I cleaned hundreds of nasties on this thing so far. (co workers son's laptop) I noticed that ctfmona.exe was running, so did a search and ran across this site. I did the combofix after running a scan with avg. So hopefully I am following procedure and am posting the contents of the combofix log below. Please let me know if it looks like all is good. Thanks.
ComboFix 08-05-01.3 - delete 2008-05-03 21:34:48.1 - [color=red][b]FAT32[/b][/color]x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.154 [GMT -7:00]
Running from: C:\Documents and Settings\delete\Desktop\ComboFix.exe
* Created a new restore point
[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\salesmonitor
C:\Documents and Settings\Jeff Griffin\Start Menu\Programs\MalwareAlarm
C:\Documents and Settings\Jeff Griffin\Start Menu\Programs\MalwareAlarm\MalwareAlarm.lnk
C:\Documents and Settings\Jeff Griffin\Start Menu\Programs\MalwareAlarm\Uninstall.lnk
C:\Program Files\License_Manager
C:\Program Files\popcorn Terms.html
C:\WINDOWS\BM313e2b3d.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\Fonts\acrsecB.fon
C:\WINDOWS\msacm32.drv
C:\WINDOWS\nivavir.config
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\afcuickq.ini
C:\WINDOWS\system32\bipcudec.ini
C:\WINDOWS\system32\cigdysej.ini
C:\WINDOWS\system32\ckyrymlw.ini
C:\WINDOWS\system32\clbdll.dll
C:\WINDOWS\system32\dbutlwdd.ini
C:\WINDOWS\system32\dwgghsrj.ini
C:\WINDOWS\system32\egfjfnkb.ini
C:\WINDOWS\system32\etupkleg.ini
C:\WINDOWS\system32\fdmsxysi.ini
C:\WINDOWS\system32\fldlfhwu.ini
C:\WINDOWS\system32\jmmdfqxk.ini
C:\WINDOWS\system32\koywkvfm.ini
C:\WINDOWS\system32\levexguy.ini
C:\WINDOWS\system32\matgbbgk.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mfmicemf.ini
C:\WINDOWS\system32\nefxibrq.ini
C:\WINDOWS\system32\npqss.bak1
C:\WINDOWS\system32\npqss.bak2
C:\WINDOWS\system32\npqss.ini
C:\WINDOWS\system32\npqss.ini2
C:\WINDOWS\system32\npqss.tmp
C:\WINDOWS\system32\opfitrtd.ini
C:\WINDOWS\system32\oqstv.ini
C:\WINDOWS\system32\oqstv.ini2
C:\WINDOWS\system32\orfrvnac.ini
C:\WINDOWS\system32\pghianhf.ini
C:\WINDOWS\system32\piagjfsm.ini
C:\WINDOWS\system32\pnewdiji.ini
C:\WINDOWS\system32\pytdcinq.ini
C:\WINDOWS\system32\qjebrerl.ini
C:\WINDOWS\system32\rdwkddbn.ini
C:\WINDOWS\system32\rqtwa.bak1
C:\WINDOWS\system32\rqtwa.bak2
C:\WINDOWS\system32\rqtwa.ini
C:\WINDOWS\system32\rqtwa.ini2
C:\WINDOWS\system32\rqtwa.tmp
C:\WINDOWS\system32\sibhuqtc.ini
C:\WINDOWS\system32\sljvrrbd.ini
C:\WINDOWS\system32\smerchab.ini
C:\WINDOWS\system32\sssnbfao.ini
C:\WINDOWS\system32\svcp.csv
C:\WINDOWS\system32\tnrsspaa.ini
C:\WINDOWS\system32\ttfxcnda.ini
C:\WINDOWS\system32\ujqecogg.ini
C:\WINDOWS\system32\vrmfeopk.ini
C:\WINDOWS\system32\vuinurqv.ini
C:\WINDOWS\system32\winsub.xml
C:\WINDOWS\system32\wnmodupa.ini
C:\WINDOWS\system32\wvvwa.bak2
C:\WINDOWS\system32\wvvwa.ini
C:\WINDOWS\system32\wwefgfrh.ini
C:\WINDOWS\system32\xlhipnlq.ini
C:\WINDOWS\system32\xsrkefnf.ini
C:\WINDOWS\system32\ylwulkvt.ini
C:\WINDOWS\system32\yovyegdx.ini
.
((((((((((((((((((((((((( Files Created from 2008-04-04 to 2008-05-04 )))))))))))))))))))))))))))))))
.
2008-05-03 21:31 . 2008-05-03 21:31 <DIR> d-------- C:\WINDOWS\LastGood.Tmp
2008-05-03 21:30 . 2008-05-03 21:30 <DIR> d-------- C:\Documents and Settings\delete\Application Data\Apple Computer
2008-05-03 20:39 . 2008-05-03 20:39 <DIR> d--h----- C:\$AVG8.VAULT$
2008-05-03 20:27 . 2008-03-01 06:06 6,066,176 --------- C:\WINDOWS\system32\dllcache\ieframe.dll
2008-05-03 20:27 . 2007-04-17 02:32 2,455,488 --------- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-05-03 20:27 . 2007-03-07 22:10 991,232 --------- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-05-03 20:27 . 2008-03-01 06:06 459,264 --------- C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-05-03 20:27 . 2008-03-01 06:06 383,488 --------- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-05-03 20:27 . 2008-03-01 06:06 267,776 --------- C:\WINDOWS\system32\dllcache\iertutil.dll
2008-05-03 20:27 . 2008-03-01 06:06 63,488 --------- C:\WINDOWS\system32\dllcache\icardie.dll
2008-05-03 20:27 . 2008-03-01 06:06 52,224 --------- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-05-03 20:27 . 2008-02-22 03:00 13,824 --------- C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-05-03 20:19 . 2008-05-03 20:19 7,412 --a------ C:\WINDOWS\SEC988.PNF
2008-05-03 20:13 . 2008-05-03 20:13 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-05-03 20:13 . 2008-05-03 20:13 2,948 --a------ C:\WINDOWS\SEC84.PNF
2008-05-03 20:12 . 2008-05-03 20:12 <DIR> d-------- C:\WINDOWS\EHome
2008-05-03 19:57 . 2008-05-03 19:57 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-05-03 19:57 . 2008-05-03 19:57 <DIR> d-------- C:\Program Files\AVG
2008-05-03 19:57 . 2008-05-03 19:57 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-05-03 19:57 . 2008-05-03 19:57 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-05-03 19:57 . 2008-05-03 19:57 75,272 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-05-03 19:57 . 2008-05-03 19:57 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-05-03 19:32 . 2008-05-03 19:32 <DIR> d-------- C:\Documents and Settings\delete
2008-05-03 19:32 . 2008-05-03 21:39 114,688 --ah----- C:\Documents and Settings\delete\ntuser.dat.LOG
2008-05-02 09:12 . 2008-05-02 09:12 <DIR> d-------- C:\WINDOWS\system32\1033
2008-05-02 09:12 . 2008-05-02 09:12 <DIR> d--hs---- C:\FOUND.000
2008-05-01 15:37 . 2008-05-01 15:37 36 --a------ C:\WINDOWS\rasqervy.dll
2008-05-01 15:37 . 2008-05-01 15:37 8 --a------ C:\WINDOWS\sdfinacs.dll
2008-05-01 15:37 . 2008-05-01 15:37 0 --a------ C:\WINDOWS\hidrwupd.dll
2008-05-01 15:31 . 2008-05-01 15:31 <DIR> d-------- C:\Documents and Settings\Kathie Griffin\Application Data\AVGTOOLBAR
2008-05-01 15:18 . 2008-04-28 17:00 47,787,248 --a------ C:\avg_free_stf_en_8_100a1295.exe
2008-05-01 15:16 . 2008-05-01 15:16 <DIR> d-------- C:\Documents and Settings\Kathie Griffin\Application Data\Apple Computer
2008-05-01 14:34 . 2008-05-03 21:28 5 --a------ C:\WINDOWS\sdfixwcs.dll
2008-04-28 12:13 . 2008-05-03 21:28 139 --a------ C:\WINDOWS\wuasirvy.dll
2008-04-26 01:50 . 2008-05-01 15:29 1,482,705 ---hs---- C:\WINDOWS\system32\[u]0[/u]793F00c__.ini
2008-04-26 01:49 . 2008-04-26 01:49 0 --a------ C:\WINDOWS\system32\perfn2872.dat
2008-04-24 12:41 . 2008-04-24 12:41 40,960 --a------ C:\WINDOWS\system32\clbdll.old
2008-04-24 12:41 . 2004-08-04 05:00 4,224 --a------ C:\WINDOWS\system32\beep.sys
2008-04-24 12:41 . 2008-04-28 12:12 1,695 --a------ C:\WINDOWS\system32\clbcfg.dat
2008-04-23 13:15 . 2008-04-23 13:15 <DIR> d-------- C:\WINDOWS\system32\Client
2008-04-22 17:28 . 2008-04-24 13:14 1,541,144 ---hs---- C:\WINDOWS\system32\40DA600c__.ini
2008-04-11 19:59 . 2008-04-11 19:59 1,219,418 --a------ C:\Documents and Settings\Jeff Griffin\Application Data\Install.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-01 22:53 90,112 ----a-w C:\WINDOWS\DUMP6be9.tmp
2008-05-01 22:51 90,112 ----a-w C:\WINDOWS\DUMP60bd.tmp
2008-05-01 22:36 90,112 ----a-w C:\WINDOWS\DUMP6215.tmp
2008-04-01 06:16 --------- d-----w C:\Program Files\Safari
2008-04-01 06:10 --------- d-----w C:\Program Files\iPod
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\dllcache\win32k.sys
2008-03-17 02:08 --------- d-----w C:\Documents and Settings\Kelli Dimoree\Application Data\Yahoo!
2008-03-02 01:36 3,591,680 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2008-02-29 08:55 70,656 ----a-w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2008-02-29 08:55 625,664 ----a-w C:\WINDOWS\system32\dllcache\iexplore.exe
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\dllcache\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dllcache\dnsrslvr.dll
2008-02-20 05:32 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-02-16 08:59 474,112 ----a-w C:\WINDOWS\system32\dllcache\shlwapi.dll
2008-02-16 08:59 151,040 ----a-w C:\WINDOWS\system32\dllcache\cdfview.dll
2008-02-16 08:59 1,494,528 ----a-w C:\WINDOWS\system32\dllcache\shdocvw.dll
2008-02-16 08:59 1,054,208 ----a-w C:\WINDOWS\system32\dllcache\danim.dll
2008-02-16 08:59 1,023,488 ----a-w C:\WINDOWS\system32\dllcache\browseui.dll
2008-02-15 05:44 161,792 ----a-w C:\WINDOWS\system32\dllcache\ieakui.dll
2004-08-04 12:00 4,096 --sha-w C:\WINDOWS\system32\1112.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6E86EFAF-547C-4004-B614-4C11B1A2D76F}]
C:\WINDOWS\system32\cmpbk3.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8E9F39F8-40EE-4dd2-A439-2A90224E5DB5}]
1980-01-01 00:00 36864 --a------ C:\WINDOWS\system32\prxsmr.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}]
C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A1CF94CD-6DF7-495C-8FCC-0D2C6DB7ED45}]
C:\WINDOWS\system32\vtsqo.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AAD1C6AD-10AB-4cae-97FB-0AADDEC8A14B}]
1980-01-01 00:00 37376 --a------ C:\WINDOWS\system32\hmlphl.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B7950236-04AB-469E-8DE5-EF6A5C6AB7FD}]
C:\WINDOWS\system32\awvvw.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{A057A204-BACC-4D26-9990-79A187E2698E}"= "C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL" [ ]
[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-9990-79a187e2698e}]
[HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmona"="C:\WINDOWS\system32\ctfmona.exe" [ ]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-05-03 19:57 1177368]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"="C:\WINDOWS\system32\Macromed\Flash\GetFlash.exe" [2006-06-22 13:44 128648]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\awtqr]
C:\WINDOWS\system32\awtqr.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cbxwutu]
cbxwutu.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wvuroli]
wvuroli.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\__c00B31FD]
C:\WINDOWS\system32\__c00B31FD.dat
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\__c00CDC0E]
C:\WINDOWS\system32\__c00CDC0E.dat
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Bfi46.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Chl47.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\clbdriver.sys]
@="driver"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=C:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak software updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak software updater.lnk
backup=C:\WINDOWS\pss\Kodak software updater.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SBC Self Support Tool.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SBC Self Support Tool.lnk
backup=C:\WINDOWS\pss\SBC Self Support Tool.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Utility Tray.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Utility Tray.lnk
backup=C:\WINDOWS\pss\Utility Tray.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\autoload]
C:\Documents and Settings\Kathie Griffin\cftmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2004-08-04 05:00 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eRecoveryService]
--a------ 2005-06-29 17:26 352256 C:\Program Files\Acer\eRecovery\Monitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ntuser]
C:\WINDOWS\system32\drivers\spools.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiS Windows KeyHook]
--a------ 2005-03-04 13:13 32768 C:\WINDOWS\system32\keyhook.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiSPower]
--a------ 2005-02-25 19:35 49152 C:\WINDOWS\system32\SiSPower.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
--a------ 2005-02-23 18:13 77824 C:\WINDOWS\SOUNDMAN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
--a------ 2004-10-07 23:43 688218 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPLpr]
--a------ 2004-10-07 23:44 98394 C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ERSvc"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\Explorer.EXE"=
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-05-03 19:57]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-05-03 19:57]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-05-03 19:57]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-05-03 19:57]
R2 int15.sys;int15.sys;C:\Program Files\Acer\eRecovery\int15.sys [2005-01-13 14:46]
R2 VISSV;VISSV;C:\WINDOWS\system32\drivers\smccs.sys [1980-01-01 00:00]
R3 SISNICXP;SiS PCI Fast Ethernet Adapter Driver for NDIS51;C:\WINDOWS\system32\DRIVERS\sisnicxp.sys [2004-11-05 01:43]
S0 Bfi46;Bfi46;C:\WINDOWS\system32\Drivers\Bfi46.sys []
S0 Chl47;Chl47;C:\WINDOWS\system32\Drivers\Chl47.sys []
S0 pmpbwnuh;pmpbwnuh;C:\WINDOWS\system32\drivers\vtjqpiic.dat []
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager\subsystems]
"Windows"= basenssg32.dll
.
Contents of the 'Scheduled Tasks' folder
"2008-03-10 17:30:08 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [url]http://www.gmer.net[/url]
Rootkit scan 2008-05-03 21:39:33
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\pmpbwnuh]
"ImagePath"="system32\drivers\vtjqpiic.dat"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\csrss.exe
-> C:\WINDOWS\system32\basenssg32.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Acer\eManager\anbmServ.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
.
**************************************************************************
.
Completion time: 2008-05-03 21:41:38 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-04 04:41:30
Pre-Run: 15,088,779,264 bytes free
Post-Run: 15,192,637,440 bytes free
282 --- E O F --- 2008-05-04 03:31:59