ComboFix scan is complete. I attached the logs. I'm still getting pop-ups and a re-direct page at bootup that says the web page cannot be displayed.
ComboFix 11-06-17.04 - User 05/18/2011 17:36:27.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1015.752 [GMT -4:00]
Running from: c:\documents and settings\User\Desktop\ComboFix.exe
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}
c:\documents and settings\All Users\Application Data\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\{1D975A5E-1126-4F46-A423-41781934A63E}
c:\documents and settings\All Users\Application Data\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\instance.dat
c:\documents and settings\All Users\Application Data\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\mia.lib
c:\documents and settings\All Users\Application Data\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}
c:\documents and settings\All Users\Application Data\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\24618E3F\611F5CA\Microsoft.VC80.MFC.manifest
c:\documents and settings\All Users\Application Data\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\29A73ACD\3E688669\stb0.dll
c:\documents and settings\All Users\Application Data\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\2A3DCDAF\611F5CA\SkinCrafterDll.dll
c:\documents and settings\All Users\Application Data\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\4DAC9037\611F5CA\gdiplus.dll
c:\documents and settings\All Users\Application Data\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\51B9750F\611F5CA\msvcr80.dll
c:\documents and settings\All Users\Application Data\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\62404B3E\3E688669\FFToolbar.xml
c:\documents and settings\All Users\Application Data\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\879169BE\611F5CA\mfc80.dll
c:\documents and settings\All Users\Application Data\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\9B242A8C\611F5CA\Microsoft.VC80.CRT.manifest
c:\documents and settings\All Users\Application Data\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\C90EEF64\3E688669\AxGifAnimator.dll
c:\documents and settings\All Users\Application Data\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\CC8FDF08\3E688669\OEActiveXDLL.dll
c:\documents and settings\All Users\Application Data\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\F0A80E14\5702F56C\home.juicyaccess.com.url
c:\documents and settings\All Users\Application Data\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\mFileBagIDE.dll\bag\AdwareSetup.exe
c:\documents and settings\All Users\Application Data\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\mFileBagIDE.dll\bag\cfcpxlog.mx
c:\documents and settings\All Users\Application Data\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\mFileBagIDE.dll\bag\FFToolbar.xpi
c:\documents and settings\All Users\Application Data\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\mFileBagIDE.dll\bag\HJSetup.exe
c:\documents and settings\All Users\Application Data\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\mFileBagIDE.dll\bag\libiconv2.dll
c:\documents and settings\All Users\Application Data\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\mFileBagIDE.dll\bag\libintl3.dll
c:\documents and settings\All Users\Application Data\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\mFileBagIDE.dll\bag\MsiZap.Exe
c:\documents and settings\All Users\Application Data\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\mFileBagIDE.dll\bag\msvcp60.dll
c:\documents and settings\All Users\Application Data\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\mFileBagIDE.dll\bag\ProductInfo.mx
c:\documents and settings\All Users\Application Data\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\mFileBagIDE.dll\bag\setup.exe
c:\documents and settings\All Users\Application Data\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\mFileBagIDE.dll\bag\sqlite3.dll
c:\documents and settings\All Users\Application Data\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\mFileBagIDE.dll\bag\SSD.exe
c:\documents and settings\All Users\Application Data\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\mFileBagIDE.dll\bag\tbcore.mx
c:\documents and settings\All Users\Application Data\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\mFileBagIDE.dll\bag\tre4.dll
c:\documents and settings\All Users\Application Data\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\mFileBagIDE.dll\mFileBagEXE.dll
c:\documents and settings\All Users\Application Data\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\mIDEFunc.dll\mEXEFunc.dll
c:\documents and settings\All Users\Application Data\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\mIDEWriteReg.dll\mEXEWriteReg.dll
c:\documents and settings\All Users\Application Data\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\mMSI.dll\mMSIExec.dll
c:\documents and settings\All Users\Application Data\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\Setup.dat
c:\documents and settings\All Users\Application Data\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\Setup.msi
c:\documents and settings\All Users\Application Data\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\Setup.par
c:\documents and settings\All Users\Application Data\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\Setup.res
c:\documents and settings\NetworkService\Local Settings\Application Data\vxfkevnpha.exe
c:\documents and settings\NetworkService\Start Menu\Programs\Security Shield.lnk
c:\documents and settings\User\Application Data\MSA
c:\documents and settings\User\Application Data\MSA\download.list
c:\documents and settings\User\Application Data\MSA\w2_0.exe
c:\documents and settings\User\Application Data\Sun\ddee.dat
c:\documents and settings\User\Application Data\Sun\mnj.dat
c:\documents and settings\User\Application Data\Sun\mxd1.txt
c:\documents and settings\User\Application Data\Sun\ppkk.dat
c:\documents and settings\User\Application Data\Sun\uuoo.dat
c:\documents and settings\User\Media
c:\documents and settings\User\Media\CANYON.MID
c:\documents and settings\User\Media\CHIMES.WAV
c:\documents and settings\User\Media\CHORD.WAV
c:\documents and settings\User\Media\DING.WAV
c:\documents and settings\User\Media\Jungle Asterisk.wav
c:\documents and settings\User\Media\Jungle Close.wav
c:\documents and settings\User\Media\Jungle Critical Stop.wav
c:\documents and settings\User\Media\Jungle Default.wav
c:\documents and settings\User\Media\Jungle Error.wav
c:\documents and settings\User\Media\Jungle Exclamation.wav
c:\documents and settings\User\Media\Jungle Maximize.wav
c:\documents and settings\User\Media\Jungle Menu Command.wav
c:\documents and settings\User\Media\Jungle Menu Popup.wav
c:\documents and settings\User\Media\Jungle Minimize.wav
c:\documents and settings\User\Media\Jungle Open.wav
c:\documents and settings\User\Media\Jungle Question.wav
c:\documents and settings\User\Media\Jungle Recycle.wav
c:\documents and settings\User\Media\Jungle Restore Down.wav
c:\documents and settings\User\Media\Jungle Restore Up.wav
c:\documents and settings\User\Media\Jungle Windows Exit.wav
c:\documents and settings\User\Media\Jungle Windows Start.wav
c:\documents and settings\User\Media\LOGOFF.WAV
c:\documents and settings\User\Media\Musica Asterisk.wav
c:\documents and settings\User\Media\Musica Close.wav
c:\documents and settings\User\Media\Musica Critical Stop.wav
c:\documents and settings\User\Media\Musica Default.wav
c:\documents and settings\User\Media\Musica Error.wav
c:\documents and settings\User\Media\Musica Exclamation.wav
c:\documents and settings\User\Media\Musica Maximize.wav
c:\documents and settings\User\Media\Musica Menu Command.wav
c:\documents and settings\User\Media\Musica Menu Popup.wav
c:\documents and settings\User\Media\Musica Minimize.wav
c:\documents and settings\User\Media\Musica Open.wav
c:\documents and settings\User\Media\Musica Question.wav
c:\documents and settings\User\Media\Musica Recycle.wav
c:\documents and settings\User\Media\Musica Restore Down.wav
c:\documents and settings\User\Media\Musica Restore Up.wav
c:\documents and settings\User\Media\Musica Windows Exit.wav
c:\documents and settings\User\Media\Musica Windows Start.wav
c:\documents and settings\User\Media\NOTIFY.WAV
c:\documents and settings\User\Media\PASSPORT.MID
c:\documents and settings\User\Media\RECYCLE.WAV
c:\documents and settings\User\Media\Robotz Asterisk.wav
c:\documents and settings\User\Media\Robotz Close.wav
c:\documents and settings\User\Media\Robotz Critical Stop.wav
c:\documents and settings\User\Media\Robotz Default.wav
c:\documents and settings\User\Media\Robotz Error.wav
c:\documents and settings\User\Media\Robotz Exclamation.wav
c:\documents and settings\User\Media\Robotz Maximize.wav
c:\documents and settings\User\Media\Robotz Menu Command.wav
c:\documents and settings\User\Media\Robotz Menu Popup.wav
c:\documents and settings\User\Media\Robotz Minimize.wav
c:\documents and settings\User\Media\Robotz Open.wav
c:\documents and settings\User\Media\Robotz Question.wav
c:\documents and settings\User\Media\Robotz Recycle.wav
c:\documents and settings\User\Media\Robotz Restore Down.wav
c:\documents and settings\User\Media\Robotz Restore Up.wav
c:\documents and settings\User\Media\Robotz Windows Exit.wav
c:\documents and settings\User\Media\Robotz Windows Start.wav
c:\documents and settings\User\Media\START.WAV
c:\documents and settings\User\Media\TADA.WAV
c:\documents and settings\User\Media\The Microsoft Sound.wav
c:\documents and settings\User\Media\Utopia Asterisk.wav
c:\documents and settings\User\Media\Utopia Close.wav
c:\documents and settings\User\Media\Utopia Critical Stop.wav
c:\documents and settings\User\Media\Utopia Default.wav
c:\documents and settings\User\Media\Utopia Error.wav
c:\documents and settings\User\Media\Utopia Exclamation.wav
c:\documents and settings\User\Media\Utopia Maximize.wav
c:\documents and settings\User\Media\Utopia Menu Command.wav
c:\documents and settings\User\Media\Utopia Menu Popup.wav
c:\documents and settings\User\Media\Utopia Minimize.wav
c:\documents and settings\User\Media\Utopia Open.wav
c:\documents and settings\User\Media\Utopia Question.wav
c:\documents and settings\User\Media\Utopia Recycle.wav
c:\documents and settings\User\Media\Utopia Restore Down.wav
c:\documents and settings\User\Media\Utopia Restore Up.wav
c:\documents and settings\User\Media\Utopia Windows Exit.wav
c:\documents and settings\User\Media\Utopia Windows Start.wav
c:\documents and settings\User\Recent\bsredirect5[1].js.zip
c:\documents and settings\User\Templates\4256o56y1a8o6x33021iv38cljbeoo2456lvgt
c:\program files\INSTALL.LOG
c:\windows\desktop
c:\windows\desktop\buzz_300.asx
.
.
((((((((((((((((((((((((( Files Created from 2011-04-18 to 2011-05-18 )))))))))))))))))))))))))))))))
.
.
2011-06-06 01:08 . 2011-06-06 01:08 -------- d-----w- c:\documents and settings\User\Application Data\IObit
2011-06-06 01:08 . 2011-06-06 01:08 -------- d-----w- c:\program files\IObit
2011-06-02 16:37 . 2011-06-02 16:37 -------- d-----w- c:\windows\system32\wbem\Repository
2011-06-02 15:44 . 2011-06-02 15:44 -------- d-----w- c:\windows\system32\config\systemprofile\IETldCache
2011-05-15 23:32 . 2011-05-15 23:32 -------- d-----w- c:\windows\system32\%APPDATA%
2011-05-15 22:47 . 2011-05-15 22:47 389120 ----a-w- c:\windows\system32\igxpun.exe
2011-05-09 02:48 . 2011-05-09 02:49 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2011-05-08 22:03 . 2011-05-08 22:05 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2011-05-08 13:29 . 2011-05-08 13:30 -------- d-----w- c:\documents and settings\User\Application Data\Axutmu
2011-05-08 13:29 . 2011-05-08 13:29 -------- d-----w- c:\documents and settings\User\Application Data\Suomet
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-07 05:33 . 2009-01-22 16:05 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-03-04 06:37 . 2008-04-14 12:00 420864 ----a-w- c:\windows\system32\vbscript.dll
2011-03-03 13:21 . 2008-04-14 12:00 1857920 ----a-w- c:\windows\system32\win32k.sys
2011-02-22 23:06 . 2008-04-14 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2011-02-22 23:06 . 2008-04-14 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-02-22 23:06 . 2008-04-14 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-02-22 11:41 . 2008-04-14 12:00 385024 ----a-w- c:\windows\system32\html.iec
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-04-12 39408]
"TomTomHOME.exe"="c:\program files\TomTom HOME 2\TomTomHOMERunner.exe" [2010-08-24 247144]
"UpdateFlow.ATT-SST"="c:\program files\ATT-SST\McciBrowser.exe" [2010-07-27 1057792]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-01-13 131072]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-01-13 163840]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-01-13 135168]
"Smapp"="c:\program files\Analog Devices\SoundMAX\SMTray.exe" [2003-07-30 143360]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-11-01 32768]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"ATT-SST_McciTrayApp"="c:\program files\ATT-SST\McciTrayApp.exe" [2010-07-27 1573888]
"ISW.exe"="c:\program files\AT&T\Internet Security Wizard\ISW.exe" [2007-05-03 2061816]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Wireless Configuration Utility.lnk - c:\program files\TRENDnet\TEW-424UB\WlanCU.exe [2007-7-10 634880]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG10\avgchsvx.exe /sync\0c:\progra~1\AVG\AVG10\avgrsx.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\WS_FTP\\WS_FTP95.exe"=
.
R2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [8/24/2010 5:38 AM 92008]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [4/12/2010 8:45 PM 135664]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [4/12/2010 8:45 PM 135664]
S3 RTL8187B;TRENDnet TEW-424UB 54M USB Dongle;c:\windows\system32\drivers\RTL8187B.sys [6/15/2009 9:12 PM 264576]
S3 SjyPkt;SjyPkt;c:\windows\system32\drivers\SjyPkt.sys [10/3/2002 12:57 AM 13532]
.
Contents of the 'Scheduled Tasks' folder
.
2011-05-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-13 00:45]
.
2011-06-07 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-13 00:45]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://msn.com/
uInternet Settings,ProxyOverride = <local>
IE: Add to AMV/AVI Video Converter... - c:\program files\Media Player Utilities 4.25\AMVConverter\grab.html
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html
Trusted Zone: motive.com\patttbc.att
TCP: DhcpNameServer = 192.168.1.254
.
- - - - ORPHANS REMOVED - - - -
.
BHO-{A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)
HKU-Default-RunOnce-vxfkevnpha - c:\docume~1\NETWOR~1\LOCALS~1\APPLIC~1\vxfkevnpha.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
GMER - Rootkit Detector and Remover
Rootkit scan 2011-05-18 17:55
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer,
GMER - Rootkit Detector and Remover
Windows 5.1.2600 Disk: ST340014AS rev.3.20 -> Harddisk1\DR1 -> \Device\Ide\IdeDeviceP2T0L0-17
.
device: opened successfully
user: MBR read successfully
error: Read A device attached to the system is not functioning.
kernel: MBR read successfully
detected disk devices:
detected hooks:
\Driver\atapi DriverStartIo -> 0x8635F31B
user & kernel MBR OK
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(732)
c:\windows\system32\WININET.dll
.
- - - - - - - > 'lsass.exe'(792)
c:\windows\system32\WININET.dll
.
- - - - - - - > 'explorer.exe'(2296)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Motive\McciCMService.exe
c:\program files\Analog Devices\SoundMAX\SMAgent.exe
c:\program files\Common Files\Java\Java Update\jucheck.exe
.
**************************************************************************
.
Completion time: 2011-05-18 18

50 - machine was rebooted
ComboFix-quarantined-files.txt 2011-05-18 22:06
.
Pre-Run: 20,260,995,072 bytes free
Post-Run: 21,882,982,400 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - 4F2DF0873A134BD7DB32ACC559F18C6F