I suppose you're right. Here's the log:
ComboFix 08-01-04.1 - ibm 2008-01-08 15:16:46.4 - NTFSx86
Running from: C:\Documents and Settings\ibm\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\ibm\Desktop\CFScript.txt
* Created a new restore point
FILE
C:\WINDOWS\IFinst25.exe
c:\windows\inf\biini.inf
C:\WINDOWS\inf\biR.inf
C:\WINDOWS\inf\btgrab.inf
c:\windows\inf\dlmax.inf
c:\windows\inf\farmmext.inf
C:\WINDOWS\inf\polmx2.inf
c:\windows\kwv2.dat
c:\windows\smdat32a.sys
c:\windows\smdat32m.sys
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\ibm\application data\lycos
c:\program files\common files\searchupgrader
c:\program files\common files\searchupgrader\client.cfg
c:\program files\common files\searchupgrader\system.cfg
c:\program files\need2find
C:\SDFix
C:\SDFix\apps\assosfix.reg
C:\SDFix\apps\cliptext.exe
C:\SDFix\apps\download.exe
C:\SDFix\apps\dummy.exe
C:\SDFix\apps\dummy.sys
C:\SDFix\apps\Enable_Command_Prompt.reg
C:\SDFix\apps\ERDNT.E_E
C:\SDFix\apps\ERDNTDOS.LOC
C:\SDFix\apps\ERDNTWIN.LOC
C:\SDFix\apps\ERUNT.EXE
C:\SDFix\apps\ERUNT.LOC
C:\SDFix\apps\fix.reg
C:\SDFix\apps\FixBH.reg
C:\SDFix\apps\FIXCU.reg
C:\SDFix\apps\FIXLM.reg
C:\SDFix\apps\FixPath.exe
C:\SDFix\apps\FixRedir.reg
C:\SDFix\apps\FixWebCheck.reg
C:\SDFix\apps\fixXP.reg
C:\SDFix\apps\FixXPsp2.reg
C:\SDFix\apps\HPFix.reg
C:\SDFix\apps\HPFix2.reg
C:\SDFix\apps\HPFix3.reg
C:\SDFix\apps\HPFix4.reg
C:\SDFix\apps\isadmin.exe
C:\SDFix\apps\leg2.txt
C:\SDFix\apps\legacy.txt
C:\SDFix\apps\legacybk.txt
C:\SDFix\apps\locate.com
C:\SDFix\apps\LS.exe
C:\SDFix\apps\MD5File.exe
C:\SDFix\apps\MyGcpvFix.reg
C:\SDFix\apps\MyGkFix2.reg
C:\SDFix\apps\Process.exe
C:\SDFix\apps\procs.exe
C:\SDFix\apps\psservice.exe
C:\SDFix\apps\RegDACL.exe
C:\SDFix\apps\regedit.exe
C:\SDFix\apps\Rem.txt
C:\SDFix\apps\Rem2.txt
C:\SDFix\apps\Replace\W2K.exe
C:\SDFix\apps\Replace\w2k\beep.sys
C:\SDFix\apps\Replace\w2k\null.sys
C:\SDFix\apps\Replace\XP.exe
C:\SDFix\apps\Replace\xp\beep.sys
C:\SDFix\apps\Replace\xp\null.sys
C:\SDFix\apps\Reset_AppInit_DLLs.reg
C:\SDFix\apps\RestartIt!.exe
C:\SDFix\apps\Restore_SecurityCenter.reg
C:\SDFix\apps\Restore_SharedAccess.reg
C:\SDFix\apps\sc.exe
C:\SDFix\apps\SecurityProviders.reg
C:\SDFix\apps\SF.exe
C:\SDFix\apps\shutdown.exe
C:\SDFix\apps\srv2.txt
C:\SDFix\apps\svc.txt
C:\SDFix\apps\svcbk.txt
C:\SDFix\apps\swreg.exe
C:\SDFix\apps\swsc.exe
C:\SDFix\apps\unzip.exe
C:\SDFix\apps\WINMSG.EXE
C:\SDFix\apps\zip.exe
C:\SDFix\backups\attrib.exe
C:\SDFix\backups\backupreg.zip
C:\SDFix\backups\find.exe
C:\SDFix\backups\findstr.exe
C:\SDFix\backups\regedit.exe
C:\SDFix\catchme.exe
C:\SDFix\dummy.exe
C:\SDFix\dummy.sys
C:\SDFix\Report.txt
C:\SDFix\RunThis.cmd
C:\SDFix\SDFIX_ReadMe_Online.url
C:\WINDOWS\IFinst25.exe
c:\windows\inf\biini.inf
C:\WINDOWS\inf\biR.inf
C:\WINDOWS\inf\btgrab.inf
c:\windows\inf\dlmax.inf
c:\windows\inf\farmmext.inf
C:\WINDOWS\inf\polmx2.inf
c:\windows\kwv2.dat
c:\windows\smdat32a.sys
c:\windows\smdat32m.sys
c:\windows\system32\fleok
c:\windows\system32\fleok\log.bak.txt
.
((((((((((((((((((((((((( Files Created from 2007-12-08 to 2008-01-08 )))))))))))))))))))))))))))))))
.
2008-01-07 14:43 . 2008-01-07 14:44 <DIR> d-------- C:\Program Files\Panda Security
2008-01-06 10:19 . 2008-01-06 10:19 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-01-06 10:18 . 2008-01-06 10:18 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-01-05 13:08 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-05 12:31 . 2008-01-05 12:31 <DIR> d-------- C:\WINDOWS\ERUNT
2008-01-04 17:42 . 2008-01-04 17:42 <DIR> d-------- C:\Program Files\Trend Micro
2008-01-02 23:09 . 2008-01-02 23:09 <DIR> d-------- C:\Program Files\Uniblue
2008-01-02 23:09 . 2008-01-02 23:09 <DIR> d-------- C:\Documents and Settings\ibm\Application Data\Uniblue
2007-12-20 19:49 . 2007-12-26 11:22 <DIR> d-------- C:\WINDOWS\.jagex_cache_32
2007-12-12 19:54 . 2008-01-06 19:25 <DIR> d-------- C:\Program Files\BitAccelerator
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-03 04:54 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-01-03 04:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\Ulead Systems
2008-01-03 04:53 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-03 03:53 --------- d-----w C:\Program Files\Netscape
2008-01-03 03:48 --------- d-----w C:\Program Files\mIRC
2008-01-03 03:40 --------- d-----w C:\Program Files\Winamp
2007-12-21 10:33 --------- d-----w C:\Program Files\Java
2007-12-21 08:06 33,816 ----a-w C:\Documents and Settings\ibm\Application Data\GDIPFONTCACHEV1.DAT
2007-12-14 04:30 --------- d-----w C:\Program Files\Extractor
2005-08-18 05:55 6,144 --sha-w C:\Program Files\Thumbs.db
2005-06-19 03:27 40 ----a-w C:\Documents and Settings\ibm\language.dat
.
((((((((((((((((((((((((((((( snapshot@2008-01-05_13.20.20.73 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-08-21 20:37:26 124,208 ----a-w C:\WINDOWS\Downloaded Program Files\ascstubie.dll
+ 2007-07-18 20:49:56 12,592 ----a-w C:\WINDOWS\Downloaded Program Files\libcomm.dll
+ 2000-08-31 14:00:00 163,328 ----a-w C:\WINDOWS\erdnt\subs\ERDNT.EXE
+ 2005-05-24 18:27:16 213,048 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 21:47:20 94,208 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 21:49:54 950,272 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:56 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TrackPointSrv"="tp4mon.exe" [2004-08-04 01:56 82432 C:\WINDOWS\system32\tp4mon.exe]
"vptray"="C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe" [2003-04-26 01:18 90112]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2004-05-08 16:00 98304]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2004-10-09 00:00 180269]
"PRISMSVR.EXE"="C:\WINDOWS\system32\PRISMSVR.exe" [2004-04-13 19:45 290905]
"SansaDispatch"="C:\Program Files\SanDisk\Sansa Updater\SansaDispatch.exe" [2007-05-02 18:00 55368]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Belkin Wireless Utility.lnk - C:\Program Files\Belkin\Cardbus F5D7010\Wireless Utility\Belkinwcui.exe [2005-08-18 16:09:58]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 00:01:04]
R3 BLKWGN;Belkin Wireless G Notebook Card Service;C:\WINDOWS\system32\DRIVERS\BLKWGN.sys [2005-06-01 20:10]
R3 SndTDriverV32;SndTDriverV32;C:\WINDOWS\system32\drivers\SndTDriverV32.sys [2007-04-03 14:13]
R3 wlanndi5;wlanndi5 NDIS Protocol Driver;C:\WINDOWS\system32\wlanndi5.SYS [2004-04-21 16:51]
S3 LSWPCv4;Wireless-B Notebook Adapter Driver;C:\WINDOWS\system32\DRIVERS\LSRTNDS.SYS [2003-04-14 11:25]
S3 WmaCDriverV32;WmaCDriverV32;C:\WINDOWS\system32\drivers\WmaCDriverV32.sys [2007-04-03 14:12]
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-01-08 15:23:23
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\System32\NavLogon.dll
.
Completion time: 2008-01-08 15:26:36
ComboFix-quarantined-files.txt 2008-01-08 21:26:17
ComboFix2.txt 2008-01-07 01:38:26
ComboFix3.txt 2008-01-06 08:01:41
ComboFix4.txt 2008-01-05 19:21:58
.
2007-07-08 03:56:05 --- E O F ---