Thanks very helpful!
Here is my log for the Combofix:
ComboFix 09-06-29.01 - Park 06/29/2009 16:19.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1526.989 [GMT -4:00]
Running from: c:\documents and settings\Park\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Park\Desktop\CFScript.txt
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\messenger\msmsgs.exe
.
((((((((((((((((((((((((( Files Created from 2009-05-28 to 2009-06-29 )))))))))))))))))))))))))))))))
.
2009-06-29 20:12 . 2009-06-29 20:12 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-06-29 19:45 . 2009-06-17 15:27 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-29 19:45 . 2009-06-29 19:45 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-29 19:45 . 2009-06-17 15:27 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-24 01:35 . 2009-06-24 01:35 -------- d-----w- c:\documents and settings\Park\Application Data\Malwarebytes
2009-06-24 01:35 . 2009-06-24 01:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-07 19:33 . 2009-06-25 23:34 -------- d-----w- c:\documents and settings\Park\Application Data\U3
2009-06-03 19:14 . 2009-06-03 19:14 98304 ----a-w- c:\windows\W2BNEUnin.exe
2009-06-03 19:14 . 2009-06-03 19:14 2829 ----a-w- c:\windows\W2BNEUnin.pif
2009-06-03 19:14 . 2009-06-03 19:14 20250 ----a-w- c:\windows\W2BNEUnin.dat
2009-06-03 19:13 . 2009-06-03 19:41 -------- d-----w- c:\program files\Warcraft II BNE
2009-06-03 17:07 . 2009-06-03 16:58 720896 ----a-w- c:\windows\iun6002.exe
2009-06-03 16:58 . 2009-06-17 01:44 -------- d-----w- c:\program files\Condition Zero
2009-06-02 19:56 . 2009-06-02 19:56 -------- d-----w- c:\documents and settings\Park\Application Data\Uniblue
2009-06-02 17:56 . 2002-03-25 22:44 722192 ----a-w- c:\windows\system32\VB40032.DLL
2009-06-02 17:56 . 2002-03-25 22:44 60416 ----a-w- c:\windows\ST4UNST.EXE
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2009-06-29 20:13 . 2005-12-29 19:49 -------- d-----w- c:\program files\Java
2009-06-29 03:52 . 2009-05-10 02:05 -------- d-----w- c:\program files\Starcraft
2009-06-25 21:56 . 2009-05-13 23:47 -------- d-----w- c:\documents and settings\Park\Application Data\uTorrent
2009-06-23 19:00 . 2009-05-21 20:56 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-06-23 18:58 . 2009-05-13 05:04 -------- d-----w- c:\program files\Common Files\Blizzard Entertainment
2009-06-11 03:05 . 2009-05-25 21:06 -------- d-----w- c:\program files\Diablo II
2009-06-04 19:19 . 2009-05-22 12:36 -------- d-----w- c:\program files\Counter-Strike 1.6 V35
2009-06-02 11:39 . 2009-05-21 20:57 -------- d-----w- c:\documents and settings\Park\Application Data\Apple Computer
2009-05-30 17:39 . 2009-05-30 17:39 86528 ----a-w- c:\windows\bnetunin.exe
2009-05-30 17:39 . 2009-05-30 17:39 61440 ----a-w- c:\windows\diabunin.exe
2009-05-27 14:27 . 2009-05-27 14:26 -------- d-----w- c:\program files\SopCast
2009-05-26 16:59 . 2009-05-26 16:59 -------- d-----w- c:\documents and settings\Park\Application Data\Moyea
2009-05-25 07:44 . 2009-05-25 06:41 21840 ----atw- c:\windows\system32\SIntfNT.dll
2009-05-25 07:44 . 2009-05-25 06:41 17212 ----atw- c:\windows\system32\SIntf32.dll
2009-05-25 07:44 . 2009-05-25 06:41 12067 ----atw- c:\windows\system32\SIntf16.dll
2009-05-21 20:57 . 2009-05-21 20:57 -------- d-----w- c:\program files\iTunes
2009-05-21 20:57 . 2009-05-21 20:57 -------- d-----w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-05-21 20:57 . 2009-05-21 20:57 -------- d-----w- c:\program files\iPod
2009-05-21 20:57 . 2009-05-21 20:54 -------- d-----w- c:\program files\Common Files\Apple
2009-05-21 20:56 . 2009-05-21 20:56 -------- d-----w- c:\program files\Bonjour
2009-05-21 20:56 . 2009-05-21 20:56 -------- d-----w- c:\program files\QuickTime
2009-05-21 20:55 . 2009-05-21 20:55 -------- d-----w- c:\program files\Apple Software Update
2009-05-21 20:54 . 2009-05-21 20:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2009-05-21 18:14 . 2009-05-19 18:29 -------- d-----w- c:\program files\Real Alternative
2009-05-19 20:19 . 2009-05-19 20:19 -------- d-----w- c:\documents and settings\Park\Application Data\Media Player Classic
2009-05-19 18:28 . 2005-12-29 20:22 -------- d-----w- c:\program files\Common Files\Real
2009-05-15 01:26 . 2005-12-29 18:26 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-05-14 21:20 . 2009-05-14 21:20 -------- d-----w- c:\program files\Microsoft Games
2009-05-14 01:36 . 2009-05-14 01:36 -------- d-----w- c:\program files\ICCup
2009-05-13 23:48 . 2009-05-13 23:48 -------- d-----w- c:\program files\uTorrent
2009-05-12 19:46 . 2009-05-12 19:46 -------- d-----w- c:\documents and settings\Park\Application Data\GRETECH
2009-05-12 19:20 . 2009-05-10 03:07 76632 ----a-w- c:\documents and settings\Park\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-12 18:55 . 2009-05-12 18:44 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-05-12 18:50 . 2009-05-12 18:50 -------- d-----w- c:\program files\Microsoft Works
2009-05-12 18:50 . 2009-05-12 18:50 -------- d-----w- c:\program files\MSBuild
2009-05-12 18:48 . 2009-05-12 18:48 -------- d-----w- c:\program files\Microsoft.NET
2009-05-10 04:39 . 2009-05-10 04:36 34811 ----a-w- c:\windows\scunin.dat
2009-05-10 04:39 . 2009-05-10 04:36 967 ----a-w- c:\windows\ScUnin.pif
2009-05-10 04:39 . 2009-05-10 04:36 94208 ----a-w- c:\windows\ScUnin.exe
2009-05-10 02:17 . 2005-12-29 19:44 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee.com
2009-05-10 02:09 . 2009-05-10 02:09 -------- d-----w- c:\program files\PowerISO
2009-05-08 19:56 . 2009-05-08 19:56 -------- d-----w- c:\documents and settings\Park\Application Data\AdobeUM
2009-05-08 07:02 . 2009-05-08 07:02 -------- d-----w- c:\program files\MSXML 4.0
2009-05-07 00:57 . 2005-12-29 20:22 -------- d-----w- c:\program files\Pure Networks
2009-05-07 00:57 . 2005-12-29 20:21 -------- d-----w- c:\program files\Common Files\AOL
2009-05-07 00:56 . 2005-12-29 19:46 -------- d-----w- c:\program files\Quicken
2009-05-07 00:55 . 2005-12-29 19:48 -------- d-----w- c:\program files\Sonic
2009-05-07 00:53 . 2005-12-29 20:21 -------- d-----w- c:\documents and settings\All Users\Application Data\AOL
2009-05-07 00:53 . 2009-05-07 01:02 -------- d-----w- c:\documents and settings\Park\Application Data\AOL
2009-05-07 00:52 . 2009-05-07 00:52 -------- d-----w- c:\program files\ArcSoft
2009-05-07 00:51 . 2009-05-07 01:02 -------- d-----w- c:\documents and settings\Park\Application Data\Intel
2009-05-07 00:51 . 2009-05-07 00:51 21275 ----a-w- c:\windows\system32\drivers\AegisP.sys
2009-05-07 00:51 . 2009-05-07 00:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Intel
2009-05-07 00:51 . 2005-12-29 18:00 -------- d-----w- c:\program files\Intel
2009-05-07 00:51 . 2009-05-07 00:51 -------- d-----w- c:\program files\InterVideo
2009-05-06 22:46 . 2009-05-06 22:46 -------- d-----w- c:\documents and settings\Park\Application Data\InterVideo
2009-05-06 22:02 . 2009-05-06 21:21 -------- d-----w- c:\documents and settings\All Users\Application Data\Estsoft
2009-05-06 22:02 . 2009-05-06 21:19 -------- d-----w- c:\documents and settings\Park\Application Data\ESTsoft
2009-05-06 21:55 . 2009-05-06 21:55 153 ----a-w- C:\DelUS.bat
2009-05-06 21:46 . 2009-05-06 21:46 -------- d-----w- c:\program files\Avira
2009-05-06 21:46 . 2009-05-06 21:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2009-05-06 21:19 . 2009-05-06 21:19 -------- d-----w- c:\program files\ESTsoft
2009-05-06 21:13 . 2009-05-06 21:13 -------- d-----w- c:\program files\GRETECH
2009-04-02 20:29 . 2009-04-02 20:29 75048 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.1.1.10\SetupAdmin.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-11-28 98304]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-11-28 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-11-28 118784]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-12-05 667718]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-11-28 602182]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-10-06 122940]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2004-03-24 196608]
"HWSetup"="c:\program files\TOSHIBA\TOSHIBA Applet\HWSetup.exe" [2004-05-01 28672]
"SVPWUTIL"="c:\program files\Toshiba\Windows Utilities\SVPWUTIL.exe" [2004-05-01 65536]
"Tvs"="c:\program files\Toshiba\Tvs\TvsTray.exe" [2005-11-30 73728]
"CeEKEY"="c:\program files\TOSHIBA\E-KEY\CeEKey.exe" [2005-12-01 671744]
"PadTouch"="c:\program files\TOSHIBA\Touch and Launch\PadExe.exe" [2005-07-15 1077322]
"SmoothView"="c:\program files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [2005-04-27 122880]
"TPNF"="c:\program files\TOSHIBA\TouchPad\TPTray.exe" [2005-12-14 53248]
"Pinger"="c:\toshiba\ivp\ism\pinger.exe" [2005-03-18 151552]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.E XE" [2004-08-04 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScI nst.exe" [2004-08-04 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT \TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TIN TSETP.EXE" [2004-08-04 455168]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2007-08-07 200704]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_04\bin\jusched.exe" [2005-06-03 36975]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\agrsmmsg.exe [2005-10-15 88203]
"NDSTray.exe"="NDSTray.exe" [BU]
"TPSMain"="TPSMain.exe" - c:\windows\system32\TPSMain.exe [2005-06-01 282624]
"ZoomingHook"="ZoomingHook.exe" - c:\windows\system32\ZoomingHook.exe [2005-06-06 24576]
"TCtryIOHook"="TCtrlIOHook.exe" - c:\windows\system32\TCtrlIOHook.exe [2005-12-05 28672]
"TFncKy"="TFncKy.exe" [BU]
"TDispVol"="TDispVol.exe" - c:\windows\system32\TDispVol.exe [2005-12-28 73728]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
RAMASST.lnk - c:\windows\system32\RAMASST.exe [2005-12-29 155648]
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\TOSHIBA\\ivp\\NetInt\\Netint.exe"=
"c:\\TOSHIBA\\Ivp\\ISM\\pinger.exe"= c:\\TOSHIBA\\IVP\\ISM\\pinger.exe
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [5/6/2009 5:46 PM 108289]
.
Contents of the 'Scheduled Tasks' folder
2009-06-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Uniblue RegistryBooster 2009 - c:\program files\Uniblue\RegistryBooster\RegistryBooster.exe
.
------- Supplementary Scan -------
.
uInternet Connection Wizard,ShellNext = hxxp://www.toshibadirect.com/dpdstart
IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
IE: Backward Links - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Similar Pages - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate into English - c:\program files\Google\GoogleToolbar1.dll/cmtrans.html
FF - ProfilePath - c:\documents and settings\Park\Application Data\Mozilla\Firefox\Profiles\v5gsatbe.default\
FF - plugin: c:\program files\Java\jre1.5.0_04\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_04\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_04\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_04\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_04\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_04\bin\NPJPI150_04.dll
FF - plugin: c:\program files\Java\jre1.5.0_04\bin\NPOJI610.dll
.
************************************************** ************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
GMER - Rootkit Detector and Remover
Rootkit scan 2009-06-29 16:23
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(3200)
c:\windows\system32\TDispVol.dll
c:\windows\system32\msi.dll
c:\windows\system32\TPwrCfg.DLL
c:\windows\system32\TPwrReg.dll
c:\windows\system32\TPSTrace.DLL
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Toshiba\ConfigFree\CFSvcs.exe
c:\windows\system32\DVDRAMSV.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\toshiba\IVP\swupdate\swupdtmr.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Toshiba\ConfigFree\NDSTray.exe
c:\program files\Apoint2K\ApntEx.exe
c:\windows\system32\TPSBattM.exe
c:\progra~1\Intel\Wireless\Bin\Dot1XCfg.exe
c:\windows\system32\wscntfy.exe
c:\program files\iPod\bin\iPodService.exe
.
************************************************** ************************
.
Completion time: 2009-06-29 16:25 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-29 20:25
Pre-Run: 31,898,116,096 bytes free
Post-Run: 31,881,211,904 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOW S
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Micro soft Windows XP Home Edition" /noexecute=optin /fastdetect
230 --- E O F --- 2009-05-08 07:09