thanks for the reply..
here's the combofix log..
ComboFix 08-09-05.02 - Neil 2008-09-06 10:36:36.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.875 [GMT 8:00]
Running from: C:\Users\Neil\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
C:\DRV\TVtuner\Liteon\Resources\_desktop.ini
D:\Autorun.inf
D:\install.exe
.
((((((((((((((((((((((((( Files Created from 2008-08-06 to 2008-09-06 )))))))))))))))))))))))))))))))
.
2008-09-06 10:13 . 2008-09-06 10:13 <DIR> d-------- C:\Program Files\Trend Micro
2008-09-04 20:13 . 2008-07-19 13:09 1,811,656 --a------ C:\Windows\System32\wuaueng.dll
2008-09-04 20:13 . 2008-07-19 11:44 1,524,736 --a------ C:\Windows\System32\wucltux.dll
2008-09-04 20:13 . 2008-07-19 13:09 563,912 --a------ C:\Windows\System32\wuapi.dll
2008-09-04 20:13 . 2008-07-19 11:44 83,456 --a------ C:\Windows\System32\wudriver.dll
2008-09-04 20:13 . 2008-07-19 13:10 53,448 --a------ C:\Windows\System32\wuauclt.exe
2008-09-04 20:13 . 2008-07-19 13:10 45,768 --a------ C:\Windows\System32\wups2.dll
2008-09-04 20:13 . 2008-07-19 13:10 36,552 --a------ C:\Windows\System32\wups.dll
2008-09-04 20:12 . 2008-07-18 22:08 163,904 --a------ C:\Windows\System32\wuwebv.dll
2008-09-04 20:12 . 2008-07-18 20:44 31,232 --a------ C:\Windows\System32\wuapp.exe
2008-09-04 17:59 . 2008-09-04 17:59 <DIR> d-------- C:\Program Files\LitexMedia
2008-09-04 16:31 . 2008-09-04 16:31 <DIR> d-------- C:\Program Files\Common Files\Logitech
2008-09-04 16:29 . 2008-09-04 16:29 <DIR> d-------- C:\Users\All Users\LogiShrd
2008-09-04 16:29 . 2008-09-04 16:29 <DIR> d-------- C:\ProgramData\LogiShrd
2008-09-02 01:29 . 2008-09-02 01:29 <DIR> d-------- C:\NVIDIA
2008-08-29 14:54 . 2001-12-19 11:45 8,576 --a------ C:\Windows\System32\drivers\VCdRom.sys
2008-08-29 13:12 . 2008-08-29 15:19 <DIR> d-------- C:\Westwood
2008-08-23 00:32 . 2008-08-23 00:32 <DIR> d-------- C:\Program Files\HD Tune
2008-08-18 06:15 . 2008-08-18 06:15 921,600 --a------ C:\Windows\System32\drivers\athr.sys
2008-08-16 19:18 . 2008-08-16 19:24 <DIR> d--h----- C:\msdownld.tmp
2008-08-16 12:25 . 2008-07-16 09:32 2,048 --a------ C:\Windows\System32\tzres.dll
2008-08-16 12:08 . 2008-06-19 11:31 361,984 --a------ C:\Windows\System32\IPSECSVC.DLL
2008-08-16 12:01 . 2008-04-18 13:48 269,312 --a------ C:\Windows\System32\es.dll
2008-08-16 11:56 . 2008-06-27 09:55 1,383,424 --a------ C:\Windows\System32\mshtml.tlb
2008-08-16 11:56 . 2008-06-27 12:15 827,392 --a------ C:\Windows\System32\wininet.dll
2008-08-16 11:53 . 2008-04-10 13:12 738,304 --a------ C:\Windows\System32\inetcomm.dll
2008-08-16 03:50 . 2008-08-20 00:41 39 --a------ C:\Windows\vbaddin.ini
2008-08-16 03:49 . 2008-08-16 03:49 <DIR> d-------- C:\Windows\PCHEALTH
2008-08-16 03:49 . 2008-08-16 03:49 <DIR> d-------- C:\Program Files\Microsoft.NET
2008-08-16 03:49 . 2008-08-16 03:49 <DIR> d-------- C:\Program Files\Microsoft Works
2008-08-16 03:46 . 2008-08-16 03:46 <DIR> dr-h----- C:\MSOCache
2008-08-16 03:41 . 2008-08-20 00:41 <DIR> d-------- C:\Users\All Users\Microsoft Help
2008-08-16 03:41 . 2008-08-20 00:41 <DIR> d-------- C:\ProgramData\Microsoft Help
2008-08-13 12:14 . 2008-08-13 12:14 <DIR> d-------- C:\Program Files\TV Expert
2008-08-13 09:39 . 2007-09-14 04:00 466,944 -ra------ C:\Windows\6000RMT.exe
2008-08-13 09:38 . 2008-08-13 11:43 <DIR> d-------- C:\Windows\MyInstall
2008-08-13 09:38 . 2007-12-25 04:00 230,528 --a------ C:\Windows\System32\drivers\TridVid.sys
2008-08-09 09:45 . 2008-08-09 09:48 3,652 --a------ C:\Windows\desctemp.dat
2008-08-07 14:21 . 2008-08-07 14:21 <DIR> d-------- C:\SAVE
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-06 02:29 --------- d---a-w C:\ProgramData\TEMP
2008-09-04 08:31 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-09-04 08:26 97,928 ----a-w C:\Windows\system32\drivers\avgldx86.sys
2008-08-26 07:00 --------- d-----w C:\Users\Neil\AppData\Roaming\LimeWire
2008-08-26 06:58 31,776 ----a-w C:\Users\All Users\nvModes.dat
2008-08-26 06:58 31,776 ----a-w C:\ProgramData\nvModes.dat
2008-08-25 21:52 --------- d-----w C:\Program Files\Java
2008-08-20 22:07 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-08-19 20:04 55,408 ----a-w C:\Users\Neil\AppData\Roaming\GDIPFONTCACHEV1.DAT
2008-08-16 04:22 --------- d-----w C:\Program Files\Windows Mail
2008-08-05 15:52 --------- d-----w C:\ProgramData\Symantec
2008-07-31 00:42 23,888 ----a-w C:\Windows\system32\drivers\COH_Mon.sys
2008-07-31 00:28 706 ----a-w C:\Windows\system32\drivers\COH_Mon.inf
2008-07-31 00:28 10,537 ----a-w C:\Windows\system32\drivers\COH_Mon.cat
2008-07-29 14:33 --------- d-----w C:\Program Files\Norton Internet Security
2008-07-24 22:58 --------- d-----w C:\ProgramData\Bluetooth
2008-07-24 22:49 --------- d-----w C:\Program Files\IVT Corporation
2008-07-23 19:19 --------- d-----w C:\ProgramData\McAfee
2008-07-23 04:55 --------- d-----w C:\Program Files\Bluesoleil
2008-07-21 11:58 --------- d-----w C:\Program Files\PC Wizard 2008
2008-07-20 05:23 --------- d-----w C:\ProgramData\NVIDIA
2008-07-20 03:39 --------- d-----w C:\Program Files\LimeWire
2008-07-19 14:14 --------- d-----w C:\Program Files\NeoSmart Technologies
2008-07-18 07:29 --------- d-----w C:\Program Files\GameHouse
2008-07-17 00:03 22,328 ----a-w C:\Windows\system32\drivers\PnkBstrK.sys
2008-07-17 00:03 103,736 ----a-w C:\Windows\System32\PnkBstrB.exe
2008-07-15 19:30 --------- d-----w C:\Program Files\MythWar_en
2008-07-09 03:37 6,923 ----a-w C:\Program Files\install.log
2008-07-09 03:37 --------- d-----w C:\ProgramData\Gamespot
2008-07-09 02:12 66,872 ----a-w C:\Windows\System32\PnkBstrA.exe
2008-07-09 01:44 --------- d-----w C:\Program Files\Electronic Arts
2008-07-07 18:48 --------- d-----w C:\Program Files\Common Files\SWF Studio
2008-07-03 16:45 10,520 ----a-w C:\Windows\System32\avgrsstx.dll
2008-06-26 03:29 801,280 ----a-w C:\Windows\System32\NaturalLanguage6.dll
2008-06-26 01:45 2,644,480 ----a-w C:\Windows\System32\NlsLexicons0009.dll
2008-06-26 01:45 12,240,896 ----a-w C:\Windows\System32\NlsLexicons0007.dll
2008-06-22 18:49 284,158,677 ----a-w C:\Windows\DUMP479a.tmp
2008-06-17 00:13 27,240 ----a-w C:\Users\Neil\AppData\Roaming\nvModes.dat
2008-06-16 23:34 446,464 ----a-w C:\Windows\System32\nvuninst.exe
2008-06-12 05:28 541,696 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-03-25 04:38 174 --sha-w C:\Program Files\desktop.ini
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2008-01-19 125952]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" [2007-08-31 4670704]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"eDataSecurity Loader"="C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2007-04-26 457216]
"eAudio"="C:\Acer\Empowering Technology\eAudio\eAudio.exe" [2007-06-12 1286144]
"PLFSet"="C:\Windows\PLFSet.dll" [2007-04-25 45056]
"LManager"="C:\PROGRA~1\LAUNCH~1\LManager.exe" [2007-06-27 752136]
"Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [2007-06-06 159744]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-09-04 1235736]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2008-06-26 13580832]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2008-06-26 92704]
"TV Card Remote Control Device Monitor"="C:\Windows\6000RMT.exe" [2007-09-14 466944]
"RtHDVCpl"="RtHDVCpl.exe" [2007-05-18 C:\Windows\RtHDVCpl.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Acer Tour Reminder"="C:\Acer\AcerTour\Reminder.exe" [2007-05-23 151552]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Empowering Technology Launcher.lnk]
path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Empowering Technology Launcher.lnk
backup=C:\Windows\pss\Empowering Technology Launcher.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^TV Expert Schedule Agent.lnk]
path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TV Expert Schedule Agent.lnk
backup=C:\Windows\pss\TV Expert Schedule Agent.lnk.CommonStartup
backupExtension=.CommonStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acer Assist Launcher]
--a------ 2007-02-03 02:05 1261568 C:\Program Files\Acer Assist\launcher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acer Product Registration]
--a------ 2007-02-03 03:24 3383296 C:\Program Files\Acer Registration\ACE1.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acer Tour Reminder]
--a------ 2007-05-23 06:49 151552 C:\Acer\AcerTour\Reminder.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-12 13:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
--a------ 2006-11-21 12:44 107112 C:\Program Files\Common Files\Symantec Shared\ccApp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\osCheck]
--a------ 2006-11-21 12:42 22696 C:\Program Files\Norton Internet Security\osCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PlayMovie]
--------- 2007-05-25 05:38 206952 C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
--a------ 2008-01-19 15:33 1233920 C:\Program Files\Windows Sidebar\sidebar.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec PIF AlertEng]
--a------ 2008-01-30 09:38 583048 C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue SpeedUpMyPC]
--a------ 2008-05-03 06:15 156952 C:\Program Files\Uniblue\SpeedUpMyPC 3\StartSUMP2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2007-08-31 09:43 4670704 C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skytel]
--a------ 2007-05-18 15:25 1826816 C:\Windows\SkyTel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"DefaultOutboundAction"= 0 (0x0)
"DefaultInboundAction"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{9B926D02-3A15-4091-B324-645526871E15}"= C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Acer Arcade Deluxe.exe:Acer Arcade Deluxe
"{0AF4A2BF-6F54-44BF-B75F-36DBCF9456D8}"= C:\Program Files\Acer Arcade Deluxe\VideoMagician\VideoMagician.exe:VideoMagician
"{6FE367BC-DA89-4B1F-BD5C-BA3D3930081B}"= C:\Program Files\Acer Arcade Deluxe\HomeMedia\HomeMedia.exe:HomeMedia
"{451B4395-2A13-4D1B-AF58-EE3C7AA931D5}"= C:\Program Files\Acer Arcade Deluxe\DV Wizard\DV Wizard.exe

V Wizard
"{E47D6E33-6D9E-4F3A-A8EC-1D5F1BEF7097}"= C:\Program Files\Acer Arcade Deluxe\DVDivine\DVDivine.exe

VDivine
"{186B1557-81A7-4293-A467-3E0F167F0E69}"= C:\Program Files\Acer Arcade Deluxe\Play Movie\PlayMovie.exe

lay Movie
"{218BBE3E-AE39-4AC0-BBFD-4A4AB6861B60}"= C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe

lay Movie Resident Program
"{7197A5C9-EB33-4293-ADF6-F5781D5B2911}"= UDP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{C8D94767-4499-4ED1-8B95-7DA375A611CA}"= TCP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{0A186720-5007-4459-B94A-49756C2169DF}"= UDP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{133EC05B-A3B1-45C0-847A-E597CCE3C33E}"= TCP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{A844A00D-45B3-4626-AC2D-D4EC8496524E}"= UDP:C:\Program Files\SpeedBit Video Accelerator\VideoAccelerator.exe:VideoAccelerator
"{2E7C0D39-B2A6-45B9-877B-EDD85ECF6263}"= TCP:C:\Program Files\SpeedBit Video Accelerator\VideoAccelerator.exe:VideoAccelerator
"TCP Query User{C458F821-E193-4E10-AD59-9824D058CB5B}C:\\program files\\mythwar_en\\update.exe"= UDP:C:\program files\mythwar_en\update.exe:update Microsoft
"UDP Query User{A1F6D88E-CD08-49D9-BD7F-CB3EDE34F2AD}C:\\program files\\mythwar_en\\update.exe"= TCP:C:\program files\mythwar_en\update.exe:update Microsoft
"{CAD12F57-E248-41FE-BA95-F9735CF0BFE7}"= UDP:C:\Program Files\Webzen\Mu\mu.exe:MU
"{117BEAEE-8A97-410D-B18D-090C792D23DD}"= TCP:C:\Program Files\Webzen\Mu\mu.exe:MU
"TCP Query User{8824E455-AFD0-4254-AD3D-DBFA1441396E}C:\\program files\\yahoo!\\messenger\\yahoomessenger.exe"= UDP:C:\program files\yahoo!\messenger\yahoomessenger.exe:Yahoo! Messenger
"UDP Query User{9690DDAB-06E1-4EFB-A712-72A1129DD8DC}C:\\program files\\yahoo!\\messenger\\yahoomessenger.exe"= TCP:C:\program files\yahoo!\messenger\yahoomessenger.exe:Yahoo! Messenger
"TCP Query User{4ACBF12D-6E77-4E63-91AB-50549372127D}C:\\program files\\limewire\\limewire.exe"= UDP:C:\program files\limewire\limewire.exe:LimeWire
"UDP Query User{32D36618-7A04-4F9C-B350-13B43504B86C}C:\\program files\\limewire\\limewire.exe"= TCP:C:\program files\limewire\limewire.exe:LimeWire
"TCP Query User{63F6B6A8-5FB6-4468-A204-C2108C705831}C:\\users\\neil\\documents\\others\\gba\\visualboyadvance\\visualboyadvance.exe"= UDP:C:\users\neil\documents\others\gba\visualboyadvance\visualboyadvance.exe:visualboyadvance.exe
"UDP Query User{4A68A985-FE23-4391-8284-F64B21DF189D}C:\\users\\neil\\documents\\others\\gba\\visualboyadvance\\visualboyadvance.exe"= TCP:C:\users\neil\documents\others\gba\visualboyadvance\visualboyadvance.exe:visualboyadvance.exe
"TCP Query User{A4369AF8-682F-415D-8B3B-9DF1D19A0271}C:\\users\\neil\\documents\\others\\gba\\visualboyadvance\\vbalink.exe"= UDP:C:\users\neil\documents\others\gba\visualboyadvance\vbalink.exe:vbalink.exe
"UDP Query User{0F36FCF5-540A-4A4D-A071-1D18F212ED1C}C:\\users\\neil\\documents\\others\\gba\\visualboyadvance\\vbalink.exe"= TCP:C:\users\neil\documents\others\gba\visualboyadvance\vbalink.exe:vbalink.exe
"TCP Query User{35EFA093-789F-4912-80DF-BEC9837A6202}C:\\program files\\mythwar_en\\update.exe"= UDP:C:\program files\mythwar_en\update.exe:update Microsoft
"UDP Query User{A93D5B4C-89C0-485E-8F54-14BE8087A05F}C:\\program files\\mythwar_en\\update.exe"= TCP:C:\program files\mythwar_en\update.exe:update Microsoft
"TCP Query User{AA4E5B1E-1CF4-40AD-97D2-4B4517B1BB09}C:\\program files\\yahoo!\\messenger\\yserver.exe"= UDP:C:\program files\yahoo!\messenger\yserver.exe:YServer Module
"UDP Query User{9199E010-2F1D-477F-9183-0A2D78B6984E}C:\\program files\\yahoo!\\messenger\\yserver.exe"= TCP:C:\program files\yahoo!\messenger\yserver.exe:YServer Module
"{1AA044B6-EDA0-4D73-8987-0C6B4D30FD55}"= UDP:C:\Program Files\SpeedBit Video Accelerator\VideoAcceleratorEngine.exe:VideoAcceleratorService
"{D7A1331B-C3C4-4BD5-BE6F-9EF22046EF59}"= TCP:C:\Program Files\SpeedBit Video Accelerator\VideoAcceleratorEngine.exe:VideoAcceleratorService
"{07396C18-AD6B-4B45-A0C8-1E55EEC2FEA8}"= UDP:C:\Program Files\SpeedBit Video Accelerator\VideoAcceleratorEngine.exe:VideoAcceleratorService
"{51276306-6CC2-480E-8D24-15572C58F538}"= TCP:C:\Program Files\SpeedBit Video Accelerator\VideoAcceleratorEngine.exe:VideoAcceleratorService
"{E777D3DF-6BF5-457D-ACFB-86949A932B87}"= C:\Program Files\AVG\AVG8\avgupd.exe:avgupd.exe
"TCP Query User{8E5DB27E-BDF0-48E0-9022-EDD5917B121D}C:\\program files\\veoh networks\\veoh\\veohclient.exe"= UDP:C:\program files\veoh networks\veoh\veohclient.exe:Veoh Client
"UDP Query User{3CFECFC5-2E0B-4FEC-A65B-E962D50F4E43}C:\\program files\\veoh networks\\veoh\\veohclient.exe"= TCP:C:\program files\veoh networks\veoh\veohclient.exe:Veoh Client
"TCP Query User{ACE6D004-ADD4-4C90-95EE-BABE0AA3F67E}C:\\program files\\e-games\\cabal online (ph)\\launcher\\update\\estdnheadless.exe"= UDP:C:\program files\e-games\cabal online (ph)\launcher\update\estdnheadless.exe:EST! download engine
"UDP Query User{1450E480-1A4B-41C5-BA7B-16C2CD497D89}C:\\program files\\e-games\\cabal online (ph)\\launcher\\update\\estdnheadless.exe"= TCP:C:\program files\e-games\cabal online (ph)\launcher\update\estdnheadless.exe:EST! download engine
"{329BEEBD-D319-4501-B8CE-27FAA9ACA460}"= UDP:C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe:BlueSoleil
"{8CAA05F2-DF85-4158-9A8E-C86C26EA7B45}"= TCP:C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe:BlueSoleil
"TCP Query User{7997673B-2394-4E1A-B5A8-DA5EB9E22D0E}C:\\users\\neil\\documents\\my completed downloads\\pspplayer.svn310.debugandrelease\\debug\\noxa.emulation.psp.player.exe"= UDP:C:\users\neil\documents\my completed downloads\pspplayer.svn310.debugandrelease\debug\noxa.emulation.psp.player.exe:noxa.emulation.psp.player.exe
"UDP Query User{F7CDD03D-1E83-4520-ABF8-F88BE83774B7}C:\\users\\neil\\documents\\my completed downloads\\pspplayer.svn310.debugandrelease\\debug\\noxa.emulation.psp.player.exe"= TCP:C:\users\neil\documents\my completed downloads\pspplayer.svn310.debugandrelease\debug\noxa.emulation.psp.player.exe:noxa.emulation.psp.player.exe
"TCP Query User{DD592B31-406D-4DA4-8D75-392D0343F1EF}C:\\users\\neil\\documents\\my completed downloads\\pspplayer.svn310.debugandrelease\\release\\noxa.emulation.psp.player.exe"= UDP:C:\users\neil\documents\my completed downloads\pspplayer.svn310.debugandrelease\release\noxa.emulation.psp.player.exe:noxa.emulation.psp.player.exe
"UDP Query User{947F371D-D9C1-49EC-9165-26990E0100C6}C:\\users\\neil\\documents\\my completed downloads\\pspplayer.svn310.debugandrelease\\release\\noxa.emulation.psp.player.exe"= TCP:C:\users\neil\documents\my completed downloads\pspplayer.svn310.debugandrelease\release\noxa.emulation.psp.player.exe:noxa.emulation.psp.player.exe
"TCP Query User{F9808D99-BA14-41EE-B3F5-0A2B79501571}C:\\users\\neil\\desktop\\counterstrike\\half-life\\hl -game cstrike -console.exe"= UDP:C:\users\neil\desktop\counterstrike\half-life\hl -game cstrike -console.exe:hl -game cstrike -console.exe
"UDP Query User{6C0FEA20-54D9-4EEA-9B00-808ABD83A1FC}C:\\users\\neil\\desktop\\counterstrike\\half-life\\hl -game cstrike -console.exe"= TCP:C:\users\neil\desktop\counterstrike\half-life\hl -game cstrike -console.exe:hl -game cstrike -console.exe
"TCP Query User{E91A41AC-86A3-4872-89CD-0AE1174F9FED}C:\\program files\\dap\\dap.exe"= UDP:C:\program files\dap\dap.exe

ownload Accelerator Plus (DAP)
"UDP Query User{82BDD714-E369-44BD-A86C-1275B42904AF}C:\\program files\\dap\\dap.exe"= TCP:C:\program files\dap\dap.exe

ownload Accelerator Plus (DAP)
"{2D2CAD3D-88C3-4F70-8B92-6C6A30FF3257}"= UDP:C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe:BlueSoleil
"{C2016BEF-2309-490B-AD47-D2291E2410BF}"= TCP:C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe:BlueSoleil
"TCP Query User{55D915EC-292B-4FE7-8C77-96D4B3906E86}C:\\program files\\limewire\\limewire.exe"= UDP:C:\program files\limewire\limewire.exe:LimeWire
"UDP Query User{36B7FC82-788F-4AD2-B7F4-FE89F2FB6EB5}C:\\program files\\limewire\\limewire.exe"= TCP:C:\program files\limewire\limewire.exe:LimeWire
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"DefaultOutboundAction"= 0 (0x0)
"DefaultInboundAction"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Acer\\Empowering Technology\\eDataSecurity\\eDSfsu.exe"= C:\Acer\Empowering Technology\eDataSecurity\eDSfsu.exe:*:Enabled:eDSfsu
"C:\\Acer\\Empowering Technology\\eDataSecurity\\encryption.exe"= C:\Acer\Empowering Technology\eDataSecurity\encryption.exe:*:Enabled:encryption
"C:\\Acer\\Empowering Technology\\eDataSecurity\\decryption.exe"= C:\Acer\Empowering Technology\eDataSecurity\decryption.exe:*:Enabled:decryption
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\Windows\system32\Drivers\avgldx86.sys [2008-09-04 97928]
R1 IDSvix86;Symantec Intrusion Prevention Driver;C:\PROGRA~2\Symantec\DEFINI~1\SymcData\idsdefs\20080429.001\IDSvix86.sys [2008-02-14 261680]
R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};C:\Program Files\Acer Arcade Deluxe\Play Movie\
000.fcl [2006-11-03 08:51 13560]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-09-04 231704]
R2 Start BT in service;Start BT in service;C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe [2007-12-28 51816]
R3 enecir;ENE CIR Receiver;C:\Windows\system32\DRIVERS\enecir.sys [2007-05-16 32256]
R3 SYMNDISV;SYMNDISV;C:\Windows\system32\Drivers\SYMNDISV.SYS [2007-10-31 37936]
S3 Ph3xIB32;Philips 713x Inbox PCI TV Card;C:\Windows\system32\DRIVERS\Ph3xIB32.sys [2006-11-02 1083520]
S3 TridVid;TM6000 TV Service;C:\Windows\system32\DRIVERS\TridVid.sys [2007-12-25 230528]
S3 TridVidx86;Trident TVMaster TM6000 Analog plus Digital Video Service x86;C:\Windows\system32\DRIVERS\TridVidx86.sys [2007-07-31 163456]
S3 WSVD;WSVD;C:\Windows\system32\drivers\WSVD.sys [2006-09-20 80744]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
\shell\AutoRun\command - H:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0ec3f830-d085-11dc-bcf6-806e6f6e6963}]
\shell\AutoRun\command - E:\setup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2e73d028-4607-11dd-949b-001b385031d3}]
\shell\auto\command - F:\Knight.exe open
\shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\Knight.exe open
\shell\explore\command - F:\Knight.exe open
\shell\find\command - F:\Knight.exe open
\shell\install\command - F:\Knight.exe open
\shell\open\command - F:\Knight.exe open
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{34667940-67f8-11dd-bd92-00116778c769}]
\shell\AutoPlay\Command - wscript.exe sowar.vbs
\shell\AutoRun\command - wscript.exe sowar.vbs
\shell\Explore\Command - wscript.exe sowar.vbs
\shell\Open\Command - wscript.exe sowar.vbs
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5752f0bd-63e6-11dd-8ff5-00116778c769}]
\shell\auto\command - Knight.exe open
\shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Knight.exe open
\shell\explore\command - Knight.exe open
\shell\find\command - Knight.exe open
\shell\install\command - Knight.exe open
\shell\open\command - Knight.exe open
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5c0db364-5751-11dd-920e-001b385031d3}]
\shell\AutoRun\command - G:\apj.com
\shell\explore\Command - G:\apj.com
\shell\open\Command - G:\apj.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5c0db36f-5751-11dd-920e-001b385031d3}]
\shell\AutoRun\command - H:\kgt8bl.cmd
\shell\explore\Command - H:\kgt8bl.cmd
\shell\open\Command - H:\kgt8bl.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{695fa4cf-58ed-11dd-a680-00116778c769}]
\shell\AutoRun\command - G:\svdioajm.cmd
\shell\explore\Command - G:\svdioajm.cmd
\shell\open\Command - G:\svdioajm.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8d6091aa-e329-11dc-bce0-001b385031d3}]
\shell\
0pen\command - krag.exe
\shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL krag.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a1645ca0-6009-11dd-9ac1-00116778c769}]
\shell\AutoRun\command - G:\rqb0v2ot.bat
\shell\explore\Command - G:\rqb0v2ot.bat
\shell\open\Command - G:\rqb0v2ot.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cfd77902-4489-11dd-a8a3-001b385031d3}]
\shell\auto\command - Knight.exe open
\shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Knight.exe open
\shell\explore\command - Knight.exe open
\shell\find\command - Knight.exe open
\shell\install\command - Knight.exe open
\shell\open\command - Knight.exe open
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dd929516-e7fe-11dc-8f26-001b385031d3}]
\shell\AutoRun\command - G:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\msnmsngr.exe
\shell\open\command - G:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\msnmsngr.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ec97fb54-79dc-11dd-8d35-00116778c769}]
\shell\AutoRun\command - G:\ktnquo.exe
\shell\explore\Command - G:\ktnquo.exe
\shell\open\Command - G:\ktnquo.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fb317308-5dd2-11dd-93d9-00116778c769}]
\shell\AutoRun\command - G:\System\Security\DriveGuard.exe -run
\shell\Explore\Command - G:\System\Security\DriveGuard.exe -run
\shell\Open\Command - G:\System\Security\DriveGuard.exe -run
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fb31730d-5dd2-11dd-93d9-00116778c769}]
\shell\AutoRun\command - H:\LaunchU3.exe -a
*Newly Created Service* - CATCHME
*Newly Created Service* - COMHOST
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Users\Neil\AppData\Roaming\Mozilla\Firefox\Profiles\zbe5vs1p.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.yahoo.com/
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npff_gdm.dll
FF -: plugin - C:\Program Files\Veoh Networks\Veoh\Plugins\noreg\NPVeohVersion.dll
FF -: plugin - C:\Program Files\Yahoo!\Shared\npYState.dll
.
.
------- File Associations (Beta) -------
.
inifile=%SystemRoot%\System32\NOTEPAD.EXE %1"
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-09-06 10:41:11
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-09-06 10:42:58
ComboFix-quarantined-files.txt 2008-09-06 02:42:53
Pre-Run: 23,064,985,600 bytes free
Post-Run: 22,920,024,064 bytes free
343 --- E O F --- 2008-09-04 12:55:17