Here are the results for the combofix:
ComboFix 08-11-27.03 - User 2008-11-29 14:44:06.3 - NTFSx86
Running from: c:\documents and settings\User\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\User\Desktop\cfscript.txt
FILE ::
c:\windows\system32\g62.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\SysNotifier.exe
c:\windows\system32\g62.exe
.
((((((((((((((((((((((((( Files Created from 2008-10-28 to 2008-11-29 )))))))))))))))))))))))))))))))
.
2008-11-24 21:23 . 2008-11-24 21:25 94,107 --a------ c:\windows\hpqins05.dat
2008-11-24 21:11 . 2007-04-19 16:14 11,634 --------- c:\windows\hpomdl11.dat.temp
2008-11-24 20:33 . 2008-11-24 20:33 1,947 --a------ c:\windows\unins000.dat
2008-11-24 19:09 . 2008-11-24 19:09 <DIR> d-------- C:\rsit
2008-11-24 12:16 . 2008-11-24 12:17 692 --a------ c:\windows\hpntwksetup.ini
2008-11-24 12:14 . 2008-11-24 21:11 116,734 --------- c:\windows\hpoins11.dat.temp
2008-11-24 06:53 . 2008-11-24 06:53 <DIR> d-------- c:\program files\Trend Micro
2008-11-24 00:55 . 2008-11-24 00:55 <DIR> d-------- c:\program files\Sygate
2008-11-24 00:55 . 2004-10-15 18:32 83,096 --a------ c:\windows\system32\SSSensor.dll
2008-11-24 00:55 . 2004-10-15 18:17 60,496 --a------ c:\windows\system32\drivers\Teefer.sys
2008-11-24 00:55 . 2004-10-15 18:18 21,075 --a------ c:\windows\system32\drivers\wpsdrvnt.sys
2008-11-24 00:55 . 2004-10-15 18:32 14,568 --a------ c:\windows\system32\drivers\wg6n.sys
2008-11-24 00:55 . 2004-10-15 18:32 14,568 --a------ c:\windows\system32\drivers\wg5n.sys
2008-11-24 00:55 . 2004-10-15 18:32 14,568 --a------ c:\windows\system32\drivers\wg4n.sys
2008-11-24 00:55 . 2004-10-15 18:32 14,568 --a------ c:\windows\system32\drivers\wg3n.sys
2008-11-23 23:35 . 2008-11-23 23:35 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-11-23 23:35 . 2008-11-23 23:35 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-23 23:35 . 2008-10-22 16:27 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-23 23:35 . 2008-10-22 16:27 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-11-23 11:06 . 2008-11-24 12:23 109 --a------ c:\windows\wininit.ini
2008-11-23 10:42 . 2008-11-23 11:09 <DIR> d-------- c:\program files\Spybot - Search & Destroy
2008-11-23 10:42 . 2008-11-23 11:43 <DIR> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-11-23 00:24 . 2008-11-23 00:24 <DIR> d-------- c:\windows\ERUNT
2008-11-23 00:21 . 2008-11-25 13:54 <DIR> d-------- C:\SDFix
2008-11-18 23:47 . 2008-11-18 23:47 <DIR> d-------- c:\program files\MozyHome
2008-11-18 23:47 . 2008-11-16 23:32 53,752 --a------ c:\windows\system32\drivers\mozy.sys
2008-11-18 15:56 . 2008-11-18 22:52 <DIR> d--hs---- c:\windows\V29ya3N0YXRpb24
2008-11-18 15:56 . 2008-11-18 22:52 <DIR> d-------- c:\windows\system32\vim
2008-11-18 15:56 . 2008-11-18 15:56 <DIR> d-------- c:\windows\system32\ip
2008-11-18 15:56 . 2008-11-18 15:57 <DIR> d-------- c:\windows\system32\hdx
2008-11-16 23:33 . 2008-11-23 00:11 9,724 --a------ c:\windows\mozy.flt
2008-11-16 23:33 . 2008-11-23 00:11 7,396 --a------ c:\windows\mozy.blk
2008-11-09 10:02 . 2008-11-28 23:03 <DIR> d-------- c:\documents and settings\All Users\Application Data\Google Updater
2008-11-01 15:57 . 2008-11-01 15:57 <DIR> d-------- c:\program files\Photo Story 3 for Windows
2008-11-01 15:45 . 2008-11-01 15:45 <DIR> d-------- c:\program files\Norton PC Checkup
2008-11-01 15:45 . 2008-11-16 16:22 <DIR> d-------- c:\program files\Common Files\Symantec Shared
2008-11-01 15:20 . 2008-11-01 15:21 <DIR> d-------- c:\windows\system32\Adobe
2008-11-01 12:39 . 2008-11-01 12:39 0 --a------ c:\windows\hpqEmlSz.INI
2008-10-30 19:52 . 2008-10-30 19:52 <DIR> d-------- c:\documents and settings\All Users\Application Data\HP
2008-10-30 19:44 . 2008-10-30 19:44 <DIR> d-------- c:\program files\Common Files\Sonic Shared
2008-10-30 19:44 . 2008-10-30 19:44 <DIR> d-------- c:\documents and settings\All Users\Application Data\Sonic
2008-10-30 19:39 . 2006-04-12 17:02 827,392 -ra------ c:\windows\system32\hpotiop2.dll
2008-10-30 19:39 . 2006-04-12 17:02 254,026 -ra------ c:\windows\system32\hpovst09.dll
2008-10-30 19:39 . 2006-01-04 02:12 77,824 -ra------ c:\windows\system32\HPZIDS01.dll
2008-10-30 19:39 . 2006-04-10 13:03 38,400 --a------ c:\windows\system32\hpz3l054.dll
2008-10-30 19:39 . 2001-08-17 13:53 6,784 --a------ c:\windows\system32\drivers\serscan.sys
2008-10-30 19:39 . 2001-08-17 13:53 6,784 --a--c--- c:\windows\system32\dllcache\serscan.sys
2008-10-30 19:39 . 2008-11-24 12:17 173 --a------ c:\windows\system32\AddPort.ini
2008-10-30 19:26 . 2008-11-24 12:19 <DIR> d-------- C:\TEMP
2008-10-30 19:24 . 2008-11-24 21:13 116,734 --a------ c:\windows\hpoins11.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-29 21:32 --------- d-----w c:\program files\Plaxo
2008-11-28 07:16 --------- d-----w c:\program files\PCPICSW
2008-11-25 04:26 --------- d-----w c:\program files\HP
2008-11-24 13:53 --------- d-----w c:\program files\Computer Maintenance
2008-11-24 07:18 --------- d-----w c:\documents and settings\All Users\Application Data\RFA_Backups
2008-11-23 15:36 --------- d-----w c:\program files\Shockwave.com
2008-11-23 15:35 --------- d-----w c:\program files\Oberon Media
2008-11-09 18:04 --------- d-----w c:\program files\Picasa2
2008-11-09 17:02 --------- d-----w c:\program files\Google
2008-10-31 02:44 --------- d-----w c:\program files\Common Files\HP
2008-10-24 11:10 453,632 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-22 22:11 --------- d-----w c:\program files\MSECache
2008-10-16 21:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 21:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 21:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 21:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 21:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 21:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 21:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 21:08 34,328 -c--a-w c:\windows\system32\wups.dll
2008-10-16 21:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 21:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-10-07 01:47 --------- d--h--w c:\program files\InstallShield Installation Information
2008-10-07 01:46 62,009 ----a-w c:\windows\system32\wpfb_ati2dvag.dll
2008-10-07 01:46 --------- d-----w c:\program files\Portrait Displays
2008-10-07 01:46 --------- d-----w c:\program files\Common Files\Portrait Displays
2008-10-07 01:46 --------- d-----w c:\program files\Acer Display
2008-10-07 01:45 --------- d-----w c:\program files\Common Files\InstallShield
2008-09-30 23:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
2008-09-15 11:57 1,846,016 ----a-w c:\windows\system32\win32k.sys
2008-09-04 16:42 1,106,944 ----a-w c:\windows\system32\msxml3.dll
2008-08-30 03:06 1,350,664 ----a-w c:\windows\system32\msxml6.dll
2008-08-29 16:18 87,336 -c--a-w c:\windows\system32\dns-sd.exe
2008-08-29 15:53 61,440 -c--a-w c:\windows\system32\dnssd.dll
2008-08-12 00:02 0 -c--a-w c:\program files\temp01
2008-07-20 23:03 23 -c--a-w c:\documents and settings\Sean\jagex_runescape_preferences.dat
2008-07-03 20:47 0 -c--a-w c:\documents and settings\User\jagex_runescape_preferences.dat
2007-07-31 19:04 630,784 -c--a-w c:\documents and settings\User\GoToAssist_chat2way__317_en.exe
2003-07-31 09:53 147,456 -c--a-w c:\windows\inf\EL2K_XP.sys
2003-07-31 09:50 448,768 -c--a-w c:\windows\inf\EL2K_N64.sys
2003-07-31 09:43 147,456 -c--a-w c:\windows\inf\EL2K_2K.sys
2007-07-02 03:32 88 -csh--r c:\windows\system32\C5501D18DC.sys
2008-06-01 22:38 1,942 -csha-w c:\windows\system32\KGyGaAvL.sys
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of c:\documents and settings\User\Application Data\IUpd721 ----
2008-11-18 16:10 1029 --a------ c:\documents and settings\User\Application Data\IUpd721\Logs\scns.log
---- Directory of c:\windows\system32\hdx ----
---- Directory of c:\windows\system32\ip ----
2008-11-17 16:39 190185 --a------ c:\windows\system32\ip\pxNT4I19.exe
---- Directory of c:\windows\system32\vim ----
---- Directory of c:\windows\V29ya3N0YXRpb24 ----
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1CAD29DF-1D6D-41A2-8C55-EAA2C7EDCDEB}]
2008-11-19 23:40 299008 --a------ c:\program files\Internet Explorer\en-US\pm3nod.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\mozy2]
@="{747E722C-CB46-4a9d-BDFE-192AAD5099B1}"
[HKEY_CLASSES_ROOT\CLSID\{747E722C-CB46-4a9d-BDFE-192AAD5099B1}]
2008-11-16 23:32 3044664 --a------ c:\program files\MozyHome\mozyshell.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\mozy3]
@="{EE6F5A00-7898-40f7-AB77-51FF9D6DEB20}"
[HKEY_CLASSES_ROOT\CLSID\{EE6F5A00-7898-40f7-AB77-51FF9D6DEB20}]
2008-11-16 23:32 3044664 --a------ c:\program files\MozyHome\mozyshell.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SmcService"="c:\progra~1\Sygate\SPF\smc.exe" [2004-10-15 2577632]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pm3nod]
2008-11-19 23:40 299008 c:\program files\Internet Explorer\en-US\pm3nod.dll
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"SpybotSD TeaTimer"=c:\program files\Spybot - Search & Destroy\TeaTimer.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
.
Contents of the 'Scheduled Tasks' folder
2008-11-19 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2008-11-22 c:\windows\Tasks\WebReg officejet 6300 series.job
- c:\program files\HP\Digital Imaging\bin\hpqwrg.exe [2006-02-19 04:09]
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-11-29 14:46:17
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet004\Services\vsdatant]
"ImagePath"=""
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1024)
c:\program files\Internet Explorer\en-US\pm3nod.dll
c:\windows\system32\SSSensor.dll
.
Completion time: 2008-11-29 14:48:16
ComboFix-quarantined-files.txt 2008-11-29 21:47:36
ComboFix2.txt 2008-11-27 22:17:59
ComboFix3.txt 2008-11-23 08:14:29
Pre-Run: 12,092,321,792 bytes free
Post-Run: 12,074,549,248 bytes free
179 --- E O F --- 2008-11-23 22:08:07
THANKS!!!