows\system32\drivers\hjgruimtabfmwg.sys
c:\windows\system32\hjgruibjoqhxnq.dll
c:\windows\system32\hjgruijobqdcbn.dat
c:\windows\system32\hjgruirctwhatd.dat
c:\windows\system32\hjgruirtiwthqp.dll
c:\windows\system32\uniq.tll
c:\windows\wiaserviv.log
D:\Autorun.inf
D:\Desktop.ini
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_hjgruitconqdxu
((((((((((((((((((((((((( Files Created from 2009-06-02 to 2009-07-02 )))))))))))))))))))))))))))))))
.
2009-07-02 17:22 . 2009-07-02 17:22 -------- d-----w- c:\program files\Trend Micro
2009-07-02 16:27 . 2009-07-02 16:27 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-07-02 15:55 . 2009-07-02 15:55 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2009-06-17 17:39 . 2009-05-19 05:36 2884832 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4426\vwpt.exe
2009-06-17 17:26 . 2006-10-12 16:29 83504 ----a-w- c:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_BBC2683C\TEMP\ProgUpd.dll
2009-06-13 13:51 . 2009-03-19 14:42 217088 ----a-w- c:\documents and settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\qf78i5qp.default\extensions\NPDyyno@dyyno.com\Plugins\npDyyno.dll
2009-06-11 22:29 . 2009-06-11 22:29 41808 ----a-w- c:\windows\system32\xfcodec.dll
2009-06-06 16:05 . 2009-06-06 16:05 120088 ----a-w- c:\documents and settings\HP_Owner\Application Data\Mozilla\Plugins\npoctoshape.dll
2009-06-06 16:05 . 2009-06-06 16:05 -------- d-----w- c:\documents and settings\HP_Owner\Application Data\Octoshape
2009-06-06 16:05 . 2009-06-04 10:03 396288 ----a-w- c:\documents and settings\HP_Owner\Application Data\Octoshape\Octoshape Streaming Services\sua-0906040-0-libOctoshapeClient.dll
2009-06-06 16:05 . 2009-06-04 10:03 124184 ----a-w- c:\documents and settings\HP_Owner\Application Data\Octoshape\Octoshape Streaming Services\sua-0906040-0-apoctoshape.dll
2009-06-06 16:05 . 2009-06-04 10:03 120088 ----a-w- c:\documents and settings\HP_Owner\Application Data\Octoshape\Octoshape Streaming Services\sua-0906040-0-npoctoshape.dll
2009-06-06 16:05 . 2009-01-08 13:44 70936 ----a-w- c:\documents and settings\HP_Owner\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe
2009-06-05 18:15 . 2009-06-05 18:15 29696 ----a-r- c:\documents and settings\HP_Owner\Application Data\Microsoft\Installer\{312255E7-E2C2-4F3E-BBCB-02C5B8696CCB}\IconF0CEFCC9.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-02 17:45 . 2009-05-27 10:31 1324 ----a-w- c:\windows\system32\d3d9caps.dat
2009-07-02 17:34 . 2009-02-19 00:53 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-07-02 14:56 . 2009-03-03 22:42 -------- d-----w- c:\program files\Xfire
2009-06-30 17:42 . 2009-03-03 22:42 -------- d-----w- c:\documents and settings\HP_Owner\Application Data\Xfire
2009-06-29 03:03 . 2007-12-25 01:11 -------- d-----w- c:\program files\Common Files\Blizzard Entertainment
2009-06-29 03:01 . 2008-09-15 20:15 -------- d-----w- c:\program files\World of Warcraft Public Test
2009-06-17 18:44 . 2008-08-16 04:09 -------- d-----w- c:\program files\AIM6
2009-06-17 17:39 . 2008-08-16 04:23 -------- d-----w- c:\documents and settings\All Users\Application Data\AOL Downloads
2009-06-17 15:27 . 2009-02-19 00:53 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-17 15:27 . 2009-02-19 00:53 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-12 10:36 . 2008-01-05 05:36 -------- d-----w- c:\documents and settings\HP_Owner\Application Data\LimeWire
2009-06-11 02:48 . 2008-11-05 01:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-06-07 01:18 . 2008-07-15 21:35 -------- d-----w- c:\program files\World of Warcraft
2009-06-05 01:48 . 2009-05-29 18:00 29696 ----a-r- c:\documents and settings\HP_Owner\Application Data\Microsoft\Installer\{BBB08B2B-F1F7-43BF-803F-AA3AA807E9FF}\IconF0CEFCC9.exe
2009-06-05 01:48 . 2009-05-29 17:57 -------- d-----w- c:\program files\Verizon
2009-06-03 00:17 . 2008-09-04 23:36 -------- d-----w- c:\documents and settings\HP_Owner\Application Data\U3
2009-05-29 18:10 . 2009-05-29 18:00 -------- d-----w- c:\documents and settings\All Users\Application Data\Motive
2009-05-29 18:05 . 2009-05-29 18:05 -------- d-----w- c:\documents and settings\HP_Owner\Application Data\Motive
2009-05-29 18:03 . 2009-05-29 18:00 -------- d-----w- c:\program files\Common Files\Motive
2009-05-27 10:31 . 2009-05-27 10:31 552 ----a-w- c:\windows\system32\d3d8caps.dat
2009-05-20 23:53 . 2009-05-20 23:26 -------- d-----w- c:\program files\Flash-Creator 1
2009-05-20 23:52 . 2009-05-20 23:26 75264 ----a-w- c:\windows\cadkasdeinst01e.exe
2009-05-20 23:47 . 2009-05-20 23:46 -------- d-----w- c:\program files\UltraSlideshow
2009-05-20 23:42 . 2009-05-20 23:38 -------- d-----w- c:\documents and settings\HP_Owner\Application Data\Download Manager
2009-05-19 05:36 . 2009-06-17 17:39 28 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4426\unregister.bat
2009-05-19 05:36 . 2009-06-17 17:39 25 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4426\register.bat
2009-05-19 05:36 . 2009-06-17 17:39 1484856 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4426\toolbar.exe
2009-05-19 05:36 . 2009-06-17 17:39 97072 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4426\bsetutil.exe
2009-05-19 05:36 . 2009-06-17 17:39 142040 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4426\alsetup.exe
2009-05-19 05:36 . 2009-06-17 17:39 30512 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4426\Uninstaller.exe
2009-05-19 05:36 . 2009-06-17 17:39 111920 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4426\AOLSearch.dll
2009-05-17 02:47 . 2009-05-17 02:47 -------- d-----w- c:\documents and settings\HP_Owner\Application Data\eMusic
2009-05-17 02:47 . 2009-05-17 02:47 -------- d-----w- c:\program files\eMusic Download Manager
2009-05-13 13:18 . 2009-04-22 17:30 77312 ----a-w- c:\windows\DEVCON.EXE
2009-05-09 14:57 . 2009-04-08 19:38 0 ----a-w- c:\windows\Mdekuqoqepoqu.bin
2009-05-07 15:32 . 2004-08-04 04:00 345600 ----a-w- c:\windows\system32\localspl.dll
2009-05-06 18:27 . 2009-05-06 18:26 -------- d-----w- c:\program files\Coupons
2009-04-29 04:56 . 2004-08-04 04:00 827392 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:55 . 2004-08-04 04:00 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-04-22 02:50 . 2009-04-22 01:07 117390 ----a-w- c:\windows\hpoins11.dat
2009-04-22 02:45 . 2007-12-25 01:19 57224 ----a-w- c:\documents and settings\HP_Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-17 12:26 . 2004-08-04 04:00 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-04-16 16:37 . 2009-04-08 19:38 408 ----a-w- c:\windows\Utodomuyixusumo.dat
2009-04-15 14:51 . 2004-08-04 04:00 585216 ----a-w- c:\windows\system32\rpcrt4.dll
2009-04-09 02:03 . 2009-04-09 02:03 81920 ----a-w- c:\documents and settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
2009-04-09 02:03 . 2009-04-09 02:03 98304 ----a-w- c:\documents and settings\All Users\Application Data\NexonUS\NGM\nxgameus.dll
2009-04-09 02:03 . 2009-04-09 02:03 520192 ----a-w- c:\documents and settings\All Users\Application Data\NexonUS\NGM\NGMDll.dll
2009-04-09 02:03 . 2009-04-09 02:03 335872 ----a-w- c:\documents and settings\All Users\Application Data\NexonUS\NGM\NGMResource.dll
2009-04-09 02:03 . 2009-04-09 02:03 258352 ----a-w- c:\documents and settings\All Users\Application Data\NexonUS\NGM\unicows.dll
2009-04-09 02:03 . 2009-04-09 02:03 167936 ----a-w- c:\documents and settings\All Users\Application Data\NexonUS\NGM\NGM.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-05-31 68856]
"Octoshape Streaming Services"="c:\documents and settings\HP_Owner\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe" [2009-01-08 70936]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HPHUPD08"="c:\program files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-01 49152]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2005-07-22 237568]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-11-09 249856]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 36975]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2006-04-05 344064]
"KBD"="c:\hp\KBD\KBD.EXE" [2005-02-02 61440]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-11-07 111936]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-10-31 185872]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-11-04 413696]
"Verizon_McciTrayApp"="c:\program files\Verizon\McciTrayApp.exe" [2009-03-10 1553920]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" - c:\windows\system32\narrator.exe [2008-04-14 53760]
c:\documents and settings\Default User\Start Menu\Programs\Startup\
Pin.lnk - c:\hp\bin\CLOAKER.EXE [2006-2-15 27136]
c:\documents and settings\Administrator\Start Menu\Programs\Startup\
Pin.lnk - c:\hp\bin\CLOAKER.EXE [2006-2-15 27136]
c:\documents and settings\HP_Owner\Start Menu\Programs\Startup\
Xfire.lnk - c:\program files\Xfire\Xfire.exe [2009-6-11 3182928]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472]
HP Photosmart Premier Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2006-2-10 73728]
Updates From HP.lnk - c:\program files\Updates from HP\9972322\Program\Updates from HP.exe [2006-2-16 36903]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"c:\\Program Files\\HP\\HP Software Update\\HPWUCli.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\World of Warcraft Public Test2\\Launcher.exe"=
"c:\\Documents and Settings\\HP_Owner\\Local Settings\\Application Data\\Dyyno Receiver\\DPPM.exe"=
"c:\\Program Files\\Xfire\\Xfire.exe"=
"c:\\Documents and Settings\\HP_Owner\\Application Data\\Macromedia\\Flash Player\\
www.macromedia.com\\bin\\octoshape\\octoshape.exe"="c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\Program Files\\Tortun\\gui.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\nexon\Combat Arms\CombatArms.exe"= c:\nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe
"c:\nexon\Combat Arms\Engine.exe"= c:\nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe
"c:\\Nexon\\Combat Arms\\NMService.exe"=