apologies for this late reply but i had my exams....
Here is the report from ComboFix....
---------------------------------------------------------------------------------------------------------------------------------------------
ComboFix 08-04-24.1 - iNdiSoUL 2008-04-26 19:00:59.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.194 [GMT -7:00]
Running from: C:\Documents and Settings\iNdiSoUL\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-03-27 to 2008-04-27 )))))))))))))))))))))))))))))))
.
2008-04-26 14:28 . 2002-10-03 00:09 38,912 --a------ C:\WINDOWS\system32\RASPPPOE.DLL
2008-04-26 14:28 . 2002-10-03 00:09 31,424 --a------ C:\WINDOWS\system32\drivers\RMSPPPOE.SYS
2008-04-26 14:28 . 2002-10-03 00:09 16,896 --a------ C:\WINDOWS\system32\RASPPPOE.EXE
2008-04-25 18:56 . 2008-04-25 18:56 <DIR> d-------- C:\Documents and Settings\Girish\Application Data\Nokia Multimedia Player
2008-04-24 08:41 . 2008-04-25 23:17 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-04-24 08:41 . 2008-04-24 08:41 1,409 --a------ C:\WINDOWS\QTFont.for
2008-04-18 08:50 . 2008-04-21 18:53 <DIR> d-------- C:\New Folder
2008-04-06 23:34 . 2008-04-06 23:41 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-02 17:56 . 2008-04-18 20:02 <DIR> d-------- C:\Hindi Songs
2008-03-30 11:30 . 2008-03-30 11:28 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-27 01:59 --------- d-----w C:\Program Files\Symantec AntiVirus
2008-04-26 21:38 --------- d-----w C:\Documents and Settings\iNdiSoUL\Application Data\MegauploadToolbar
2008-04-26 21:31 --------- d-----w C:\Documents and Settings\iNdiSoUL\Application Data\Orbit
2008-03-31 02:04 --------- d-----w C:\Documents and Settings\iNdiSoUL\Application Data\U3
2008-03-24 00:07 19,944 ----a-w C:\Documents and Settings\iNdiSoUL\Application Data\GDIPFONTCACHEV1.DAT
2008-03-23 00:11 --------- d-----w C:\Program Files\iPod
2008-03-21 19:52 --------- d-----w C:\Program Files\eLitecore
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-09 06:31 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-09 06:31 --------- d-----w C:\Program Files\ATI Technologies
2008-03-07 21:42 --------- d-----w C:\Documents and Settings\Girish\Application Data\MEGAUPLOADTOOLBAR
2008-03-07 00:38 --------- d-----w C:\Program Files\MegauploadToolbar
2008-03-02 19:38 --------- d-----w C:\Program Files\Windows Live
2008-03-02 19:37 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-03-02 19:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-03-01 06:00 --------- d-----w C:\Documents and Settings\iNdiSoUL\Application Data\AdobeUM
2008-02-29 06:12 --------- d-----w C:\Program Files\Java
2008-02-29 05:41 --------- d-----w C:\Program Files\Common Files\Java
2008-02-28 04:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Adobe Systems
2008-02-28 03:59 --------- d-----w C:\Program Files\Common Files\Adobe
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-16 08:59 659,456 ----a-w C:\WINDOWS\system32\wininet.dll
2008-01-27 22:23 1,071,480 ----a-w C:\WINDOWS\system32\SpoonUninstall.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-05-29 17:33 52840]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2007-10-07 21:48 125368]
"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2004-08-04 05:00 158208]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^24Online Client.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\24Online Client.lnk
backup=C:\WINDOWS\pss\24Online Client.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
backup=C:\WINDOWS\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Synchronizer.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Synchronizer.lnk
backup=C:\WINDOWS\pss\Adobe Acrobat Synchronizer.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^iNdiSoUL^Start Menu^Programs^Startup^Anapod Manager.lnk]
path=C:\Documents and Settings\iNdiSoUL\Start Menu\Programs\Startup\Anapod Manager.lnk
backup=C:\WINDOWS\pss\Anapod Manager.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
--a------ 2006-01-12 21:52 483328 D:\Miscellaneous\Adobe acrobat\Distillr\Acrotray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0]
D:\Miscellaneous\Adobe Acrobat\Acrobat\Acrotray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2007-09-20 16:35 202024 C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-01-15 04:22 267048 D:\Miscellaneous\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-10-13 09:24 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
C:\Program Files\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
--a------ 2007-09-20 10:51 1836328 D:\Miscellaneous\Nero 8\Nero BackItUp\NBKeyScan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2007-03-01 16:57 153136 C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
--a------ 2006-06-15 13:36 229376 D:\MISCEL~1\NOKIAP~1\NOKIAP~1\LAUNCH~1.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PcSync]
--a------ 2006-06-27 17:21 1449984 D:\Miscellaneous\Nokia PC Suite\Nokia PC Suite 6\PcSync2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
--a------ 2007-08-06 17:05 200704 D:\Miscellaneous\PowerISO\PWRISOVM.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-01-10 16:27 385024 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAX]
--a------ 2003-05-30 10:42 585728 C:\Program Files\Analog Devices\SoundMAX\smax4.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
--a------ 2003-05-29 17:28 790528 C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-12-14 04:42 144784 C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2008-02-07 05:20 151597 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Auth orizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"D:\\Miscellaneous\\BitComet\\BitComet.exe"=
"C:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
"C:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"D:\\Miscellaneous\\Orbitdownloader\\orbitnet.exe"=
"D:\\Miscellaneous\\iTunes\\iTunes.exe"=
"D:\\Miscellaneous\\Firefox 2.0\\firefox.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"D:\\Miscellaneous\\Orbitdownloader\\orbitdm.exe"=
R3 RMSPPPOE;WAN Miniport (PPP over Ethernet Protocol);C:\WINDOWS\system32\DRIVERS\RMSPPPOE.SYS [2002-10-03 00:09]
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2008-04-27 01:31:50 C:\WINDOWS\Tasks\XoftSpySE 2.job"
- D:\Miscellaneous\XoftSpySE\XoftSpy.exe
"2008-04-23 15:55:58 C:\WINDOWS\Tasks\XoftSpySE.job"
- D:\Miscellaneous\XoftSpySE\XoftSpy.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-04-26 19:02:10
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\sccfg.sys 326 bytes
scan completed successfully
hidden files: 1
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\Ati2evxx.dll
.
Completion time: 2008-04-26 19:02:53
ComboFix-quarantined-files.txt 2008-04-27 02:02:40
Pre-Run: 708,829,184 bytes free
Post-Run: 714,969,088 bytes free
147 --- E O F --- 2008-04-14 18:48:00