MAN what an ugly POS to kill.... finally got it with this:
Malwarebytes' Anti-Malware 1.09
Database version: 552
Scan type: Quick Scan
Objects scanned: 41652
Time elapsed: 16 minute(s), 31 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 7
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 3
Files Infected: 8
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{c4ee31f3-4768-11d2-be5c-00a0c9a83da1} (Rogue.WinFixer) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{e94eb13e-d78f-0857-7734-5e67a49ffff1} (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{db9fba9d-ab1b-4cc6-9745-f3b549d64e40} (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{7d7bd0c4-4913-4933-b870-7388a7bffb82} (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{fca3958a-8d38-4d14-8b81-ccd7f68a8a01} (Rogue.VirusHeat) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dhlp (Rogue.Multiple) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\E404.e404mgr (Trojan.BHO) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{7d7bd0c4-4913-4933-b870-7388a7bffb82} (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run\user32.dll (Trojan.Zlob) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
C:\Program Files\Common Files\WinSecureAv (Rogue.WinSecureAv) -> Quarantined and deleted successfully.
C:\Program Files\Helper (Adware.BHO) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\WinSecureAv (Rogue.WinSecureAv) -> Quarantined and deleted successfully.
Files Infected:
C:\WINDOWS\system32\tdidrv32.sys (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Program Files\Common Files\WinSecureAv\bm.exe (Rogue.WinSecureAv) -> Quarantined and deleted successfully.
C:\Program Files\Common Files\WinSecureAv\ugac.exe (Rogue.WinSecureAv) -> Quarantined and deleted successfully.
C:\Program Files\Helper\1206331442.dll (Adware.BHO) -> Quarantined and deleted successfully.
C:\Program Files\Helper\1206331855.dll (Adware.BHO) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\WinSecureAv\Contact Customer Support.lnk (Rogue.WinSecureAv) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\WinSecureAv\Uninstall WinSecureAv.lnk (Rogue.WinSecureAv) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\WinSecureAv\WinSecureAv.lnk (Rogue.WinSecureAv) -> Quarantined and deleted successfully.
dude

so far 2 spybot's 1 adaware, 2 avg and an online norton scan reveal nothing left.
I had to do 13 manual reg edits too.
I rock!
