not sure that I would like to be compared to a bug hahha.... Just glad all is well...
I ran the combofix.. this is the log hope it makes sense to you, I could read it upside down and it couldnt make less sense....
"User" - 2007-06-06 23:03:19 Service Pack 1 NTFS
ComboFix 07-06-3B - Running from: "C:\Documents and Settings\User\Desktop\"
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\Program Files\winupdates
C:\WINDOWS\b.exe
C:\WINDOWS\system32\info.txt
((((((((((((((((((((((((( Files Created from 2007-05-06 to 2007-06-06 )))))))))))))))))))))))))))))))
2007-06-04 05:31 <DIR> d-------- C:\DOCUME~1\User\APPLIC~1\Lavasoft
2007-06-03 22:48 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-06-03 22:45 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-06-03 22:39 446,464 --a------ C:\DOCUME~1\ADMINI~1\NTUSER.DAT
2007-06-02 00:30 <DIR> d-------- C:\Program Files\CCleaner
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-06-04 09:58:15 -------- d-----w C:\Program Files\ErrorKiller
2007-06-03 13:34:32 -------- d-----w C:\Program Files\Common Files\Companion Wizard
2007-06-03 12:48:06 -------- d-----w C:\Program Files\Lavasoft
2007-06-01 23:13:52 -------- d-----w C:\Program Files\Google
2007-06-01 22:55:07 -------- d-----w C:\Program Files\MSN Games
2004-11-09 10:20:29 56 --sh--r C:\WINDOWS\system32\EB051588A6.sys
2004-11-11 01:16:38 848 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}=C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2004-12-14 01:56]
{53707962-6F74-2D53-2644-206D7942484F}=C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2005-05-31 01:04]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll [2007-03-14 03:43]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2003-08-15 17:34 C:\WINDOWS\SOUNDMAN.EXE]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-10-28 21:10]
"PowerMenu"="%systemroot%\system32\powermenu.exe" []
"LWBMOUSE"="C:\Program Files\Mouse Driver\Mouse Driver\3.5\MOUSE32A.EXE" [2001-11-09 16:47]
"CTStartup"="C:\Program Files\Creative\Splash Screen\CTEaxSpl.exe" [2001-12-20 01:00]
"NOMAD Detector"="C:\Program Files\Creative\NOMAD Jukebox 3\PlayCenter2\CTNMRUN.EXE" [2002-06-26 13:16]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2004-10-10 17:35]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-10-25 17:58]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]
"SSC_UserPrompt"="C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe" [2004-11-02 16:59]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-10-30 08:36]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-06-03 22:45]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2006-10-07 22:20]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NOMAD Detector"="C:\Program Files\Creative\NOMAD Jukebox 3\PlayCenter2\CTNMRUN.EXE" [2002-06-26 13:16]
"Nero PhotoShow Media Manager"="C:\PROGRA~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe" [2006-01-14 07:22]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoVisualStyleChoice"=0 (0x0)
"NoColorChoice"=0 (0x0)
"NoSizeChoice"=0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
@=
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoLowDiskSpaceChecks"=1 (0x1)
"NoChangeKeyboardNavigationIndicators"=0 (0x0)
"NoSaveSettings"=0 (0x0)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2006-09-29 00:13]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
rundll32.exe irprops.cpl,,BluetoothAuthenticationAgent
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs*
Contents of the 'Scheduled Tasks' folder
2007-06-03 09:44:03 C:\WINDOWS\tasks\AppleSoftwareUpdate.job
2007-06-04 17:00:00 C:\WINDOWS\tasks\Disk Cleanup.job
**************************************************************************
catchme 0.3.692 W2K/XP/Vista - userland rootkit detector by Gmer,
http://www.gmer.netRootkit scan 2007-06-06 23:03:57
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CTStartup = C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run???p???w^?s?
?>?wH ?w?
???w*??w4???U??w4?
???D8?s4???.
?&2?
?\
\
??H?s.???3:?w.
?T?w?U?w\
\
`?
??C@?\
\
???s.
\
???s\
?&2?d??s?&2??C@?x?
??sx?
;?w\
??@
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-06-06 23:04:31
C:\ComboFix-quarantined-files.txt ... 2007-06-06 23:04
--- E O F ---
Still have to update anti virus..will do in morning and let you know if that helps...
can say thanks enough ... you are a champion!!!!!
thanks