right, i finally got it to work here is the combofix log
ComboFix 07-12-21.4 - jessica 2007-12-24 17:34:58.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.358 [GMT 0:00]
Running from: C:\Users\jessica\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Users\jessica\AppData\Roaming\macromedia\Flash Player\#SharedObjects\R8TKFQZW\iforex.com
C:\Users\jessica\AppData\Roaming\macromedia\Flash Player\#SharedObjects\R8TKFQZW\iforex.com\Emerp\Ev ents\flash_object.swf\user_data.sol
C:\Users\jessica\AppData\Roaming\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#ifo rex.com
C:\Users\jessica\AppData\Roaming\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#ifo rex.com\settings.sol
.
((((((((((((((((((((((((( Files Created from 2007-11-24 to 2007-12-24 )))))))))))))))))))))))))))))))
.
2007-12-22 13:01 . 2007-12-22 13:01 <DIR> d-------- C:\Users\jessica\AppData\Roaming\Apple Computer
2007-12-21 23:03 . 2007-12-21 23:03 <DIR> d-------- C:\Program Files\Trend Micro
2007-12-21 22:46 . 2007-12-21 22:48 <DIR> d-------- C:\Users\jessica\AppData\Roaming\RegClean
2007-12-14 18:27 . 2007-12-14 18:27 <DIR> d-------- C:\Program Files\Abexo
2007-12-14 17:56 . 2007-12-15 20:49 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-12-14 09:58 . 2007-12-14 09:58 256 --a------ C:\Windows\adaway.lic
2007-12-13 17:00 . 2007-12-13 17:00 1,327,104 --a------ C:\Windows\System32\quartz.dll
2007-12-13 16:59 . 2007-12-13 16:59 223,232 --a------ C:\Windows\System32\WMASF.DLL
2007-12-13 16:59 . 2007-12-13 16:59 9,728 --a------ C:\Windows\System32\LAPRXY.DLL
2007-12-13 16:59 . 2007-12-13 16:59 2,048 --a------ C:\Windows\System32\asferror.dll
2007-12-13 16:55 . 2007-12-13 16:55 56,320 --a------ C:\Windows\System32\iesetup.dll
2007-12-13 16:55 . 2007-12-13 16:55 26,624 --a------ C:\Windows\System32\ieUnatt.exe
2007-12-13 16:52 . 2007-12-13 16:52 130,048 --a------ C:\Windows\System32\drivers\srv2.sys
2007-12-13 16:52 . 2007-12-13 16:52 101,888 --a------ C:\Windows\System32\drivers\mrxsmb.sys
2007-12-13 16:52 . 2007-12-13 16:52 84,992 --a------ C:\Windows\System32\drivers\srvnet.sys
2007-12-13 16:52 . 2007-12-13 16:52 58,368 --a------ C:\Windows\System32\drivers\mrxsmb20.sys
2007-12-13 16:44 . 2007-12-13 16:44 3,504,824 --a------ C:\Windows\System32\ntkrnlpa.exe
2007-12-13 16:44 . 2007-12-13 16:44 3,470,520 --a------ C:\Windows\System32\ntoskrnl.exe
2007-12-13 16:43 . 2007-12-13 16:43 2,048 --a------ C:\Windows\System32\tzres.dll
2007-12-12 21:07 . 2007-12-12 21:07 <DIR> d-------- C:\Windows\RegistryCleaner
2007-12-12 20:29 . 2007-12-12 20:29 <DIR> d-------- C:\Users\jessica\AppData\Roaming\CyberLink
2007-12-12 20:08 . 2007-12-12 20:09 <DIR> d-------- C:\Users\jessica\AppData\Roaming\SpywareBot
2007-12-12 19:23 . 2007-12-12 19:26 <DIR> d-------- C:\Users\jessica\AppData\Roaming\PrevxCSI
2007-12-12 19:23 . 2007-12-12 19:23 <DIR> d-------- C:\ProgramData\Prevx
2007-12-11 12:39 . 2007-12-12 17:19 1,896 --a------ C:\Windows\System32\SDRemoveDB.db
2007-12-11 12:38 . 2007-12-12 17:07 63 --a------ C:\Windows\system\SysSD.dll
2007-12-10 22:14 . 2005-09-23 08:29 626,688 --a------ C:\Windows\System32\msvcr80.dll
2007-12-10 21:28 . 2007-12-24 09:55 <DIR> d-------- C:\Users\jessica\AppData\Roaming\AVG7
2007-12-10 21:28 . 2007-12-21 12:19 55,304 --a------ C:\Windows\System32\drivers\avgwfp.sys
2007-12-10 21:28 . 2007-12-10 21:28 9,216 --a------ C:\Windows\System32\avgwlntf.dll
2007-12-10 21:27 . 2007-12-10 21:27 <DIR> d-------- C:\ProgramData\Grisoft
2007-12-10 21:27 . 2007-12-10 21:31 <DIR> d-------- C:\ProgramData\avg7
2007-12-10 21:11 . 2007-12-10 21:11 <DIR> d-------- C:\Windows\PCHEALTH
2007-12-10 21:01 . 2007-12-10 21:11 <DIR> d-------- C:\Program Files\Windows Live
2007-12-10 21:01 . 2007-12-10 21:11 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2007-12-10 21:00 . 2007-12-10 21:00 <DIR> d-------- C:\ProgramData\WLInstaller
2007-12-09 00:26 . 2007-12-10 21:53 <DIR> d-------- C:\ProgramData\Spybot - Search & Destroy
2007-12-08 20:57 . 2007-12-08 23:49 <DIR> d-------- C:\ProgramData\STOPzilla!
2007-12-08 20:57 . 2007-12-08 20:57 <DIR> d-------- C:\Program Files\Common Files\iS3
2007-12-08 00:09 . 2007-12-08 00:09 <DIR> d-------- C:\ProgramData\SiteAdvisor
2007-12-08 00:09 . 2007-12-08 00:09 <DIR> d-------- C:\Program Files\SiteAdvisor
2007-12-07 22:42 . 2007-12-07 22:42 <DIR> d-------- C:\ProgramData\Safe extra mode
2007-12-07 22:42 . 2007-12-08 20:37 <DIR> d-------- C:\ProgramData\LICENSE FORD HOPE DRAW
2007-11-27 22:36 . 2007-12-19 22:59 230,424 --a------ C:\img2-001.raw
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2007-12-21 23:50 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-21 23:50 --------- d-----w C:\Program Files\Common Files\InstallShield
2007-12-20 09:28 --------- d-----w C:\Program Files\SUPERAntiSpyware
2007-12-14 17:56 --------- d-----w C:\Users\jessica\AppData\Roaming\SUPERAntiSpyware. com
2007-12-14 10:04 --------- d-----w C:\Program Files\Google
2007-12-13 16:56 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2007-12-12 20:29 --------- d-----w C:\ProgramData\CyberLink
2007-12-12 19:50 --------- d-----w C:\Program Files\Windows Live Toolbar
2007-12-08 20:37 --------- d-----w C:\ProgramData\McAfee
2007-12-08 13:15 --------- d-----w C:\Users\jessica\AppData\Roaming\SiteAdvisor
2007-12-04 10:29 --------- d-----w C:\Program Files\Java
2007-11-26 23:33 --------- d-----w C:\Users\jessica\AppData\Roaming\LimeWire
2007-11-21 20:10 --------- d-----w C:\ProgramData\SUPERAntiSpyware.com
2007-11-21 20:04 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-11-21 20:02 --------- d-----w C:\ProgramData\Symantec
2007-11-21 20:02 --------- d-----w C:\Program Files\Symantec
2007-10-18 11:31 51,224 ----a-w C:\Windows\System32\sirenacm.dll
2007-10-11 09:12 84,480 ----a-w C:\Windows\System32\INETRES.dll
2007-10-11 09:12 737,792 ----a-w C:\Windows\System32\inetcomm.dll
2007-10-11 09:09 788,992 ----a-w C:\Windows\System32\rpcrt4.dll
2007-09-08 19:35 174 --sha-w C:\Program Files\desktop.ini
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2006-11-02 12:35]
"WindowsWelcomeCenter"="oobefldr.dll" [2006-11-02 12:34 C:\Windows\System32\oobefldr.dll]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06]
"Grim chic"="C:\ProgramData\SizeJoyJoy.wqqscw3" [2007-12-23 21:43]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2007-02-15 09:07 C:\Windows\RtHDVCpl.exe]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-10-27 21:50]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
"snpstd3"="C:\Windows\vsnpstd3.exe" [2006-09-19 08:07]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-12-21 12:19]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-12-10 21:27]
[hkey_local_machine\software\microsoft\windows\curr entversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgwlntf]
avgwlntf.dll 2007-12-10 21:28 9216 C:\Windows\System32\avgwlntf.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\contro l\securityproviders]
SecurityProviders credssp.dll
R3 AvgWFP;AVG7 Firewall Driver x86;C:\Windows\system32\Drivers\avgwfp.sys [2007-12-21 12:19]
R3 R300;R300;C:\Windows\system32\DRIVERS\atikmdag.sys [2007-01-25 16:19]
R3 rt61x86;Ralink RT61 Wireless Driver for Windows Vista;C:\Windows\system32\DRIVERS\netr61.sys [2007-05-11 16:28]
S3 NETw3v32;Intel(R) PRO/Wireless 3945ABG Adapter Driver for Windows Vista 32 Bit;C:\Windows\system32\DRIVERS\NETw3v32.sys [2006-11-02 07:30]
S3 RTL8169;Realtek 8169 NT Driver;C:\Windows\system32\DRIVERS\Rtlh86.sys [2006-11-02 07:30]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalSystemNetworkRestricted REG_MULTI_SZ hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc EMDMgmt TabletInputService wlansvc WPDBusEnum
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder
"2007-12-22 09

38 C:\Windows\Tasks\RegClean Scheduled Scan.job"
- C:\Program Files\RegClean\RegClean.ex
"2007-12-13 16:25:38 C:\Windows\Tasks\SpywareBot Scheduled Scan.job"
- C:\Program Files\SpywareBot\SpywareBot.ex
- C:\Program Files\SpywareBot
"2007-12-23 23:47:37 C:\Windows\Tasks\User_Feed_Synchronization-{238D96AB-AFEB-4DFE-94D0-5388151FED2A}.job"
- C:\Windows\system32\msfeedssync.exe
.
************************************************** ************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-12-24 17:39:15
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0