Hiya Blade.... followed your instructions, hopefully did it right. Ran Combofix and am in normal mode now, with so far no sign of infection. Below is combofix log. Thanks!
ComboFix 09-06-07.01 - goodpaster 06/07/2009 17:14.1 - NTFSx86 NETWORK
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.511.380 [GMT -4:00]
Running from: c:\documents and settings\goodpaster\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\13182504
c:\documents and settings\All Users\Application Data\13182504\13182504.exe
c:\documents and settings\All Users\Application Data\13182504\13182504.glu
c:\documents and settings\All Users\Application Data\13182504\pc13182504cnf
c:\documents and settings\All Users\Application Data\13182504\pc13182504ins
c:\documents and settings\All Users\Application Data\93192496
c:\documents and settings\All Users\Application Data\93192496\93192496.exe
c:\documents and settings\goodpaster\Application Data\wiaserva.log
c:\windows\msa.exe
c:\windows\system32\13012.exe
c:\windows\system32\ativvax.dll
c:\windows\system32\drivers\ip_fw.sys
c:\windows\system32\dumphive.exe
c:\windows\system32\mcrh.tmp
c:\windows\system32\msxml71.dll
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\wbem\grpconv.exe
c:\windows\Tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job
c:\windows\Tasks\{783AF354-B514-42d6-970E-3E8BF0A5279C}.job
c:\windows\system32\grpconv.exe was missing
Restored copy from - c:\windows\ServicePackFiles\i386\grpconv.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_IPFW
-------\Legacy_IP_FW
-------\Service_ip_fw
-------\Service_ipfw
((((((((((((((((((((((((( Files Created from 2009-05-07 to 2009-06-07 )))))))))))))))))))))))))))))))
.
2009-06-04 21:44 . 2009-06-04 21:44 115716 ----a-w- c:\windows\msb.exe
2009-06-02 21:55 . 2009-06-02 21:55 -------- d-sh--w- c:\documents and settings\goodpaster\PrivacIE
2009-06-02 04:22 . 2009-06-02 04:22 -------- d-----w- c:\documents and settings\goodpaster\Local Settings\Application Data\Symantec
2009-06-02 03:28 . 2009-06-02 03:28 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Symantec
2009-06-01 23:32 . 2009-06-01 23:33 -------- d-----w- c:\program files\Windows Live Safety Center
2009-06-01 23:05 . 2009-06-01 23:05 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2009-05-23 00:00 . 2009-05-23 00:00 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2009-05-22 00:50 . 2009-05-22 00:52 -------- dc-h--w- c:\windows\ie8
2009-05-22 00:27 . 2008-02-26 11:59 294912 -c----w- c:\windows\system32\dllcache\msctf.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-04 22:09 . 2006-03-10 21:56 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-06-04 22:09 . 2006-03-10 21:56 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-06-02 04:22 . 2009-06-02 04:22 36784 ----a-w- c:\documents and settings\goodpaster\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-30 05:18 . 2009-04-12 21:15 -------- d-----w- c:\program files\Full Tilt Poker
2009-05-03 22:42 . 2004-11-12 23:09 -------- d-----w- c:\program files\LimeWire
2009-05-03 20:48 . 2004-11-12 23:08 -------- d-----w- c:\program files\Java
2009-04-21 02:10 . 2004-11-14 16:28 -------- d-----w- c:\program files\Hewlett-Packard
2009-04-21 02:08 . 2004-10-26 20:30 -------- d-----w- c:\program files\Common Files\InstallShield
2009-04-21 02:08 . 2004-10-26 20:31 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-04-21 02:08 . 2004-11-11 22:19 -------- d-----w- c:\program files\AIM
2009-04-21 02:05 . 2006-02-15 01:22 -------- d-----w- c:\program files\PokerStars
2009-04-16 01:45 . 2009-04-12 20:56 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-04-14 21:06 . 2009-04-14 21:06 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-04-14 21:04 . 2005-02-28 01:05 -------- d-----w- c:\program files\Common Files\Adobe
2009-04-14 20:55 . 2009-04-12 20:56 -------- d-----w- c:\program files\NOS
2009-04-12 20:45 . 2009-04-12 20:45 -------- d-----w- c:\program files\Misc. Support Library (Spybot - Search & Destroy)
2009-04-12 20:45 . 2009-04-12 20:45 -------- d-----w- c:\program files\TeaTimer (Spybot - Search & Destroy)
2009-04-12 20:45 . 2009-04-12 20:45 -------- d-----w- c:\program files\SDHelper (Spybot - Search & Destroy)
2009-04-12 20:45 . 2009-04-12 20:45 -------- d-----w- c:\program files\File Scanner Library (Spybot - Search & Destroy)
2009-04-09 01:38 . 2009-06-02 02:46 194948 ----a-w- c:\windows\PCHEALTH\HELPCTR\Config\Cache\Professional_32_1033.dat
2006-12-06 22:15 . 2006-12-06 22:15 5186048 ----a-w- c:\program files\WindowsDefender.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CoolSwitch"="c:\windows\System32\taskswitch.exe" [2002-03-19 45632]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2004-02-23 3026944]
"vptray"="c:\progra~1\SYMANT~1\SYMANT~1\vptray.exe" [2003-05-21 90112]
"NeroCheck"="c:\windows\system32\NeroCheck.exe" [2003-07-13 155648]
"RoxioEngineUtility"="c:\program files\Common Files\Roxio Shared\System\EngUtil.exe" [2004-11-12 65536]
"PowerMenu"="c:\windows\system32\powermenu.exe" [2002-12-20 57344]
"KBD"="c:\hp\KBD\KBD.EXE" [2003-02-11 61440]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"BluetoothAuthenticationAgent"="irprops.cpl" - c:\windows\system32\irprops.cpl [2004-08-04 380416]
"LTMSG"="LTMSG.exe" - c:\windows\ltmsg.exe [2003-07-14 40960]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\
0stera
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP

xpsp2res.dll,-22009
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
- - - - ORPHANS REMOVED - - - -
BHO-{0116D7B9-51A9-4CB6-BD04-3164753824C8} - c:\windows\system32\ativvax.dll
HKLM-Run-QuickTime Task - c:\program files\QuickTime\qttask.exe
HKLM-Run-13182504 - c:\documents and settings\All Users\Application Data\13182504\13182504.exe
HKLM-Run-93192496 - c:\documents and settings\All Users\Application Data\93192496\93192496.exe
SafeBoot-procexp90.Sys
.
------- Supplementary Scan -------
.
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-06-07 17:18
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(2112)
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
------------------------ Other Running Processes ------------------------
.
c:\progra~1\SYMANT~1\SYMANT~1\DefWatch.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\progra~1\SYMANT~1\SYMANT~1\Rtvscan.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\wscntfy.exe
c:\progra~1\SYMANT~1\SYMANT~1\DWHWizrd.exe
c:\windows\system32\imapi.exe
.
**************************************************************************
.
Completion time: 2009-06-07 17:25 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-07 21:25
Pre-Run: 9,195,847,680 bytes free
Post-Run: 9,196,482,560 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
156