Mr. Jak3, I think that may have gotten it!
Here is the combofix log and a Spybot log -
ComboFix 07-06-13.3 - C:\Documents and Settings\Glenn\Desktop\ComboFix.exe
"Glenn" - 2007-06-13 11:26:28 - Service Pack 2 NTFS
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\DOCUME~1\Glenn\APPLIC~1.\.rdr.ini
C:\Temp\tn3
C:\WINDOWS\cs_cache.ini
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_ASPI113210
-------\LEGACY_CORE
-------\LEGACY_WINCOM32
-------\windbg48
-------\core
((((((((((((((((((((((((( Files Created from 2007-05-13 to 2007-06-13 )))))))))))))))))))))))))))))))
2007-06-13 11:26 49,152 --a------ C:\WINDOWS\nircmd.exe
2007-06-12 14:57 <DIR> d--h----- C:\WINDOWS\PIF
2007-06-09 10:01 <DIR> d-------- C:\Program Files\iTunes
2007-06-09 10:01 <DIR> d-------- C:\Program Files\iPod
2007-06-09 09:58 <DIR> d-------- C:\Program Files\QuickTime
2007-06-08 10:33 <DIR> d-------- C:\Program Files\RFA Platinum
2007-06-08 10:33 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\RFA_Backups
2007-06-08 09:50 <DIR> d-------- C:\Program Files\CCleaner
2007-06-07 16:01 <DIR> d-------- C:\Program Files\MSXML 6.0
2007-06-07 15:53 <DIR> d-------- C:\Program Files\MSBuild
2007-06-07 15:47 <DIR> d-------- C:\WINDOWS\system32\XPSViewer
2007-06-07 15:47 <DIR> d-------- C:\Program Files\Reference Assemblies
2007-06-07 15:46 14,048 --------- C:\WINDOWS\system32\spmsg2.dll
2007-06-07 15:46 <DIR> d-------- C:\4c484d75baf431bcb7847fc87c
2007-06-07 15:43 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2007-06-07 15:40 36,352 --------- C:\WINDOWS\system32\tsgqec.dll
2007-06-07 15:40 288,768 --------- C:\WINDOWS\system32\rhttpaa.dll
2007-06-07 15:40 116,736 --------- C:\WINDOWS\system32\aaclient.dll
2007-06-07 15:12 <DIR> d-a------ C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
2007-06-07 14:15 874 --a------ C:\WINDOWS\system32\tmp.reg
2007-06-05 09:04 69,632 --a------ C:\WINDOWS\system32\asprouni.exe
2007-06-05 09:03 <DIR> d-------- C:\WINDOWS\system32\ASPRO
2007-06-05 08:46 786,432 --a------ C:\DOCUME~1\ADMINI~1\NTUSER.DAT
2007-05-14 22:30 0 --a------ C:\DOCUME~1\Glenn\win32.exe
2007-05-14 22:29 0 --a------ C:\DOCUME~1\Glenn\win.exe
2007-05-14 22:29 0 --a------ C:\DOCUME~1\Glenn\flash.exe
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-06-12 17:12:42 -------- d-----w C:\Program Files\Messenger
2007-06-09 18:01:23 -------- d-----w C:\DOCUME~1\Glenn\APPLIC~1\Apple Computer
2007-06-07 23:45:25 -------- d-----w C:\Program Files\Windows Media Connect 2
2007-06-05 17:21:08 -------- d-----w C:\Program Files\fsupport
2007-05-16 15:12:02 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-04-25 14:21:15 144,896 ----a-w C:\WINDOWS\system32\schannel.dll
2007-04-18 16:12:23 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll
2007-04-17 06:47:36 33,624 ----a-w C:\WINDOWS\system32\wups.dll
2007-04-17 06:45:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-17 06:45:48 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-04-17 06:45:42 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-04-17 06:45:36 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-04-17 06:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-04-17 06:45:20 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-17 06:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
2007-04-17 06:44:20 271,224 ----a-w C:\WINDOWS\system32\mucltui.dll
2007-04-17 06:44:18 208,248 ----a-w C:\WINDOWS\system32\muweb.dll
2007-04-14 17:54:48 -------- d-----w C:\Program Files\Apple Software Update
2007-03-23 14:07:56 1,683,280 ------w C:\WINDOWS\system32\XpsSvcs.dll
2007-03-23 14:07:54 583,504 ------w C:\WINDOWS\system32\XPSSHHDR.dll
2007-03-23 04:25:02 124,928 ------w C:\WINDOWS\system32\prntvpt.dll
2007-03-17 13:43:01 292,864 ----a-w C:\WINDOWS\system32\winsrv.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{02478D38-C3F9-4EFB-9B51-7695ECA05670}=C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2006-10-26 11:28]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}=C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2006-01-12 20:38]
{53707962-6F74-2D53-2644-206D7942484F}=C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2005-05-31 01:04]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll [2007-03-14 03:43]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-06-06 12:35]
"rfagent"="C:\Program Files\RFA Platinum\rfagent.exe" [2007-04-14 16:38]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-06-01 16:51]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 08:24]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2006-11-30 22:49]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoDispAppearancePage"=0 (0x0)
"NoColorChoice"=0 (0x0)
"NoSizeChoice"=0 (0x0)
"NoDispBackgroundPage"=0 (0x0)
"NoDispScrSavPage"=0 (0x0)
"NoDispCPL"=0 (0x0)
"NoVisualStyleChoice"=0 (0x0)
"NoDispSettingsPage"=0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoActiveDesktopChanges"=0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSaveSettings"=0 (0x0)
"NoThemesTab"=0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Utility]
Logi_MwX.Exe
Contents of the 'Scheduled Tasks' folder
2007-06-09 17:53:01 C:\WINDOWS\tasks\AppleSoftwareUpdate.job
**************************************************************************
catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-06-13 11:31:02
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
? [4012]
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-06-13 11:32:01 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-06-13 11:31
--- E O F ---
--------------------------------------------------------------------------
Microsoft.Windows.ActiveDesktop: User settings (Registry change, nothing done)
HKEY_USERS\S-1-5-21-1123561945-2139871995-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoHTMLWallPaper!=W=1
--- Spybot - Search & Destroy version: 1.4 (build: 20050523) ---
2005-05-31 blindman.exe (1.0.0.1)
2005-05-31 SpybotSD.exe (1.4.0.3)
2005-05-31 TeaTimer.exe (1.4.0.2)
2006-06-26 unins000.exe (51.41.0.0)
2005-05-31 Update.exe (1.4.0.0)
2007-05-23 advcheck.dll (1.5.3.0)
2005-05-31 aports.dll (2.1.0.0)
2005-05-31 borlndmm.dll (7.0.4.453)
2005-05-31 delphimm.dll (7.0.4.453)
2005-05-31 SDHelper.dll (1.4.0.0)
2007-01-02 Tools.dll (2.0.1.0)
2005-05-31 UnzDll.dll (1.73.1.1)
2005-05-31 ZipDll.dll (1.73.2.0)
2007-06-13 Includes\Cookies.sbi (*)
2007-05-30 Includes\Dialer.sbi (*)
2007-06-13 Includes\DialerC.sbi (*)
2007-06-13 Includes\Hijackers.sbi (*)
2007-06-13 Includes\HijackersC.sbi (*)
2006-10-27 Includes\Keyloggers.sbi (*)
2007-06-13 Includes\KeyloggersC.sbi (*)
2007-05-30 Includes\Malware.sbi (*)
2007-06-13 Includes\MalwareC.sbi (*)
2007-03-21 Includes\PUPS.sbi (*)
2007-06-13 Includes\PUPSC.sbi (*)
2007-06-13 Includes\Revision.sbi (*)
2007-05-30 Includes\Security.sbi (*)
2007-06-13 Includes\SecurityC.sbi (*)
2007-06-06 Includes\Spybots.sbi (*)
2007-06-13 Includes\SpybotsC.sbi (*)
2005-02-17 Includes\Tracks.uti
2007-05-16 Includes\Trojans.sbi (*)
2007-06-13 Includes\TrojansC.sbi (*)
2007-06-06 Plugins\TCPIPAddress.dll