OK, I did what you said and here's the log...
ComboFix 08-03-26.3 - Administrator 06/04/2008 9:25:01.3 - NTFSx86
Microsoft Windows 2000 Professional 5.0.2195.4.1252.1.1033.18.375 [GMT 10:00]
Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Administrator\Desktop\CFScript
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\VundoFix Backups
C:\VundoFix Backups\i9.exe.bad
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_SERVICEHOST
-------\Legacy_WSERVTIME
-------\Service_ServiceHost
-------\Service_wservtime
((((((((((((((((((((((((( Files Created from 2008-03-05 to 2008-04-05 )))))))))))))))))))))))))))))))
.
2008-04-06 09:31 . 16,384 C:\WINNT\system32\Perflib_Perfdata_368.dat
2008-04-05 10:06 . 08-04-05 10:06 55,081 --a------ C:\WINNT\Aware40.mch
2008-04-04 15:22 . 08-04-04 15:22 0 --a------ C:\WINNT\BBCAUTO.INI
2008-04-01 14:01 . 08-04-06 09:31 42 d-a------ C:\WINNT\.
2008-04-01 14:01 . 08-04-06 09:31 38 d-a------ C:\WINNT\.
2008-04-01 13:58 . 08-04-01 13:58 38 --a------ C:\WINNT\@
2008-04-01 13:50 . 08-04-03 19:01 95,482 --a------ C:\WINNT\Run32A50.mch
2008-04-01 13:50 . 08-04-01 13:50 0 --a------ C:\WINNT\mfont.dat
2008-04-01 13:07 . 08-04-03 18:57 <DIR> d-------- C:\WINNT\A5W_DATA
2008-04-01 13:07 . 08-04-03 18:57 35 --a------ C:\WINNT\A5W.INI
2008-04-01 10:01 . 08-04-01 10:01 <DIR> d-------- C:\LearningLand
2008-04-01 10:00 . 08-04-05 09:23 <DIR> d-------- C:\WINNT\A4W_DATA
2008-04-01 10:00 . 08-04-05 09:23 35 --a------ C:\WINNT\A4W.INI
2008-04-01 08:56 . 08-04-01 08:56 <DIR> d-------- C:\Program Files\directx
2008-04-01 08:56 . 08-04-01 08:56 <DIR> d-------- C:\Program Files\BBC Multimedia
2008-04-01 08:56 . 00-05-17 18:59 198,640 --a------ C:\WINNT\system32\Mci32.ocx
2008-03-31 08:59 . 08-03-31 08:59 97 --a------ C:\WINNT\CR.ini
2008-03-31 08:45 . 08-03-31 08:45 <DIR> d-------- C:\Program Files\Disney Interactive
2008-03-31 08:45 . 08-03-31 08:45 441 --a------ C:\WINNT\Disney.ini
2008-03-31 08:31 . 08-04-01 13:55 <DIR> d-------- C:\Program Files\Activision Value
2008-03-30 18:20 . 08-03-30 18:20 <DIR> d-------- C:\Program Files\THQ
2008-03-30 18:13 . 08-04-01 16:28 689 --a------ C:\WINNT\Sharktales.INI
2008-03-30 13:05 . 08-04-05 09:06 694,090 ---h----- C:\WINNT\ShellIconCache
2008-03-29 20:46 . 08-03-29 20:46 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy 1.5
2008-03-29 18:12 . 08-04-06 09:24 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-29 18:10 . 07-12-10 13:53 81,288 --a------ C:\WINNT\system32\drivers\iksyssec.sys
2008-03-29 18:10 . 07-12-10 13:53 66,952 --a------ C:\WINNT\system32\drivers\iksysflt.sys
2008-03-29 18:10 . 08-02-01 11:55 42,376 --a------ C:\WINNT\system32\drivers\ikfilesec.sys
2008-03-29 18:10 . 07-12-10 13:53 29,576 --a------ C:\WINNT\system32\drivers\kcom.sys
2008-03-29 18:09 . 08-04-03 19:11 <DIR> d-------- C:\Program Files\Spyware Doctor
2008-03-29 18:09 . 08-03-29 18:09 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\PC Tools
2008-03-29 18:09 . 02-05-15 15:16 462,848 --a------ C:\WINNT\system32\msaatext.dll
2008-03-29 18:09 . 02-05-15 15:16 360,448 --a------ C:\WINNT\system32\oleacc.dll
2008-03-29 18:09 . 02-05-15 15:16 356,352 --a------ C:\WINNT\system32\oleaccrc.dll
2008-03-29 18:09 . 02-05-15 15:16 356,352 --a--c--- C:\WINNT\system32\dllcache\oleaccrc.dll
2008-03-28 17:06 . 08-03-28 17:06 <DIR> d-------- C:\WINNT\winsxs
2008-03-28 17:05 . 08-03-28 17:05 <DIR> d-------- C:\Program Files\MSECache
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-04 12:50 --------- d-----w C:\Program Files\S.M.A.R.T. AUS 1000
2008-04-04 12:32 154,112 ----a-w C:\WINNT\Internet Logs\xDB30.tmp
2008-04-04 12:08 2,739,712 ----a-w C:\WINNT\Internet Logs\xDB2F.tmp
2008-04-04 06:19 45,568 ----a-w C:\WINNT\Internet Logs\xDB2D.tmp
2008-04-04 06:19 2,706,432 ----a-w C:\WINNT\Internet Logs\xDB2E.tmp
2008-04-03 12:36 54,784 ----a-w C:\WINNT\Internet Logs\xDB2B.tmp
2008-04-03 12:36 2,708,480 ----a-w C:\WINNT\Internet Logs\xDB2C.tmp
2008-04-01 07:02 29,696 ----a-w C:\WINNT\Internet Logs\xDB2A.tmp
2008-04-01 04:19 31,232 ----a-w C:\WINNT\Internet Logs\xDB29.tmp
2008-04-01 04:05 75,264 ----a-w C:\WINNT\Internet Logs\xDB28.tmp
2008-03-31 22:55 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-31 00:12 33,280 ----a-w C:\WINNT\Internet Logs\xDB27.tmp
2008-03-30 22:58 --------- d-----w C:\Program Files\Scholastic's Clifford
2008-03-30 22:38 28,672 ----a-w C:\WINNT\Internet Logs\xDB26.tmp
2008-03-30 12:39 45,568 ----a-w C:\WINNT\Internet Logs\xDB25.tmp
2008-03-29 11:47 479,232 ----a-w C:\WINNT\Internet Logs\xDB24.tmp
2008-03-29 10:57 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-03-29 10:49 --------- d---a-w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-03-27 10:12 --------- d-----w C:\Documents and Settings\Administrator\Application Data\LimeWire
2008-03-15 08:46 --------- d-----w C:\Program Files\LimeWire
2008-03-03 07:28 --------- d-----w C:\Program Files\Scholastic
2008-02-27 12:51 225,792 ----a-w C:\WINNT\Internet Logs\xDB23.tmp
2008-02-21 07:26 33,792 ----a-w C:\WINNT\Internet Logs\xDB22.tmp
2008-02-20 12:00 228,352 ----a-w C:\WINNT\Internet Logs\xDB20.tmp
2008-02-20 12:00 2,474,496 ----a-w C:\WINNT\Internet Logs\xDB21.tmp
2008-02-01 11:42 39,424 ----a-w C:\WINNT\Internet Logs\xDB1E.tmp
2008-02-01 11:42 2,448,896 ----a-w C:\WINNT\Internet Logs\xDB1F.tmp
2008-01-30 11:34 108,032 ----a-w C:\WINNT\Internet Logs\xDB1D.tmp
2008-01-27 01:03 88,064 ----a-w C:\WINNT\Internet Logs\xDB1C.tmp
2008-01-24 09:13 176,128 ----a-w C:\WINNT\Internet Logs\xDB1B.tmp
2008-01-14 11:32 2,376,192 ----a-w C:\WINNT\Internet Logs\xDB1A.tmp
2008-01-14 11:32 147,456 ----a-w C:\WINNT\Internet Logs\xDB17.tmp
2008-01-09 11:40 272,384 ----a-w C:\WINNT\Internet Logs\xDB16.tmp
2007-12-27 10:34 67,072 ----a-w C:\WINNT\Internet Logs\xDB15.tmp
2007-12-25 05:18 69,632 ----a-w C:\WINNT\Internet Logs\xDB13.tmp
2007-12-22 07:51 106,027 ----a-w C:\WINNT\Internet Logs\vsmon_2nd_2007_12_22_18_45_59_small.dmp.zip
2007-12-22 07:46 2,305,024 ----a-w C:\WINNT\Internet Logs\xDB19.tmp
2007-12-22 07:46 16,896 ----a-w C:\WINNT\Internet Logs\xDB18.tmp
2007-12-22 07:37 104,918 ----a-w C:\WINNT\Internet Logs\vsmon_2nd_2007_12_22_18_18_30_small.dmp.zip
2007-12-22 07:18 91,136 ----a-w C:\WINNT\Internet Logs\xDB12.tmp
2007-12-22 07:18 2,305,024 ----a-w C:\WINNT\Internet Logs\xDB14.tmp
2007-12-17 11:09 117,248 ----a-w C:\WINNT\Internet Logs\xDB11.tmp
2007-12-12 10:56 66,048 ----a-w C:\WINNT\Internet Logs\xDB10.tmp
2007-12-10 11:57 185,856 ----a-w C:\WINNT\Internet Logs\xDBF.tmp
2007-12-02 01:12 123,392 ----a-w C:\WINNT\Internet Logs\xDBE.tmp
2007-11-27 10:40 65,536 ----a-w C:\WINNT\Internet Logs\xDBD.tmp
2007-11-25 07:00 199,680 ----a-w C:\WINNT\Internet Logs\xDBC.tmp
2007-11-17 12:10 193,024 ----a-w C:\WINNT\Internet Logs\xDBB.tmp
2007-11-07 12:03 25,600 ----a-w C:\WINNT\Internet Logs\xDBA.tmp
2007-11-06 11:26 172,032 ----a-w C:\WINNT\Internet Logs\xDB9.tmp
2007-10-29 10:24 307,200 ----a-w C:\WINNT\Internet Logs\xDB8.tmp
2007-10-24 01:40 2,091,008 ----a-w C:\WINNT\Internet Logs\xDB7.tmp
2007-10-18 08:59 49,664 ----a-w C:\WINNT\Internet Logs\xDB6.tmp
2007-10-17 09:00 637,440 ----a-w C:\WINNT\Internet Logs\xDB5.tmp
2007-10-08 11:39 741,376 ----a-w C:\WINNT\Internet Logs\xDB4.tmp
2007-09-29 23:44 93,184 ----a-w C:\WINNT\Internet Logs\xDB3.tmp
2007-09-27 12:24 1,490,944 ----a-w C:\WINNT\Internet Logs\tvDebug.zip
2007-09-25 13:07 1,360,384 ----a-w C:\WINNT\Internet Logs\xDB2.tmp
2007-09-04 05:11 1,687,040 ----a-w C:\WINNT\Internet Logs\xDB1.tmp
2007-08-11 02:41 242,907 ----a-w C:\Documents and Settings\Steve & Kay\setup.exe
2005-12-08 01:42 271 ---h--w C:\Program Files\desktop.ini
2005-12-08 01:42 21,952 ---h--w C:\Program Files\folder.htt
1999-12-07 04:00 32,528 ----a-w C:\WINNT\inf\wbfirdma.sys
2007-08-15 22:33 479,232 ----a-w C:\Program Files\mozilla firefox\plugins\msvcm80.dll
2007-08-15 22:33 548,864 ----a-w C:\Program Files\mozilla firefox\plugins\msvcp80.dll
2007-08-15 22:33 626,688 ----a-w C:\Program Files\mozilla firefox\plugins\msvcr80.dll
.
((((((((((((((((((((((((((((( snapshot@Fri 2008-04-04_22.21.28.20 )))))))))))))))))))))))))))))))))))))))))
.
+ 2000-08-30 22:00:00 163,328 ----a-w C:\WINNT\erdnt\subs\ERDNT.EXE
- 2008-04-04 12:13:14 4,212 ---h--w C:\WINNT\system32\zllictbl.dat
+ 2008-04-05 23:32:06 4,212 ---h--w C:\WINNT\system32\zllictbl.dat
- 2008-03-26 20:41:43 8,469,801 ----a-w C:\WINNT\system32\ZoneLabs\spyware.dat
+ 2008-04-05 02:35:09 8,551,189 ----a-w C:\WINNT\system32\ZoneLabs\spyware.dat
- 2008-03-26 20:41:43 8,469,801 ----a-w C:\WINNT\system32\ZoneLabs\zlasdbup.dat
+ 2008-04-05 02:35:09 8,551,189 ----a-w C:\WINNT\system32\ZoneLabs\zlasdbup.dat
- 2007-12-01 05:17:23 49,152 ----a-w C:\WINNT\system32\ZoneLabs\zlqrtdb.dat
+ 2008-04-05 08:18:48 101,376 ----a-w C:\WINNT\system32\ZoneLabs\zlqrtdb.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"internat.exe"="internat.exe" [99-12-07 14:00 20752 C:\WINNT\system32\internat.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Synchronization Manager"="mobsync.exe" [03-06-20 05:05 111376 C:\WINNT\system32\mobsync.exe]
"NeroCheck"="C:\WINNT\system32\NeroCheck.exe" [01-07-09 19:50 155648]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [06-05-25 21:29 77824]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [05-06-06 22:46 57344]
"Zone Labs Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [05-10-02 22:05 980736]
"itype"="C:\Program Files\Microsoft IntelliType Pro\itype.exe" [06-11-22 11:08 813912]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [07-02-06 09:52 849280]
"SysTrayFind"="C:\WINNT\SysTrayFind.exe" [02-09-04 11:27 24576]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"internat.exe"="internat.exe" [99-12-07 14:00 20752 C:\WINNT\system32\internat.exe]
C:\Documents and Settings\Steve & Kay\Start Menu\Programs\Startup\
Cyber-shot Viewer Media Check Tool.lnk - C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2006-12-23 15:58:41 155648]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-03-23 09:30:00 65588]
R0 SONYPVM1;Sony Memory Stick Driver(SONYPVM1);C:\WINNT\system32\DRIVERS\SONYPVM1.SYS [00-05-27 03:37 ]
R3 EL90BC;3Com EtherLink XL B/C Adapter Driver;C:\WINNT\system32\DRIVERS\el90xbc5.sys [99-10-23 22:22 ]
S3 TFBULK;Topfield USB client driver;C:\WINNT\system32\drivers\TfBulk.sys [03-02-26 14:09 ]
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-04-06 09:31:25
Windows 5.0.2195 Service Pack 4 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\WINNT\QTFont.for
C:\WINNT\QTFont.qfn
scan completed successfully
hidden files: 2
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINNT\system32\hidserv.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\CNAB3RPK.EXE
.
**************************************************************************
.
Completion time: 2008-04-06 9:38:06 - machine was rebooted
ComboFix-quarantined-files.txt 2008-04-05 23:37:57
ComboFix2.txt 2008-04-04 12:22:50
Pre-Run: 3,686,219,776 bytes free
Post-Run: 3,623,686,144 bytes free
Thanks,
Escapee33