Thank you so much Gringo I think that fixed it. No more redirect and the MSE started simply brilliant, My hat is off to you sir!!!
Here is the log from combofix with the script.
ComboFix 11-08-08.03 - User 08/09/2011 12:56:41.2.2 - x86
Microsoft® Windows Vista™ Business 6.0.6002.2.1252.1.1033.18.2045.1091 [GMT -4:00]
Running from: c:\users\User\Desktop\ComboFix.exe
Command switches used :: c:\users\User\Desktop\cfscript.txt
AV: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
AV: Microsoft Security Essentials *Enabled/Outdated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Microsoft Security Essentials *Enabled/Outdated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
FILE ::
"c:\windows\system32\schtasksp.dll"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\schtasksp.dll
.
.
((((((((((((((((((((((((( Files Created from 2011-07-09 to 2011-08-09 )))))))))))))))))))))))))))))))
.
.
2011-08-09 17:00 . 2011-08-09 17:00 -------- d-----w- c:\users\User\AppData\Local\temp
2011-08-09 17:00 . 2011-08-09 17:00 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-08-09 14:02 . 2011-08-09 14:02 -------- d-----w- C:\99fffd6596f3d5360fff
2011-07-30 14:09 . 2011-06-07 15:55 7074640 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F96AA22C-B98A-45F2-9D30-1EF473F3780A}\mpengine.dll
2011-07-30 14:08 . 2011-06-07 15:55 7074640 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Updates\mpengine.dll
2011-07-30 04:43 . 2011-07-30 04:43 -------- d-----w- c:\users\User\AppData\Roaming\Malwarebytes
2011-07-30 04:43 . 2011-07-30 04:43 -------- d-----w- c:\programdata\Malwarebytes
2011-07-30 04:43 . 2011-08-09 13:01 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-07-24 16:49 . 2011-07-24 16:55 -------- d-----w- c:\users\User\audio books
2011-07-22 01:22 . 2011-07-22 01:22 -------- d-----w- c:\users\User\AppData\Roaming\AVG10
2011-07-22 01:20 . 2011-08-09 13:01 -------- d-----w- c:\programdata\AVG10
2011-07-22 01:20 . 2011-08-09 12:59 -------- d-----w- c:\windows\system32\drivers\AVG
2011-07-22 01:19 . 2011-07-22 01:19 -------- d-----w- c:\program files\AVG
2011-07-20 00:23 . 2011-07-20 00:23 -------- d-----w- c:\windows\Sun
2011-07-13 11:26 . 2011-06-02 13:34 2043392 ----a-w- c:\windows\system32\win32k.sys
2011-07-13 11:26 . 2011-04-20 15:55 375808 ----a-w- c:\windows\system32\winsrv.dll
2011-07-13 11:26 . 2011-04-20 15:50 49152 ----a-w- c:\windows\system32\csrsrv.dll
2011-07-13 02:08 . 2011-07-13 02:11 -------- d-----w- c:\users\User\AppData\Local\Google
2011-07-11 05:29 . 2011-07-11 05:34 -------- d-----w- c:\users\User\AppData\Roaming\DivX
2011-07-11 05:28 . 2011-07-11 05:28 -------- d-----w- c:\program files\Common Files\DivX Shared
2011-07-11 05:23 . 2011-07-11 05:29 -------- d-----w- c:\program files\DivX
2011-07-11 05:22 . 2011-07-11 05:29 -------- d-----w- c:\programdata\DivX
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-06-23 03:50 . 2010-06-24 15:33 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-06-13 12:45 . 2011-05-26 14:20 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-06-07 15:55 . 2011-05-29 03:41 7074640 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-06-02 17:53 . 2011-06-02 17:53 94208 ----a-w- c:\windows\system32\dpl100.dll
2011-05-28 01:44 . 2011-05-28 01:44 439632 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BCE45DA4-8231-4C7E-BF60-1CD8D4550441}\gapaengine.dll
2011-05-26 20:16 . 2010-06-08 00:30 252512 ----a-w- c:\windows\system32\drivers\sxuptp.sys
2011-05-26 17:18 . 2011-05-26 17:18 86528 ----a-w- c:\windows\system32\iesysprep.dll
2011-05-26 17:18 . 2011-05-26 17:18 76800 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2011-05-26 17:18 . 2011-05-26 17:18 74752 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2011-05-26 17:18 . 2011-05-26 17:18 63488 ----a-w- c:\windows\system32\tdc.ocx
2011-05-26 17:18 . 2011-05-26 17:18 48640 ----a-w- c:\windows\system32\mshtmler.dll
2011-05-26 17:18 . 2011-05-26 17:18 367104 ----a-w- c:\windows\system32\html.iec
2011-05-26 17:18 . 2011-05-26 17:18 161792 ----a-w- c:\windows\system32\msls31.dll
2011-05-26 17:18 . 2011-05-26 17:18 1126912 ----a-w- c:\windows\system32\wininet.dll
2011-05-26 17:18 . 2011-05-26 17:18 74752 ----a-w- c:\windows\system32\iesetup.dll
2011-05-26 17:18 . 2011-05-26 17:18 420864 ----a-w- c:\windows\system32\vbscript.dll
2011-05-26 17:18 . 2011-05-26 17:18 35840 ----a-w- c:\windows\system32\imgutil.dll
2011-05-26 17:18 . 2011-05-26 17:18 23552 ----a-w- c:\windows\system32\licmgr10.dll
2011-05-26 17:18 . 2011-05-26 17:18 152064 ----a-w- c:\windows\system32\wextract.exe
2011-05-26 17:18 . 2011-05-26 17:18 150528 ----a-w- c:\windows\system32\iexpress.exe
2011-05-26 17:18 . 2011-05-26 17:18 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2011-05-26 17:18 . 2011-05-26 17:18 1427456 ----a-w- c:\windows\system32\inetcpl.cpl
2011-05-26 17:18 . 2011-05-26 17:18 11776 ----a-w- c:\windows\system32\mshta.exe
2011-05-26 17:18 . 2011-05-26 17:18 101888 ----a-w- c:\windows\system32\admparse.dll
2011-05-26 17:18 . 2011-05-26 17:18 110592 ----a-w- c:\windows\system32\IEAdvpack.dll
2011-05-26 17:18 . 2011-05-26 17:18 98816 ----a-w- c:\windows\system32\mfps.dll
2011-05-26 17:18 . 2011-05-26 17:18 979456 ----a-w- c:\windows\system32\MFH264Dec.dll
2011-05-26 17:18 . 2011-05-26 17:18 586240 ----a-w- c:\windows\system32\stobject.dll
2011-05-26 17:18 . 2011-05-26 17:18 357376 ----a-w- c:\windows\system32\MFHEAACdec.dll
2011-05-26 17:18 . 2011-05-26 17:18 302592 ----a-w- c:\windows\system32\mfmp4src.dll
2011-05-26 17:18 . 2011-05-26 17:18 2873344 ----a-w- c:\windows\system32\mf.dll
2011-05-26 17:18 . 2011-05-26 17:18 261632 ----a-w- c:\windows\system32\mfreadwrite.dll
2011-05-26 17:18 . 2011-05-26 17:18 209920 ----a-w- c:\windows\system32\mfplat.dll
2011-05-26 17:18 . 2011-05-26 17:18 683008 ----a-w- c:\windows\system32\d2d1.dll
2011-05-26 17:18 . 2011-05-26 17:18 638336 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2011-05-26 17:18 . 2011-05-26 17:18 486400 ----a-w- c:\windows\system32\d3d10level9.dll
2011-05-26 17:18 . 2011-05-26 17:18 478720 ----a-w- c:\windows\system32\dxgi.dll
2011-05-26 17:18 . 2011-05-26 17:18 37376 ----a-w- c:\windows\system32\cdd.dll
2011-05-26 17:18 . 2011-05-26 17:18 258048 ----a-w- c:\windows\system32\winspool.drv
2011-05-26 17:18 . 2011-05-26 17:18 219648 ----a-w- c:\windows\system32\d3d10_1core.dll
2011-05-26 17:18 . 2011-05-26 17:18 189952 ----a-w- c:\windows\system32\d3d10core.dll
2011-05-26 17:18 . 2011-05-26 17:18 160768 ----a-w- c:\windows\system32\d3d10_1.dll
2011-05-26 17:18 . 2011-05-26 17:18 135680 ----a-w- c:\windows\system32\XpsRasterService.dll
2011-05-26 17:18 . 2011-05-26 17:18 1172480 ----a-w- c:\windows\system32\d3d10warp.dll
2011-05-26 17:18 . 2011-05-26 17:18 1029120 ----a-w- c:\windows\system32\d3d10.dll
2011-05-26 17:18 . 2011-05-26 17:18 847360 ----a-w- c:\windows\system32\OpcServices.dll
2011-05-26 17:18 . 2011-05-26 17:18 667648 ----a-w- c:\windows\system32\printfilterpipelinesvc.exe
2011-05-26 17:18 . 2011-05-26 17:18 26112 ----a-w- c:\windows\system32\printfilterpipelineprxy.dll
2011-05-26 17:18 . 2011-05-26 17:18 1554432 ----a-w- c:\windows\system32\xpsservices.dll
2011-05-26 17:18 . 2011-05-26 17:18 4096 ----a-w- c:\windows\system32\drivers\en-US\dxgkrnl.sys.mui
2011-05-26 17:18 . 2011-05-26 17:18 974848 ----a-w- c:\windows\system32\WindowsCodecs.dll
2011-05-26 17:18 . 2011-05-26 17:18 519680 ----a-w- c:\windows\system32\d3d11.dll
2011-05-26 17:18 . 2011-05-26 17:18 369664 ----a-w- c:\windows\system32\WMPhoto.dll
2011-05-26 17:18 . 2011-05-26 17:18 321024 ----a-w- c:\windows\system32\PhotoMetadataHandler.dll
2011-05-26 17:18 . 2011-05-26 17:18 252928 ----a-w- c:\windows\system32\dxdiag.exe
2011-05-26 17:18 . 2011-05-26 17:18 195584 ----a-w- c:\windows\system32\dxdiagn.dll
2011-05-26 17:18 . 2011-05-26 17:18 189440 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
2011-05-26 16:15 . 2006-11-02 10:32 101888 ----a-w- c:\windows\system32\ifxcardm.dll
2011-05-26 16:15 . 2006-11-02 10:32 82432 ----a-w- c:\windows\system32\axaltocm.dll
2011-06-26 01:36 . 2011-05-26 16:04 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^Users^User^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.3.lnk]
path=c:\users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk
backup=c:\windows\pss\OpenOffice.org 3.3.lnk.Startup
backupExtension=.Startup
.
[HKLM\~\startupfolder\C:^Users^User^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^SimpleCenter.lnk]
path=c:\users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SimpleCenter.lnk
backup=c:\windows\pss\SimpleCenter.lnk.Startup
backupExtension=.Startup
.
[HKLM\~\startupfolder\C:^Users^User^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^SX Virtual Link.lnk]
path=c:\users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SX Virtual Link.lnk
backup=c:\windows\pss\SX Virtual Link.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-06-06 16:55 937920 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
2011-03-15 21:42 499608 ------w- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2011-03-21 18:56 1230704 ----a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2011-07-13 02:08 136176 ----atw- c:\users\User\AppData\Local\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2007-10-05 01:24 8497696 ----a-w- c:\windows\System32\nvcpl.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NVHotkey]
2007-10-05 01:24 86016 ----a-w- c:\windows\System32\nvhotkey.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2007-10-05 01:24 81920 ----a-w- c:\windows\System32\nvmctray.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvSvc]
2007-10-05 01:24 86016 ----a-w- c:\windows\System32\nvsvc.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2011-04-08 16:59 254696 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
2011-03-22 18:37 74752 ----a-w- c:\program files\Winamp\winampa.exe
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2010-07-15 14216]
R3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2010-07-15 8456]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2011-04-27 65024]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 208944]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R4 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
R4 BRA_Scheduler;Brother BRAdminPro Scheduler;c:\program files\Brother\BRAdmin Professional 3\bratimer.exe [2010-09-15 65536]
S2 sxuptp;SXUPTP Driver;c:\windows\system32\DRIVERS\sxuptp.sys [2011-05-26 252512]
S3 b57nd60x;%SvcDispName%;c:\windows\system32\DRIVERS\b57nd60x.sys [2008-01-19 179712]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2011-04-18 43392]
S3 WSDPrintDevice;WSD Print Support via UMB;c:\windows\system32\DRIVERS\WSDPrint.sys [2008-01-19 16896]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - 47685160
*Deregistered* - 47685160
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
2011-08-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4246529846-2366681449-1627127897-1000Core.job
- c:\users\User\AppData\Local\Google\Update\GoogleUpdate.exe [2011-07-13 02:08]
.
2011-08-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4246529846-2366681449-1627127897-1000UA.job
- c:\users\User\AppData\Local\Google\Update\GoogleUpdate.exe [2011-07-13 02:08]
.
.
------- Supplementary Scan -------
.
uStart Page = file:///C:/Users/User/Scott's%20Page%202/index.html
TCP: Interfaces\{537AACB9-E1A6-4E7C-B059-CD22088603E1}: NameServer = 209.55.5.10,209.55.5.11
FF - ProfilePath - c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\yv46utje.default\
FF - prefs.js: browser.startup.homepage - file:///C:/Users/User/Scott%27s%20Page%202/index.html
FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?pc=ZUGO&form=ZGAADF&q=
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-08-09 13:00
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2011-08-09 13:01:25
ComboFix-quarantined-files.txt 2011-08-09 17:01
ComboFix2.txt 2011-08-09 13:22
.
Pre-Run: 41,503,473,664 bytes free
Post-Run: 41,486,905,344 bytes free
.
- - End Of File - - 66D99CAFF0A7EA234710FA1287925468