Here is the Combofix text log. Did notice that the files in question was being deleted during the process. Anyway you will know better when you see the log.
ComboFix 08-10-30.04 - Administrator 2008-10-30 13:18:49.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1103 [GMT 5.5:30]
Running from: C:\Documents and Settings\Administrator.HOME-5E315BF5A7\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Administrator.HOME-5E315BF5A7\Desktop\CFScript.txt
* Created a new restore point
FILE ::
C:\WINDOWS\system32\win.dll
C:\WINDOWS\system32\win.dll\reg.bkp\winthb.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\win.dll
C:\WINDOWS\system32\win.dll\Desktop.ini
C:\WINDOWS\system32\win.dll\DLL.ico
C:\WINDOWS\system32\win.dll\drivelist.txt
C:\WINDOWS\system32\win.dll\Icon.ico
C:\WINDOWS\system32\win.dll\reg.bkp\winthb.exe
C:\WINDOWS\system32\win.dll\reproduce.txt
C:\WINDOWS\system32\win.dll\script1.txt
C:\WINDOWS\system32\win.dll\std.txt
C:\WINDOWS\system32\win.dll\thb.ico
C:\WINDOWS\system32\win.dll\win.mp3
.
((((((((((((((((((((((((( Files Created from 2008-09-28 to 2008-10-30 )))))))))))))))))))))))))))))))
.
2008-10-30 07:38 . 2008-10-30 07:38 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Avira
2008-10-29 06:03 . 2008-10-29 06:03 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Sunbelt
2008-10-27 23:19 . 2008-10-27 23:19 <DIR> d-------- C:\Program Files\VS Revo Group
2008-10-27 23:12 . 2008-10-28 09:13 23,392 --a------ C:\WINDOWS\system32\nscompat.tlb
2008-10-27 23:12 . 2008-10-28 09:13 16,832 --a------ C:\WINDOWS\system32\amcompat.tlb
2008-10-27 10:02 . 2008-10-30 13:11 <DIR> d-------- C:\!KillBox
2008-10-27 05:22 . 2003-06-25 16:05 266,360 --a------ C:\WINDOWS\system32\TweakUI.exe
2008-10-27 05:22 . 2002-06-21 15:09 160,217 --a------ C:\WINDOWS\system32\PowerToysLicense.rtf
2008-10-26 14:53 . 2008-10-26 14:53 <DIR> d-------- C:\Program Files\Common Files\Adobe Systems Shared
2008-10-26 14:06 . 2008-10-26 14:06 <DIR> d-------- C:\Documents and Settings\Administrator.HOME-5E315BF5A7\Application Data\TERMINAL Studio
2008-10-26 14:05 . 2008-10-26 14:05 <DIR> d-------- C:\Documents and Settings\Administrator.HOME-5E315BF5A7\Application Data\Astro Gemini Software
2008-10-26 06:49 . 2008-10-30 07:38 <DIR> d-------- C:\Program Files\Avira
2008-10-26 04:36 . 2008-10-26 04:36 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Kaspersky Lab Setup Files
2008-10-26 03:44 . 2008-10-26 03:46 10,752 --ahs---- C:\WINDOWS\system32\Thumbs.db
2008-10-26 03:43 . 2008-10-26 03:43 7,680 --ahs---- C:\WINDOWS\Thumbs.db
2008-10-26 03:43 . 2008-10-26 03:43 5,632 --ahs---- C:\Thumbs.db
2008-10-24 10:06 . 2008-10-15 22:04 337,408 -----c--- C:\WINDOWS\system32\dllcache\netapi32.dll
2008-10-24 06:52 . 2008-10-24 06:54 <DIR> d-------- C:\Program Files\Trend Micro
2008-10-24 06:45 . 2008-10-24 06:45 410,976 --a------ C:\WINDOWS\system32\deploytk.dll
2008-10-24 05:15 . 2008-10-24 05:16 <DIR> d-------- C:\Program Files\CCleaner
2008-10-24 04:50 . 2008-10-24 04:50 <DIR> d-------- C:\Program Files\BinaryMark
2008-10-24 04:41 . 2008-10-26 14:54 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-10-20 12:19 . 2008-09-08 16:11 333,824 -----c--- C:\WINDOWS\system32\dllcache\srv.sys
2008-10-20 12:17 . 2008-08-14 15:41 2,189,184 -----c--- C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2008-10-20 12:17 . 2008-08-14 15:39 2,145,280 -----c--- C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2008-10-20 12:17 . 2008-08-14 15:03 2,066,048 -----c--- C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2008-10-20 12:17 . 2008-08-14 15:03 2,023,936 -----c--- C:\WINDOWS\system32\dllcache\ntkrpamp.exe
2008-10-20 12:17 . 2008-09-15 17:42 1,846,400 -----c--- C:\WINDOWS\system32\dllcache\win32k.sys
2008-10-15 08:49 . 2008-10-15 08:49 <DIR> d-------- C:\Program Files\123 Free Solitaire
2008-10-15 00:02 . 2008-10-15 00:02 <DIR> d-------- C:\swsetup
2008-10-14 23:26 . 2008-10-14 23:26 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\PC Drivers Headquarters
2008-10-14 00:46 . 2008-10-14 00:46 <DIR> d-------- C:\Documents and Settings\Administrator.HOME-5E315BF5A7\Application Data\Auslogics
2008-10-10 23:56 . 2008-10-10 23:56 <DIR> d-------- C:\Program Files\Sun
2008-10-02 12:57 . 2008-10-02 12:59 <DIR> d-------- C:\WINDOWS\system32\Adobe
2008-09-05 16:53 . 2008-09-05 16:53 <DIR> d-------- C:\Program Files\Litsoft
2008-09-05 16:53 . 1997-07-03 09:35 109,056 --a------ C:\WINDOWS\UNWISE.EXE
2008-09-05 01:00 . 2008-09-05 01:00 432 --a------ C:\WINDOWS\system32\iolo.ini
2008-09-05 01:00 . 2008-09-05 01:00 406 --a------ C:\WINDOWS\system32\ioloBootDefrag.cfg
2008-09-05 00:57 . 2008-09-14 15:01 <DIR> d-------- C:\Documents and Settings\LocalService.NT AUTHORITY\Application Data\iolo
2008-09-05 00:57 . 2008-08-26 15:23 118,784 --a------ C:\WINDOWS\system32\iavlsp.dll
2008-09-05 00:44 . 2008-09-05 00:44 74,703 --a------ C:\WINDOWS\system32\mfc45.dll
2008-09-05 00:43 . 2008-10-10 04:37 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\iolo
2008-09-05 00:43 . 2008-09-05 09:50 <DIR> d-------- C:\Documents and Settings\Administrator.HOME-5E315BF5A7\Application Data\iolo
2008-09-01 01:50 . 2008-09-01 01:50 2,812 --a------ C:\Settings.ini
2008-09-01 01:50 . 2008-09-01 01:50 2,617 --a------ C:\Commands.cfg
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-27 17:40 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-10-25 23:14 --------- d-----w C:\Documents and Settings\Administrator.HOME-5E315BF5A7\Application Data\SUPERAntiSpyware.com
2008-10-24 01:15 --------- d-----w C:\Program Files\Java
2008-10-22 07:06 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-10-15 01:21 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-10-10 11:14 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2008-10-09 07:38 --------- d-----w C:\Documents and Settings\Administrator.HOME-5E315BF5A7\Application Data\LimeWire
2008-10-02 07:28 --------- d-----w C:\Program Files\Google
2008-09-15 12:12 1,846,400 ----a-w C:\WINDOWS\system32\win32k.sys
2008-09-08 10:41 333,824 ----a-w C:\WINDOWS\system32\drivers\srv.sys
2008-08-31 10:26 --------- d---a-w C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
2008-08-31 10:26 --------- d-----w C:\Documents and Settings\Administrator.HOME-5E315BF5A7\Application Data\EAST Technologies
2008-08-29 10:50 --------- d-----w C:\Documents and Settings\Administrator.HOME-5E315BF5A7\Application Data\Windows Search
2008-08-29 04:02 --------- d-----w C:\Documents and Settings\Administrator.HOME-5E315BF5A7\Application Data\Windows Desktop Search
2008-08-29 04:01 --------- d-----w C:\Program Files\Windows Desktop Search
2008-08-28 08:44 98,304 ----a-w C:\WINDOWS\system32\JkDefragScreenSaver.scr
2008-08-28 08:44 237,056 ----a-w C:\WINDOWS\system32\JkDefragScreenSaver.exe
2008-08-26 07:24 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-08-14 10:11 2,189,184 ----a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-08-14 09:33 2,066,048 ----a-w C:\WINDOWS\system32\ntkrnlpa.exe
2008-07-18 16:40 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 16:40 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 16:40 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 16:40 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-18 16:39 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 16:39 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 16:39 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 16:39 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-18 16:37 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
2008-07-18 16:37 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
2008-07-07 20:26 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-03-27 05:09 14,523,983 ----a-w C:\Program Files\klcodec385f.exe
2008-03-26 08:09 2,400,784 ----a-w C:\Program Files\WLinstaller.exe
2003-03-21 08:07 16,056 ----a-w C:\Program Files\owcstp16.dll
2008-05-15 15:26 32,768 --sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008051520080516\index.dat
.
((((((((((((((((((((((((((((( snapshot@2008-10-30_ 6.30.55.75 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-05-09 07:45:51 45,376 ----a-w C:\WINDOWS\system32\drivers\avgntdd.sys
+ 2008-01-21 12:41:28 22,336 ----a-w C:\WINDOWS\system32\drivers\avgntmgr.sys
+ 2008-06-27 09:33:55 75,072 ----a-w C:\WINDOWS\system32\drivers\avipbb.sys
+ 2007-03-01 05:04:22 28,352 ----a-w C:\WINDOWS\system32\drivers\ssmdrv.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2002-10-15 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2002-10-15 114688]
"CTSysVol"="C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe" [2002-09-11 53248]
"SunJavaUpdateSched"="C:\Program Files\Java\jre6\bin\jusched.exe" [2008-10-24 136600]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 286720]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"CTHelper"="CTHELPER.EXE" [2007-04-09 C:\WINDOWS\system32\CtHelper.exe]
"EssSpkPhone"="essspk.exe" [2002-05-30 C:\WINDOWS\essspk.exe]
C:\Documents and Settings\Administrator.HOME-5E315BF5A7\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664]
C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\
Windows Search.lnk - C:\Program Files\Windows Desktop Search\WindowsSearch.exe [2008-05-26 123904]
C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\AutorunsDisabled
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe [2008-01-11 39792]
Adobe Reader Synchronizer.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2007-05-11 738968]
Kodak EasyShare software.lnk - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2008-05-10 282624]
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2008-06-23 118784]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"C:\\WINDOWS\\system32\\mmc.exe"=
R2 JavaQuickStarterService;Java Quick Starter;C:\Program Files\Java\jre6\bin\jqs.exe [2008-10-24 152984]
R3 ctgame;Game Port;C:\WINDOWS\system32\DRIVERS\ctgame.sys [2002-12-30 12160]
S3 SBRE;SBRE;C:\WINDOWS\system32\drivers\SBREdrv.sys [ ]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\Shell\AutoRun\command - setup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8882d75a-7cf3-11dd-a5ca-0008a174a0ac}]
\Shell\AutoRun\command - F:\System\DriveGuard\DriveProtect.exe -run
\Shell\Explore\Command - F:\System\DriveGuard\DriveProtect.exe -run
\Shell\Open\Command - F:\System\DriveGuard\DriveProtect.exe -run
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{93b6f101-cc8c-11dc-acfc-aa8fad93d89f}]
\Shell\AutoRun\command - setup.exe
*Newly Created Service* - SSMDRV
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{1EC04D97-5F10-DD1B-0306-020403060503}]
C:\WINDOWS\system32\SecSystem.exe
.
Contents of the 'Scheduled Tasks' folder
2008-10-30 C:\WINDOWS\Tasks\1-Click Maintenance.job
- C:\Program Files\TuneUp Utilities 2008\OneClickStarter.exe []
2008-10-30 C:\WINDOWS\Tasks\At1.job
- C:\WINDOWS\system32\svchost []
2008-10-27 C:\WINDOWS\Tasks\EasyShare Registration Task.job
- C:\WINDOWS\system32\rundll32.exe [2008-04-14 05:42]
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-10-30 13:22:39
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\system32\CTSVCCDA.EXE
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\searchindexer.exe
C:\WINDOWS\system32\searchprotocolhost.exe
C:\WINDOWS\system32\searchfilterhost.exe
C:\WINDOWS\system32\searchprotocolhost.exe
.
**************************************************************************
.
Completion time: 2008-10-30 13:29:33 - machine was rebooted
ComboFix-quarantined-files.txt 2008-10-30 07:59:27
ComboFix2.txt 2008-10-30 01:44:23
ComboFix3.txt 2008-10-30 01:01:50
Pre-Run: 4,444,672,000 bytes free
Post-Run: 4,471,721,984 bytes free
205 --- E O F --- 2008-10-29 18:45:52