I followed the instructions. Here is the log file.
ComboFix 08-12-07.04 - Kishkoway 2008-12-08 22:21:41.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.206 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Jennifer\Local Settings\Temporary Internet Files\fbk.sts
c:\windows\IE4 Error Log.txt
c:\windows\system32\bxxqfjwh.dll
c:\windows\system32\ddcApnNH.dll
c:\windows\system32\dhpbdb.dll
c:\windows\system32\drddth.dll
c:\windows\system32\eolyspdd.dll
c:\windows\system32\EOVxayxx.ini
c:\windows\system32\EOVxayxx.ini2
c:\windows\system32\flekat.dll
c:\windows\system32\gkgqorfh.dll
c:\windows\system32\gvhwkmyg.dll
c:\windows\system32\icajnx.dll
c:\windows\system32\idqzec.dll
c:\windows\system32\ilgspmac.dll
c:\windows\system32\impsvwfs.dll
c:\windows\system32\jlulfb.dll
c:\windows\system32\jnheaj.dll
c:\windows\system32\jrpvdfdv.dll
c:\windows\system32\knfriyir.dll
c:\windows\system32\ltrvorvv.dll
c:\windows\system32\mcrh.tmp
c:\windows\system32\pwiygfoh.dll
c:\windows\system32\qnqkrmql.dll
c:\windows\system32\sknuphie.dll
c:\windows\system32\soqaogmy.dll
c:\windows\system32\tlxktspo.dll
c:\windows\system32\usadigsk.dll
c:\windows\system32\uyknjq.dll
c:\windows\system32\vmxvqr.dll
c:\windows\system32\vtUoPICR.dll
c:\windows\system32\wacnov.dll
c:\windows\system32\wpv691228088626.cpx
c:\windows\system32\xxyaxVOE.dll
c:\windows\wiaserviv.log
.
((((((((((((((((((((((((( Files Created from 2008-11-09 to 2008-12-09 )))))))))))))))))))))))))))))))
.
2008-12-08 20:46 . 2008-12-08 20:46 1,525,316 –ahs—- c:\windows\system32\sfwvspmi.ini
2008-12-08 20:45 . 2008-12-08 20:45 d——– c:\documents and settings\Jennifer\Application Data\SUPERAntiSpyware.com
2008-12-08 20:45 . 2008-12-08 20:45 d——– c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2008-12-08 20:02 . 2008-12-08 20:03 d——– C:\rsit
2008-12-08 20:02 . 2008-12-08 21:55 d——– c:\program files\trend micro
2008-12-05 15:18 . 2008-12-05 15:19 d——– c:\documents and settings\All Users\Application Data\AntiVir PersonalEdition Classic
2008-12-03 22:53 . 2008-12-03 22:53 d——– c:\documents and settings\All Users\Application Data\Lavasoft
2008-11-16 07:29 . 2008-11-16 07:29 d——– c:\program files\Kiwee Toolbar
2008-11-16 07:29 . 2008-11-16 07:29 d——– c:\documents and settings\LocalService\Application Data\agi
2008-11-16 07:27 . 2008-11-16 07:27 2,117,632 –a—— c:\windows\system32\python25.dll
2008-11-16 07:27 . 2008-09-16 11:26 1,332,197 –a—— c:\windows\system32\pythondll.zip
2008-11-16 07:27 . 2008-11-16 07:27 339,968 –a—— c:\windows\system32\pythoncom25.dll
2008-11-16 07:27 . 2008-11-16 07:27 114,688 –a—— c:\windows\system32\pywintypes25.dll
2008-11-14 05:32 . 2008-11-14 05:32 d——– c:\documents and settings\All Users\Application Data\Blizzard
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-09 01:42 ——— d—–w c:\program files\Common Files\Wise Installation Wizard
2008-12-08 20:35 ——— d—–w c:\documents and settings\Jennifer\Application Data\BitTorrent
2008-12-06 09:03 ——— d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-02 12:04 ——— d—–w c:\documents and settings\Jennifer\Application Data\Skype
2008-12-02 04:54 ——— d—–w c:\program files\CA Yahoo! Anti-Spy
2008-11-21 23:22 ——— d—–w c:\documents and settings\Jennifer\Application Data\SecondLife
2008-11-18 03:50 ——— d—–w c:\program files\MySpace
2008-11-01 15:55 ——— d—–w c:\program files\MSXML 6.0
2008-10-10 18:37 ——— d—–w c:\documents and settings\Jennifer\Application Data\Winamp
2008-10-09 19:25 ——— d—–w c:\program files\Netflix
2006-08-15 03:28 24,096 -c–a-w c:\documents and settings\Jennifer\Application Data\GDIPFONTCACHEV1.DAT
2008-01-15 14:13 861 –sha-w c:\windows\system32\dllcache\aamonit.dll
2008-01-15 14:13 847,872 –sha-r c:\windows\system32\dllcache\libeay32.dll
2008-01-15 14:13 159,744 –sha-r c:\windows\system32\dllcache\ssleay32.dll
2008-01-15 14:13 64,000 –sha-r c:\windows\system32\dllcache\syschk32.dll
2008-01-15 14:13 488 –sha-r c:\windows\system32\dllcache\winsvcf.dll
2008-01-15 14:13 895 –sha-r c:\windows\system32\dllcache\winsvcn.dll
2007-07-31 22:42 55,296 -csha-r c:\windows\system32\spool\drivers\raddrv.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2006-11-30 4662776]
"SpybotSD TeaTimer"="e:\spybot - search & destroy\TeaTimer.exe" [2008-09-16 1833296]
"SUPERAntiSpyware"="E:\SUPERAntiSpyware.exe" [2008-12-04 1809648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-01-19 339968]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 132496]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2005-05-26 180269]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2007-06-29 286720]
"WinampAgent"="e:\winamp\winampa.exe" [2007-10-10 36352]
"avgnt"="c:\program files\AntiVir PersonalEdition Classic\avgnt.exe" [2007-04-02 327720]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 c:\windows\soundman.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-05-16 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-24 29696]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\KEM.exe [2005-02-24 573440]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
WinZip Quick Pick.lnk - e:\winzip\WZQKPICK.EXE [2006-05-03 122880]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoViewOnDrive"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "E:\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-03 14:56 352256 E:\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=icajnx.dll idqzec.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinSvc32]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"e:\\World of Warcraft\\WoW-1.2.4-to-1.3.0-enUS-downloader.exe"=
"e:\\World of Warcraft\\WoW-1.2.3-patch-enUS-Downloader.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\SAM\\SAMBC.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"e:\\BitTorrent\\bittorrent.exe"=
"e:\\SecondLife\\SLVoice.exe"=
"e:\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\WINDOWS\\system32\\ftp.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"e:\\Soulseek\\SoulseekNS\\slsk.exe"=
"e:\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:WoW
"6112:TCP"= 6112:TCP:WoW
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R1 SASDIFSV;SASDIFSV;\??\E:\SASDIFSV.SYS [2008-12-04 8944]
R1 SASKUTIL;SASKUTIL;\??\E:\SASKUTIL.sys [2008-12-04 55024]
R2 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance;c:\program files\Firebird\Firebird_1_5\bin\fbguard.exe -s []
R3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance;c:\program files\Firebird\Firebird_1_5\bin\fbserver.exe -s []
R3 GETNDIS;VIA Networking Velocity Family Giga-bit Ethernet Adapter Driver;c:\windows\system32\DRIVERS\getnd5b.sys [2005-02-24 44544]
R3 SASENUM;SASENUM;\??\E:\SASENUM.SYS [2008-12-04 7408]
S2 PostgreSQL;PostgreSQL Database Server;"c:\program files\PostgreSQL\8.0-beta2-dev3\bin\pg_ctl.exe" runservice -N "PostgreSQL" -D "c:\program files\PostgreSQL\8.0-beta2-dev3\data\" []
S2 WinSvc;Windows services;c:\windows\system32\dllcache\winsvc.exe []
S2 WinSvc32;Windows application manager;c:\windows\system32\dllcache\winsvc32.exe []
S3 Aupclo;Aupclo; []
S3 Cdrmdis;Cdrmdis; []
S3 WinSvcDrv;WinSvcDrv;\??\c:\windows\system32\dllcache\winsvc32.sys []
.
Contents of the 'Scheduled Tasks' folder
2008-12-03 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 13:57]
.
- - - - ORPHANS REMOVED - - - -
BHO-{3494711E-1FFE-4439-9037-2FBD9E60B763} - c:\windows\system32\xxyaxVOE.dll
BHO-{72307D24-D6A0-4C77-AE48-79F89AF4622F} - (no file)
BHO-{8eb74e2a-aabe-430e-a930-fcb385e6fb41} - c:\windows\system32\vmxvqr.dll
BHO-{A63E645F-13BD-45ED-B15F-6E8C1BD57279} - (no file)
BHO-{fa831eaa-e8e2-4765-a511-2bfa3c011ce2} - c:\windows\system32\idqzec.dll
HKCU-Run-BitTorrent DNA - c:\program files\DNA\btdna.exe
HKU-Default-Run-GetModule30 - c:\program files\GetModule\GetModule30.exe
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
mStart Page = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/stp/ymsgr6/*http://www.yahoo.com
IE: &Yahoo! Search - file:///c:\program files\Yahoo!\Common/ycsrch.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Yahoo! &Dictionary - file:///c:\program files\Yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps - file:///c:\program files\Yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS - file:///c:\program files\Yahoo!\Common/ycsms.htm
c:\windows\Downloaded Program Files\DoggieDash.1.0.0.6.dll - O16 -: {6715D12F-213F-4C6E-ACE1-8A363F550B96}
hxxp://aolsvc.aol.com/onlinegames/free-trial-doggie-dash/DoggieDash.1.0.0.6.cab
c:\windows\Downloaded Program Files\DoggieDash.1.0.0.6.inf
FireFox -: Profile - c:\documents and settings\Jennifer\Application Data\Mozilla\Firefox\Profiles\s6y15soe.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-amo&p=
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.yahoo.com/
FF -: plugin - c:\documents and settings\Jennifer\Application Data\Mozilla\Firefox\Profiles\s6y15soe.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npmnqmp07051001.dll
FF -: plugin - c:\progra~1\Yahoo!\Common\npyaxmpb.dll
FF -: plugin - c:\program files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\NPAdbESD.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npmozax.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF -: plugin - c:\program files\Yahoo!\Shared\npYState.dll
FF -: plugin - e:\divx web player\DivX\DivX Content Uploader\npUpload.dll
FF -: plugin - e:\divx web player\DivX\DivX Player\npDivxPlayerPlugin.dll
FF -: plugin - e:\divx web player\DivX\DivX Web Player\npdivx32.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-12-08 22:32:06
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(472)
E:\SASWINLO.dll
c:\windows\system32\Ati2evxx.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
E:\aawservice.exe
c:\program files\AntiVir PersonalEdition Classic\avguard.exe
c:\program files\AntiVir PersonalEdition Classic\sched.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\program files\Firebird\Firebird_1_5\bin\fbguard.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\program files\Firebird\Firebird_1_5\bin\fbserver.exe
c:\program files\Yahoo!\Messenger\Ymsgr_tray.exe
c:\windows\system32\wscntfy.exe
c:\program files\Logitech\SetPoint\KHALMNPR.exe
c:\windows\system32\WgaTray.exe
.
**************************************************************************
.
Completion time: 2008-12-08 22:36:16 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-09 03:35:38
Pre-Run: 3,206,094,848 bytes free
Post-Run: 3,163,770,880 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
236 — E O F — 2007-11-14 08:25:25