Okay, I figured it out. Here is my Combofix log:
ComboFix 09-06-07.03 - HP_Owner 06/07/2009 20:33.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.503.125 [GMT -4:00]
Running from: c:\documents and settings\HP_Owner\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\temp\vtmp2
c:\windows\system32\fustqcae.ini
c:\windows\system32\nkjxnxmv.ini
c:\windows\system32\xpeptfwx.ini
D:\Autorun.inf
D:\Desktop.ini
.
((((((((((((((((((((((((( Files Created from 2009-05-08 to 2009-06-08 )))))))))))))))))))))))))))))))
.
2009-06-07 17:58 . 2009-06-07 17:58 -------- d-----w- c:\program files\LSI SoftModem
2009-06-07 17:32 . 2004-11-02 12:58 163840 ----a-w- c:\windows\system32\igfxres.dll
2009-06-07 17:25 . 2009-06-07 17:25 -------- d-----w- c:\windows\system32\RTCOM
2009-06-06 11:20 . 2009-06-07 16:12 -------- d-----w- c:\documents and settings\All Users\Application Data\PCPitstop
2009-06-06 11:20 . 2009-06-07 16:12 -------- d-----w- c:\program files\PCPitstop
2009-06-05 01:29 . 2009-06-05 10:15 -------- d--h--w- C:\$AVG8.VAULT$
2009-06-03 11:05 . 2009-06-03 11:05 -------- d-----w- c:\program files\iPod
2009-06-03 11:05 . 2009-06-03 11:05 -------- d-----w- c:\program files\iTunes
2009-06-03 10:57 . 2009-06-03 10:58 -------- d-----w- c:\program files\QuickTime
2009-05-30 16:50 . 2009-05-30 16:50 75048 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.2.0.23\SetupAdmin.exe
2009-05-30 12:08 . 2009-05-30 12:08 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-05-30 12:08 . 2009-05-30 12:08 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-05-30 12:08 . 2009-05-30 12:08 325896 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-05-30 12:08 . 2009-05-30 12:08 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-05-30 12:08 . 2009-06-07 21:38 -------- d-----w- c:\windows\system32\drivers\Avg
2009-05-30 12:08 . 2009-06-06 12:32 -------- d-----w- c:\documents and settings\HP_Owner\Application Data\AVGTOOLBAR
2009-05-30 12:08 . 2009-05-30 12:08 -------- d-----w- c:\program files\AVG
2009-05-30 12:08 . 2009-05-30 12:08 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-05-29 00:51 . 2009-05-29 21:47 -------- d-----w- c:\program files\MeadCo Neptune
2009-05-29 00:37 . 2009-05-29 00:37 152576 ----a-w- c:\documents and settings\HP_Owner\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-05-28 10:37 . 2009-05-28 10:52 -------- d-----w- c:\documents and settings\HP_Owner\.SunDownloadManager
2009-05-28 10:12 . 2009-05-28 10:12 -------- d-----w- c:\program files\Secunia
2009-05-28 00:06 . 2009-03-06 14:22 284160 -c----w- c:\windows\system32\dllcache\pdh.dll
2009-05-28 00:06 . 2009-02-09 12:10 401408 -c----w- c:\windows\system32\dllcache\rpcss.dll
2009-05-28 00:06 . 2009-02-09 12:10 473600 -c----w- c:\windows\system32\dllcache\fastprox.dll
2009-05-28 00:06 . 2009-02-09 12:10 453120 -c----w- c:\windows\system32\dllcache\wmiprvsd.dll
2009-05-28 00:06 . 2009-02-06 11:11 110592 -c----w- c:\windows\system32\dllcache\services.exe
2009-05-28 00:06 . 2009-02-06 10:10 227840 -c----w- c:\windows\system32\dllcache\wmiprvse.exe
2009-05-28 00:06 . 2009-02-09 12:10 729088 -c----w- c:\windows\system32\dllcache\lsasrv.dll
2009-05-28 00:06 . 2009-02-09 12:10 714752 -c----w- c:\windows\system32\dllcache\ntdll.dll
2009-05-28 00:06 . 2009-02-09 12:10 617472 -c----w- c:\windows\system32\dllcache\advapi32.dll
2009-05-28 00:06 . 2009-02-06 11:08 2189056 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2009-05-28 00:06 . 2009-02-06 11:06 2145280 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-05-28 00:06 . 2009-02-06 10:32 2023936 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2009-05-28 00:04 . 2008-10-24 11:21 455296 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2009-05-28 00:03 . 2008-12-11 10:57 333952 -c----w- c:\windows\system32\dllcache\srv.sys
2009-05-27 23:55 . 2008-10-15 16:34 337408 -c----w- c:\windows\system32\dllcache\netapi32.dll
2009-05-27 23:55 . 2008-09-04 17:15 1106944 -c----w- c:\windows\system32\dllcache\msxml3.dll
2009-05-27 23:53 . 2008-05-03 11:55 2560 ------w- c:\windows\system32\xpsp4res.dll
2009-05-27 23:53 . 2008-04-21 12:08 215552 -c----w- c:\windows\system32\dllcache\wordpad.exe
2009-05-23 21:37 . 2009-05-23 21:37 -------- d-----w- c:\program files\CCleaner
2009-05-17 19:01 . 2003-10-02 04:01 27965 ----a-w- c:\windows\system32\EPPICPresetData_JP.dat
2009-05-17 19:01 . 2003-10-02 04:00 91923 ----a-w- c:\windows\system32\EPPICPrinterDB.dat
2009-05-17 19:01 . 2003-10-02 04:00 76956 ----a-w- c:\windows\system32\EPPICPattern2.dat
2009-05-17 19:01 . 2003-10-02 04:00 39121 ----a-w- c:\windows\system32\EPPICPattern1.dat
2009-05-17 19:01 . 2002-11-01 04:00 65536 ----a-w- c:\windows\system32\EPPicMgr.dll
2009-05-17 19:01 . 2002-11-01 04:00 114688 ----a-w- c:\windows\system32\EpPicPrt.dll
2009-05-17 19:01 . 2003-10-02 04:00 413696 ----a-w- c:\windows\system32\PICSDK.dll
2009-05-15 19:58 . 2009-05-15 19:58 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-07 00:49 . 2008-03-20 19:21 -------- d-----w- c:\documents and settings\HP_Owner\Application Data\Apple Computer
2009-06-05 01:46 . 2008-03-21 23:23 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2009-06-05 01:46 . 2004-10-22 21:12 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-06-03 11:05 . 2009-04-15 22:30 -------- d-----w- c:\program files\Common Files\Apple
2009-05-30 12:16 . 2008-03-22 15:39 1222 -c--a-w- c:\documents and settings\HP_Owner\Application Data\wklnhst.dat
2009-05-30 12:03 . 2008-03-21 23:24 -------- d-----w- c:\program files\Norton 360
2009-05-30 12:03 . 2008-03-21 23:23 -------- d-----w- c:\program files\Symantec
2009-05-29 00:38 . 2008-12-02 23:15 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-05-28 10:36 . 2004-10-22 00:27 -------- d-----w- c:\program files\Java
2009-05-27 22:49 . 2008-12-03 21:32 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-05-27 22:49 . 2009-02-02 00:19 3371383 -c--a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-05-26 17:20 . 2008-12-03 21:32 40160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-26 17:19 . 2008-12-03 21:32 19096 -c--a-w- c:\windows\system32\drivers\mbam.sys
2009-05-23 22:36 . 2008-10-27 20:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-05-23 14:44 . 2009-03-23 00:55 -------- d-----w- c:\program files\Winamp
2009-05-23 14:44 . 2004-10-22 01:46 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-05-07 22:23 . 2009-05-07 22:23 -------- d-----w- c:\documents and settings\All Users\Application Data\muvee Technologies
2009-04-21 00:46 . 2008-10-31 18:22 -------- d-----w- c:\program files\Support Tools
2009-04-15 22:34 . 2009-04-15 22:33 -------- d-----w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-04-15 22:32 . 2009-04-15 22:32 -------- d-----w- c:\program files\Bonjour
2009-04-15 22:31 . 2004-10-22 01:58 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-04-15 22:30 . 2009-04-15 22:30 -------- d-----w- c:\program files\Apple Software Update
2009-04-15 22:30 . 2009-04-15 22:30 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2009-04-12 12:34 . 2008-03-25 23:58 -------- d-----w- c:\program files\Common Files\Adobe
2009-03-25 10:29 . 2009-03-25 10:29 130432 ----a-w- c:\windows\system32\drivers\Rtnicxp.sys
2009-03-24 11:03 . 2009-03-24 11:03 7808 ----a-w- c:\windows\system32\drivers\psi_mf.sys
2009-03-19 20:32 . 2009-03-19 20:32 23400 ----a-w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}\x86\x86\GEARAspiWDM.sys
2009-03-19 20:32 . 2006-09-19 18:44 23400 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2008-07-05 00:11 . 2008-07-05 00:11 6104632 -c--a-w- c:\program files\picasaweb-current-setup.exe
2005-04-07 03:37 . 2008-03-20 19:10 0 -csha-w- c:\windows\SMINST\HPCD.SYS
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2004-04-15 233472]
"PS2"="c:\windows\system32\ps2.exe" [2002-10-16 81920]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-15 253952]
"KBD"="c:\hp\KBD\KBD.EXE" [2003-02-12 61440]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"Share-to-Web Namespace Daemon"="c:\program files\HP\HP Share-to-Web\hpgs2wnd.exe" [2002-04-17 69632]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb10.exe" [2004-03-04 172032]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2004-10-22 180269]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-04-13 69632]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-05-30 1947928]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\AGRSMMSG.exe [2004-06-30 88363]
"AlcWzrd"="ALCWZRD.EXE" - c:\windows\ALCWZRD.EXE [2005-09-21 2807808]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-05-30 12:08 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^HP_Owner^Start Menu^Programs^Startup^Secunia PSI.lnk]
path=c:\documents and settings\HP_Owner\Start Menu\Programs\Startup\Secunia PSI.lnk
backup=c:\windows\pss\Secunia PSI.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Updates from HP\\309731\\Program\\Updates from HP.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [5/30/2009 8:08 AM 325896]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [5/30/2009 8:08 AM 108552]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [5/30/2009 8:08 AM 298776]
S3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [3/24/2009 7:03 AM 7808]
S3 w300mgmt;Sony Ericsson W300 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\w300mgmt.sys [3/24/2008 9:12 PM 87824]
S3 w300obex;Sony Ericsson W300 USB WMC OBEX Interface;c:\windows\system32\drivers\w300obex.sys [3/24/2008 9:12 PM 85696]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder
2009-05-15 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
2009-05-24 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SpybotSD.exe [2008-10-27 13:42]
2009-05-24 c:\windows\Tasks\Spybot - Search & Destroy Updater - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SDUpdate.exe [2008-10-27 13:42]
.
- - - - ORPHANS REMOVED - - - -
SafeBoot-procexp90.Sys
.
------- Supplementary Scan -------
.
uStart Page = hxxp://excite.com/
uInternet Settings,ProxyOverride = *.local
IE: &Winamp Search - c:\documents and settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\4i210dax.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampie7&query=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://excite.com
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampab&query=
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\ToolbarFF\components\vmAVGConnector.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-06-07 20:35
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-06-08 20:37
ComboFix-quarantined-files.txt 2009-06-08 00:37
Pre-Run: 123,648,933,888 bytes free
Post-Run: 123,732,676,608 bytes free
192 --- E O F --- 2009-05-28 02:23