ok heres the combofix log
ComboFix 08-06-01.6 - Caleb 2008-06-03 14:07:05.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.221 [GMT -5:00]
Running from: C:\Documents and Settings\TEMP.BERGQUES-UMDPSM.000\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\TEMP.BERGQUES-UMDPSM.000\Desktop\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\MyWebSearch
C:\Program Files\Uninstall Fun Web Products.dll
C:\WINDOWS\system32\A.tmp
C:\WINDOWS\system32\ctfmona.exe
C:\WINDOWS\system32\drivers\fad.sys
C:\WINDOWS\system32\hgGwWMeF.dll
.
((((((((((((((((((((((((( Files Created from 2008-05-03 to 2008-06-03 )))))))))))))))))))))))))))))))
.
2008-06-03 06:24 . 2008-06-02 18:15 160,256 --a------ C:\WINDOWS\system32\12.tmp
2008-06-02 18:09 . 2008-06-02 18:09 <DIR> d-------- C:\Documents and Settings\TEMP.BERGQUES-UMDPSM.000\Application Data\Symantec
2008-06-02 18:01 . 2008-06-02 18:01 <DIR> d-------- C:\WINDOWS\Speeditup Free
2008-06-02 18:01 . 2008-06-02 18:10 <DIR> d-------- C:\Program Files\Speeditup Free
2008-06-02 17:07 . 2008-06-02 17:07 73 --a------ C:\WINDOWS\st_affiliate.ini
2008-06-02 16:18 . 2008-06-02 16:18 <DIR> d-------- C:\Documents and Settings\TEMP.BERGQUES-UMDPSM.000\Application Data\AXPFixer
2008-06-02 16:05 . 2008-06-02 16:05 <DIR> d-------- C:\Deckard
2008-06-02 14:46 . 2008-06-02 18:15 269,334 --a------ C:\WINDOWS\system32\ctfmonb.bmp
2008-06-02 14:46 . 2008-06-03 06:25 160,256 --a------ C:\WINDOWS\system32\blackster.scr
2008-06-02 14:25 . 2008-06-02 14:25 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-06-02 14:25 . 2008-06-02 14:25 1,409 --a------ C:\WINDOWS\QTFont.for
2008-06-01 19:27 . 2008-06-02 14:48 <DIR> d-------- C:\Program Files\SpiralFrog
2008-05-09 16:31 . 2008-05-09 16:43 <DIR> d-------- C:\Program Files\ezt
2008-05-09 16:16 . 2008-05-09 16:16 <DIR> d-------- C:\Program Files\Free Offers from Freeze.com
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2008-06-03 13:00 --------- d-----w C:\Documents and Settings\TEMP.BERGQUES-UMDPSM.000\Application Data\AVG7
2008-06-02 23:14 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-06-02 20:21 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-05-24 19:07 --------- d-----w C:\Program Files\QuickVerse 2007
2008-05-22 18:08 --------- d-----w C:\Program Files\Yahoo!
2008-04-22 00:55 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-04-22 00:51 --------- d-----w C:\Program Files\Windows Live
2008-04-22 00:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-03-27 08:12 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56 15360]
"Aim6"="" []
"CTZDetec.exe"="C:\Program Files\Creative\Creative Media Lite\CTZDetec.exe" [2007-12-18 14:20 401408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"Share-to-Web Namespace Daemon"="C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2002-04-11 05:19 69632]
"AdaptecDirectCD"="C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-04-10 17:44 679936]
"Promon.exe"="Promon.exe" [2001-07-19 12:26 61440 C:\WINDOWS\system32\PROMon.exe]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 05:59 122880 C:\WINDOWS\BCMSMMSG.exe]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-22 13:22 7700480]
"nwiz"="nwiz.exe" [2006-10-22 13:22 1622016 C:\WINDOWS\system32\nwiz.exe]
"NAV Agent"="C:\PROGRA~1\NORTON~1\navapw32.exe" [ ]
"stcloader"="C:\WINDOWS\System32\stcloader.exe " [ ]
"winupdtl"="C:\WINDOWS\System32\winupdtl.exe" [ ]
"saie"="c:\windows\system32\saie.exe" [ ]
"mmrrcc"="C:\WINDOWS\System32\mmrrcc.exe" [ ]
"uFrR32l"="synspool.exe" []
"AutoUpdater"="C:\Program Files\AutoUpdate\AutoUpdate.exe" [ ]
"Win Server Updt"="C:\WINDOWS\wupdt.exe" [ ]
"zmbnzc"="C:\WINDOWS\System32\zmbnzc.exe" [ ]
"Windows ControlAd"="C:\Program Files\Windows ControlAd\WinCtlAd.exe" [ ]
"WebRebates0"="C:\Program Files\Web_Rebates\WebRebates0.exe" [ ]
"USB controller"="C:\DOCUME~1\JANETB~1\LOCALS~1\Temp\IC D1.tmp\svcmm32.exe" [ ]
"Xcpy1"="C:\Program Files\Common Files\Java\Xcpy1.exe" [ ]
"qmtsdsqlprr"="C:\WINDOWS\System32\gzoqtl.exe" [ ]
"jsluxid"="C:\WINDOWS\jsluxid.exe" [ ]
"farmmext"="C:\WINDOWS\farmmext.exe" [ ]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-04-15 09:07 579584]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray. dll" [2006-10-22 13:22 86016]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41 282624]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-06-01 16:51 257088]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06 40048]
"UnlockerAssistant"="C:\Program Files\Unlocker\UnlockerAssistant.exe" [ ]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-10-23 21:02 219136]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
hp psc 2000 Series.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe [2002-06-27 02:20:58 323646]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 02:01:04 83360]
officejet 6100.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe [2002-06-27 02:21:30 147456]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.MJPG"= m3jpeg32.dll
"vidc.dmb1"= m3jpeg32.dll
"vidc.3IV2"= 3ivxVfWCodec_dec.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\contro l\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\AIM\\aim.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
"C:\\Program Files\\EA Games\\Command and Conquer Generals\\game.dat"=
"C:\\WINDOWS\\system32\\dplaysvr.exe"=
"C:\\Program Files\\EA Games\\Command & Conquer Generals Zero Hour\\game.dat"=
"C:\\WINDOWS\\system32\\mmc.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\iTunes\\iTunesHelper.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
R2 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);"c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sMSSMLBIZ []
R2 NMSSvc;Intel(R) NMS;C:\WINDOWS\System32\NMSSvc.exe [2001-07-11 09:59]
R3 NMSCFG;NIC Management Service Configuration Driver;C:\WINDOWS\system32\drivers\NMSCFG.SYS [2001-07-11 09:59]
S3 MTK;Media Technology Kernel Driver;C:\WINDOWS\system32\Drivers\mtk.sys []
S3 UnlockerDriver4;UnlockerDriver4 Driver;C:\Program Files\Unlocker\UnlockerDriver4.sys []
*Newly Created Service* - CATCHME
*Newly Created Service* - NMSCFG
.
Contents of the 'Scheduled Tasks' folder
"2008-05-31 03:54:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2005-11-06 02:36:16 C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 2200 series#1112239132.job"
- C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe4-I
"2008-06-03 18:55:14 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
************************************************** ************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-06-03 14:09:41
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
************************************************** ************************
.
Completion time: 2008-06-03 14:13:08
ComboFix-quarantined-files.txt 2008-06-03 19:12:02
Pre-Run: 18,350,362,624 bytes free
Post-Run: 18,526,994,432 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOW S
[operating systems]
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Micro soft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
146 --- E O F --- 2008-06-03 08:01:48