Here is the log, thank you:
ComboFix 08-11-09.04 - Owner 2008-11-10 17:58:19.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.96 [GMT -5:00]
Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\program files\Common\helper.sig
c:\program files\INSTALL.LOG
c:\windows\IE4 Error Log.txt
c:\windows\system32\bwvntkoq.ini
c:\windows\system32\dsrufmwu.dll
c:\windows\system32\hddoakan.ini
c:\windows\system32\jgjwptec.dll
c:\windows\system32\oohlot.dll
c:\windows\system32\pwwqem.dll
c:\windows\system32\tpgercos.ini
c:\windows\wiaserviv.log
D:\Autorun.inf
----- BITS: Possible infected sites -----
hxxp://dna65.fastaccess.com
.
((((((((((((((((((((((((( Files Created from 2008-10-10 to 2008-11-10 )))))))))))))))))))))))))))))))
.
2008-11-07 00:51 . 2008-11-07 00:51 <DIR> d-------- C:\_OTMoveIt
2008-11-07 00:31 . 2008-11-10 00:12 <DIR> d-------- C:\Lop SD
2008-11-07 00:09 . 2008-11-07 00:09 <DIR> d-------- c:\program files\Raxco
2008-11-07 00:09 . 2008-11-07 00:09 <DIR> d-------- c:\documents and settings\All Users\Application Data\Raxco
2008-11-06 23:53 . 2008-11-06 23:53 <DIR> d-------- c:\program files\Common Files\Authentium
2008-11-06 23:53 . 2008-11-07 00:08 53,192 --a------ c:\windows\system32\drivers\rp_skt32.sys
2008-11-06 23:53 . 2007-04-19 11:24 48,384 --a------ c:\windows\system32\drivers\rp_pkt32.sys
2008-11-06 23:52 . 2008-11-06 23:59 <DIR> d-------- c:\program files\Common Files\Scanner
2008-11-06 23:50 . 2008-11-06 23:50 <DIR> d-------- c:\documents and settings\Owner\Application Data\InstallShield
2008-11-06 23:47 . 2008-11-06 23:47 <DIR> d-------- c:\documents and settings\Scott Burdette\Application Data\Malwarebytes
2008-11-06 22:35 . 2008-11-06 22:35 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-11-06 22:35 . 2008-11-06 22:35 <DIR> d-------- c:\documents and settings\Owner\Application Data\Malwarebytes
2008-11-06 22:35 . 2008-11-06 22:35 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-06 22:35 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-06 22:35 . 2008-10-22 16:10 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-11-06 21:18 . 2008-11-06 21:18 <DIR> d-------- c:\program files\Trend Micro
2008-11-06 00:17 . 2008-11-06 00:17 <DIR> d-------- C:\VundoFix Backups
2008-11-04 20:43 . 2008-11-04 20:43 <DIR> d-------- c:\documents and settings\Scott Burdette\Application Data\SUPERAntiSpyware.com
2008-11-04 19:59 . 2008-11-06 23:49 <DIR> d-------- c:\program files\SUPERAntiSpyware
2008-11-04 17:58 . 2008-11-06 23:49 <DIR> d-------- c:\program files\Enigma Software Group
2008-11-04 17:49 . 2008-11-04 17:49 <DIR> d-------- c:\documents and settings\Scott Burdette\Application Data\Simply Super Software
2008-11-04 17:49 . 2008-11-04 17:49 <DIR> d-------- c:\documents and settings\All Users\Application Data\Simply Super Software
2008-11-04 17:49 . 2006-05-25 15:52 162,304 --a------ c:\windows\system32\ztvunrar36.dll
2008-11-04 17:49 . 2003-02-02 20:06 153,088 --a------ c:\windows\system32\unrar3.dll
2008-11-04 17:49 . 2005-08-26 01:50 77,312 --a------ c:\windows\system32\ztvunace26.dll
2008-11-04 17:49 . 2002-03-06 01:00 75,264 --a------ c:\windows\system32\unacev2.dll
2008-11-04 17:49 . 2006-06-19 13:01 69,632 --a------ c:\windows\system32\ztvcabinet.dll
2008-11-03 20:56 . 2008-11-03 20:56 <DIR> d-------- c:\documents and settings\Administrator\Application Data\AT&T
2008-11-03 20:45 . 2004-08-27 04:54 <DIR> d-------- c:\documents and settings\Administrator\WINDOWS
2008-11-03 20:45 . 2005-10-29 20:57 <DIR> d-------- c:\documents and settings\Administrator\Application Data\You've Got Pictures Screensaver
2008-11-03 20:45 . 2005-10-29 21:58 <DIR> d-------- c:\documents and settings\Administrator\Application Data\SampleView
2008-11-03 20:45 . 2006-02-04 15:01 <DIR> d-------- c:\documents and settings\Administrator\Application Data\AOL
2008-11-03 20:45 . 2008-11-03 20:45 <DIR> d-------- c:\documents and settings\Administrator
2008-11-03 18:37 . 2008-11-03 18:37 116 --a------ c:\windows\wininit.ini
2008-11-03 18:14 . 2008-11-06 23:49 <DIR> d-------- c:\program files\Spybot - Search & Destroy
2008-11-03 18:14 . 2008-11-06 23:49 <DIR> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-11-02 17:49 . 2008-11-02 17:49 <DIR> d-------- c:\program files\XoftSpySE
2008-11-02 17:06 . 2008-11-02 17:06 4,334 --a------ c:\windows\system32\tmp.reg
2008-11-02 17:05 . 2007-09-05 23:22 289,144 --a------ c:\windows\system32\VCCLSID.exe
2008-11-02 17:05 . 2006-04-27 16:49 288,417 --a------ c:\windows\system32\SrchSTS.exe
2008-11-02 17:05 . 2008-09-08 22:38 88,576 --a------ c:\windows\system32\AntiXPVSTFix.exe
2008-11-02 17:05 . 2008-10-01 14:51 87,552 --a------ c:\windows\system32\VACFix.exe
2008-11-02 17:05 . 2008-10-10 07:58 82,944 --a------ c:\windows\system32\o4Patch.exe
2008-11-02 17:05 . 2008-05-18 20:40 82,944 --a------ c:\windows\system32\IEDFix.exe
2008-11-02 17:05 . 2008-10-10 07:58 82,944 --a------ c:\windows\system32\IEDFix.C.exe
2008-11-02 17:05 . 2008-08-18 11:19 82,432 --a------ c:\windows\system32\404Fix.exe
2008-11-02 17:05 . 2004-07-31 17:50 51,200 --a------ c:\windows\system32\dumphive.exe
2008-11-02 17:05 . 2007-10-03 23:36 25,600 --a------ c:\windows\system32\WS2Fix.exe
2008-11-02 16:59 . 2007-08-21 07:00 1,536 --a------ c:\windows\system32\Delete_Me_Dummy_karna.dat
2008-10-24 08:24 . 2008-10-15 11:34 337,408 --a--c--- c:\windows\system32\dllcache\netapi32.dll
2008-10-15 16:33 . 2008-08-14 05:11 2,189,184 --a--c--- c:\windows\system32\dllcache\ntoskrnl.exe
2008-10-15 16:33 . 2008-08-14 05:09 2,145,280 --a--c--- c:\windows\system32\dllcache\ntkrnlmp.exe
2008-10-15 16:33 . 2008-08-14 04:33 2,066,048 --a--c--- c:\windows\system32\dllcache\ntkrnlpa.exe
2008-10-15 16:33 . 2008-08-14 04:33 2,023,936 --a--c--- c:\windows\system32\dllcache\ntkrpamp.exe
2008-10-15 16:33 . 2008-09-15 07:12 1,846,400 --a--c--- c:\windows\system32\dllcache\win32k.sys
2008-10-15 16:33 . 2008-09-08 05:41 333,824 --a--c--- c:\windows\system32\dllcache\srv.sys
2008-10-14 16:29 . 2008-11-06 23:52 <DIR> d-------- c:\program files\CA
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-10 22:58 --------- d-----w c:\program files\Common
2008-11-07 05:08 --------- d-----w c:\documents and settings\Scott Burdette\Application Data\InstallShield
2008-11-07 05:06 --------- d-----w c:\documents and settings\Scott Burdette\Application Data\AT&T
2008-11-07 04:52 --------- d-----w c:\program files\AT&T
2008-11-07 04:52 --------- d-----w c:\documents and settings\All Users\Application Data\AT&T
2008-11-07 04:49 --------- d-----w c:\documents and settings\Owner\Application Data\SUPERAntiSpyware.com
2008-11-06 03:58 --------- d-----w c:\program files\Lx_cats
2008-11-05 00:21 --------- d-----w c:\documents and settings\Owner\Application Data\AT&T
2008-11-04 01:16 --------- d-----w c:\program files\Yahoo SiteBuilder
2008-11-04 01:14 --------- d-----w c:\program files\EA SPORTS
2008-11-02 22:54 --------- d-----w c:\documents and settings\All Users\Application Data\FLEXnet
2008-11-02 15:32 --------- d-----w c:\program files\Viewpoint
2008-11-02 15:32 --------- d-----w c:\documents and settings\All Users\Application Data\Viewpoint
2008-11-02 15:28 --------- d--h--w c:\program files\InstallShield Installation Information
2008-10-25 19:59 --------- d-----w c:\documents and settings\Owner\Application Data\Move Networks
2008-10-19 22:33 --------- d-----w c:\documents and settings\Owner\Application Data\Motive
2008-10-04 19:10 --------- d-----w c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2008-09-15 12:12 1,846,400 ----a-w c:\windows\system32\win32k.sys
2008-08-20 05:30 666,112 ----a-w c:\windows\system32\wininet.dll
2008-08-14 10:11 2,189,184 ----a-w c:\windows\system32\ntoskrnl.exe
2008-08-14 09:33 2,066,048 ----a-w c:\windows\system32\ntkrnlpa.exe
2006-09-18 06:19 0 ----a-w c:\documents and settings\Owner\Application Data\wklnhst.dat
2006-08-01 00:16 2,096,420 ----a-w c:\program files\unnamed.[1]
2006-07-25 22:38 24,070,456 ----a-w c:\program files\wmp11-windowsxp-x86-enu.exe
2006-07-01 23:08 5,118,288 ----a-w c:\program files\Firefox Setup 1.5.0.4.exe
2006-03-17 00:41 14,088,248 ----a-w c:\program files\snagit.exe
2006-03-03 13:21 62,352,622 ----a-w c:\program files\Audible.zip
2006-02-05 01:32 2,891,768 ----a-w c:\program files\ComcastToolbar.exe
2006-12-09 23:37 13,386 ----a-w c:\program files\mozilla firefox\plugins\atgpcdec.dll
2006-12-09 23:37 92,746 ----a-w c:\program files\mozilla firefox\plugins\atgpcext.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"Creative Detector"="c:\program files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-02 102400]
"AdobeUpdater"="c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2008-08-28 2321600]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunKistEM"="c:\program files\Digital Media Reader\shwiconem.exe" [2004-11-15 135168]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-09-18 7204864]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2005-09-18 86016]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"LXCFCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXCFtime.dll" [2005-04-27 69632]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-05-08 180269]
"Lexmark 2200 Series"="c:\program files\Lexmark 2200 Series\lxbvbmgr.exe" [2004-02-13 57344]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2007-03-14 257088]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-10-19 286720]
"HelpCenter4.1"="c:\program files\Bellsouth\HelpCenter40b\bin\sprtcmd.exe" [2007-06-28 198184]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2006-10-22 620152]
"AT&T Internet Security Suite"="c:\program files\AT&T\AT&T Internet Security Suite\Rps.exe" [2007-06-28 310000]
"ISW.exe"="c:\program files\AT&T\Internet Security Wizard\ISW.exe" [2007-05-03 2061816]
"-FreedomNeedsReboot"="c:\program files\AT&T\AT&T Internet Security Suite\ZkRunOnceR.exe" [2007-06-28 13552]
"SoundMan"="SOUNDMAN.EXE" [2005-09-26 c:\windows\soundman.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-0000-7760-000000000003}\_SC_Acrobat.exe [2008-08-27 295606]
Adobe Acrobat Synchronizer.lnk - c:\program files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe [2006-10-22 734872]
BigFix.lnk - c:\program files\BigFix\bigfix.exe [2005-10-29 2168360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=lwmavc.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\lxcfcoms.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
R2 McciCMService;McciCMService;c:\program files\Common Files\Motive\McciCMService.exe [2008-01-28 303104]
S3 MREMP50;MREMP50 NDIS Protocol Driver;c:\progra~1\COMMON~1\Motive\MREMP50.SYS [2008-01-28 19712]
S3 MREMP50a64;MREMP50a64 NDIS Protocol Driver;c:\progra~1\COMMON~1\Motive\MREMP50a64.SYS [ ]
S3 MRESP50;MRESP50 NDIS Protocol Driver;c:\progra~1\COMMON~1\Motive\MRESP50.SYS [2008-01-28 18304]
S3 MRESP50a64;MRESP50a64 NDIS Protocol Driver;c:\progra~1\COMMON~1\Motive\MRESP50a64.SYS [ ]
S3 Radialpoint Security Services;AT&T Internet Security Suite;c:\windows\system32\dllhost.exe [2008-04-13 5120]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{09826001-48e5-11da-bf8e-806d6172696f}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1019e541-51ec-11da-9c61-806d6172696f}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{815a0671-62bc-11da-b957-806d6172696f}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480
.
Contents of the 'Scheduled Tasks' folder
2008-10-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 14:57]
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
Notify-ljJCsstS - (no file)
.
------- Supplementary Scan -------
.
FireFox -: Profile - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\mtci5306.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://my.att.net/
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-11-10 18:01:48
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\AT&T\AT&T Internet Security Suite\Fws.exe
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\windows\system32\CTSVCCDA.EXE
c:\program files\Common Files\Authentium\AntiVirus\dvpapi.exe
c:\program files\CA\PPRT\bin\ITMRTSVC.exe
c:\windows\system32\rundll32.exe
c:\program files\Lexmark 2200 Series\lxbvbmon.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
c:\program files\AT&T\Internet Security Wizard\ISWComHandler.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\AT&T\AT&T Internet Security Suite\rpsupdaterR.exe
c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
.
**************************************************************************
.
Completion time: 2008-11-10 18:12:42 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-10 23:12:32
Pre-Run: 139,623,866,368 bytes free
Post-Run: 139,545,653,248 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
225 --- E O F --- 2008-10-31 00:46:47