Thank you so much for responding. Here is the Combofix log:
ComboFix 09-07-31.04 - TAX 07/31/2009 21:18.1.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.750 [GMT -5:00]
Running from: c:\documents and settings\TAX\Desktop\Combo-Fix.exe
AV: PC Tools AntiVirus 5.0.0.16 *On-access scanning disabled* (Outdated) {832E7172-E406-4BB2-8B19-6D29F2C93A98}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Administrator.BKB_PDC\Application Data\Microsoft\Internet Explorer\Quick Launch\PC Tools AntiVirus.lnk
c:\documents and settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\PC Tools AntiVirus.lnk
c:\documents and settings\TAX\Application Data\Microsoft\Internet Explorer\Quick Launch\PC Tools AntiVirus.lnk
c:\recycler\S-1-5-21-1406924294-3442860757-1802248941-500
c:\recycler\S-1-5-21-3591582154-2265895377-1804255741-500
c:\windows\Installer\WinRMSrv.msi
c:\windows\system32\drivers\UACkbgkndpsmwvdhaq.sys
c:\windows\system32\gdi32lib.dll
c:\windows\system32\iehostcx32.dll
c:\windows\system32\UACbimxfqpaculvydr.dll
c:\windows\system32\UACcjrqhicfioykffp.dll
c:\windows\system32\UACcvwdijkuixdqicp.log
c:\windows\system32\UAChtybmsfgkqbtdae.log
c:\windows\system32\uacinit.dll
c:\windows\system32\UACjytlrhohagodlie.dll
c:\windows\system32\UACmkkbqxylvmqlnhi.dat
c:\windows\system32\UACoyrbsajnhlvyqmv.dll
c:\windows\system32\UACrjeqjkuyypmwuyp.dll
c:\windows\system32\UACudsentnfppklhfh.log
c:\windows\system32\proquota.exe was missing
Restored copy from - c:\windows\ServicePackFiles\i386\proquota.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_UACd.sys
-------\Legacy_NPF
-------\Service_NPF
((((((((((((((((((((((((( Files Created from 2009-07-01 to 2009-08-01 )))))))))))))))))))))))))))))))
.
2009-07-11 21:23 . 2009-07-11 21:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-07-11 21:23 . 2009-07-11 21:23 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-07-11 16:17 . 2009-07-03 14:49 15688 ----a-w- c:\windows\system32\lsdelete.exe
2009-07-11 15:32 . 2009-07-03 14:49 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-07-11 15:32 . 2009-07-11 15:32 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}
2009-07-11 15:32 . 2009-07-08 17:28 2920112 -c--a-w- c:\documents and settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}\Ad-AwareAE.exe
2009-07-11 15:31 . 2009-07-11 15:31 -------- d-----w- c:\program files\Lavasoft
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-01 02:28 . 2009-06-08 03:52 -------- d-----w- c:\program files\PC Tools AntiVirus
2009-08-01 02:06 . 2009-06-08 03:53 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-07-19 03:56 . 2009-05-29 20:23 67352 ---ha-w- c:\windows\system32\mlfcache.dat
2009-07-18 23:32 . 2007-03-15 13:32 81496 -c--a-w- c:\documents and settings\TAX\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-11 15:31 . 2009-05-26 22:39 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-07-11 03:42 . 2005-01-08 09:28 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-11 03:39 . 2005-09-19 11:15 -------- d-----w- c:\documents and settings\All Users\Application Data\Network Associates
2009-07-07 03:50 . 2009-04-30 04:21 -------- d-----w- c:\program files\Full Tilt Poker
2009-06-29 16:12 . 2005-01-08 06:27 827392 ----a-w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2009-06-13 23:20 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2005-01-08 06:27 17408 ----a-w- c:\windows\system32\corpol.dll
2009-06-16 14:36 . 2005-01-08 06:27 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2005-01-08 06:27 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-08 03:53 . 2009-06-08 03:53 -------- d-----w- c:\documents and settings\TAX\Application Data\PC Tools
2009-06-08 03:53 . 2009-06-08 03:52 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
2009-06-08 03:53 . 2009-06-08 03:53 -------- d-----w- c:\program files\Common Files\PC Tools
2009-06-07 19:57 . 2009-06-07 19:57 17801 ----a-w- c:\windows\system32\drivers\AegisP.sys
2009-06-07 19:56 . 2009-06-07 19:56 -------- d-----w- c:\program files\Belkin
2009-06-04 21:21 . 2009-04-30 04:17 -------- d-----w- c:\documents and settings\TAX\Application Data\AdobeUM
2009-06-03 19:09 . 2005-01-08 06:27 1291264 ----a-w- c:\windows\system32\quartz.dll
2009-05-26 21:59 . 2009-05-26 21:59 174 ----a-w- c:\documents and settings\TAX\Application Data\asd.bat
2009-05-26 21:59 . 2009-05-26 21:59 174 ----a-w- c:\documents and settings\TAX\Application Data\asd.bat
2009-05-24 17:08 . 2009-05-24 17:08 13696 ----a-w- c:\windows\system32\drivers\wpsnuio.sys
2009-05-23 14:27 . 2009-05-23 14:21 19558 ----a-w- c:\windows\hpoins01.dat
2009-05-23 14:16 . 2009-05-23 14:16 10134 ----a-r- c:\documents and settings\TAX\Application Data\Microsoft\Installer\{4CCC7F68-A437-4559-A840-F5E010934951}\ARPPRODUCTICON.exe
2009-05-10 17:31 . 2005-01-08 07:54 87447 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-05-07 15:32 . 2005-01-08 06:27 345600 ----a-w- c:\windows\system32\localspl.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2004-11-25 5419008]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-2032953301-357304917-1260796959-500\Scripts\Logon\]
"Script"=Default Domain.cmd
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-2032953301-357304917-1260796959-500\Scripts\Logon\1]
"Script"=BK.cmd
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\TOSHIBA\\ivp\\NetInt\\Netint.exe"=
"c:\\TOSHIBA\\Ivp\\ISM\\pinger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [7/11/2009 10:32 AM 64160]
R1 DualPointDev;DualPointDev;c:\program files\Toshiba\DualPointUtility\DualPointDev.sys [12/11/2004 8:24 AM 6144]
R1 TMEI3E;TMEI3E;c:\windows\system32\drivers\TMEI3E.sys [1/8/2005 3:33 PM 5888]
R2 Tmesrv;Tmesrv3;c:\program files\Toshiba\TME3\TMESRV31.exe [1/8/2005 3:33 PM 126976]
S3 BLKWGN;Belkin Wireless G Notebook Card Service;c:\windows\system32\drivers\BLKWGN.sys [6/7/2009 2:57 PM 463872]
S3 Cpmt;Cisco Media Termination;c:\windows\system32\Drivers\Cpmt.sys --> c:\windows\system32\Drivers\Cpmt.sys [?]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [7/3/2009 9:49 AM 1029456]
S3 wlanndi5;wlanndi5 NDIS Protocol Driver;c:\windows\system32\wlanndi5.sys [4/21/2004 5:51 PM 16384]
.
Contents of the 'Scheduled Tasks' folder
2009-07-27 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-07-03 14:49]
2009-07-31 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
.
.
------- Supplementary Scan -------
.
LSP: c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-07-31 21:28
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(616)
c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll
- - - - - - - > 'explorer.exe'(4088)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\program files\TOSHIBA\TME3\TMEEJMD.DLL
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\acs.exe
c:\program files\Toshiba\ConfigFree\CFSvcs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\nvsvc32.exe
c:\program files\PC Tools AntiVirus\PCTAVSvc.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\Toshiba\TME3\TMEEJME.exe
c:\windows\system32\sessmgr.exe
.
**************************************************************************
.
Completion time: 2009-08-01 21:32 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-01 02:31
Pre-Run: 24,784,023,552 bytes free
Post-Run: 24,788,299,776 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
168 --- E O F --- 2009-07-30 12:40