here it is - I am going to leave computer on tonight to see if it sends out emails again - thanks for your help.
ComboFix 11-07-20.05 - Owner 07/20/2011 17:48:35.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.510.253 [GMT -5:00]
Running from: c:\documents and settings\Owner\Desktop\email problem\ComboFix.exe
AV: Trend Micro Titanium Internet Security *Enabled/Updated* {7D2296BC-32CC-4519-917E-52E652474AF5}
FW: Trend Micro Firewall Booster *Disabled* {3E790E9E-6A5D-4303-A7F9-185EC20F3EB6}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\drvrtmp
c:\windows\system32\service
c:\windows\system32\service\19112010_TIS17_SfFniAU.log
c:\windows\system32\service\22112010_TIS17_SfFniAU.log
.
.
((((((((((((((((((((((((( Files Created from 2011-06-20 to 2011-07-20 )))))))))))))))))))))))))))))))
.
.
2011-07-19 08:55 . 2011-07-19 08:55 388096 ----a-r- c:\documents and settings\Owner\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-07-18 20:22 . 2011-07-18 20:22 -------- d-----w- c:\documents and settings\Owner\Application Data\SUPERAntiSpyware.com
2011-07-18 20:22 . 2011-07-18 20:22 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2011-07-18 20:22 . 2011-07-18 20:23 -------- d-----w- c:\program files\SUPERAntiSpyware
2011-07-17 23:33 . 2011-07-17 23:33 -------- d-----w- c:\documents and settings\Pam\Application Data\Malwarebytes
2011-07-17 10:11 . 2011-07-17 10:11 -------- d-----w- c:\windows\system32\wbem\Repository
2011-07-16 04:06 . 2009-08-07 00:23 274288 ----a-w- c:\windows\system32\mucltui.dll
2011-07-16 04:06 . 2009-08-07 00:23 215920 ----a-w- c:\windows\system32\muweb.dll
2011-07-15 19:52 . 2011-07-15 19:52 -------- d-----w- c:\documents and settings\Owner\Application Data\Leadertech
2011-07-15 19:40 . 2011-07-15 19:40 -------- d-----w- c:\program files\Common Files\Sonic
2011-07-15 19:37 . 2011-07-15 19:38 -------- d-----w- c:\program files\Common Files\Sonic Shared
2011-07-15 19:37 . 2004-08-13 07:56 40544 ----a-w- c:\windows\system32\drivers\drvnddm.sys
2011-07-15 19:37 . 2004-08-04 08:21 87136 ----a-w- c:\windows\system32\drivers\drvmcdb.sys
2011-07-15 19:37 . 2004-08-13 06:05 98358 ----a-w- c:\windows\dla.exe
2011-07-15 19:37 . 2004-08-13 06:05 61498 ----a-w- c:\windows\system32\tfswapi.dll
2011-07-15 19:37 . 2004-07-14 16:29 5627 ----a-w- c:\windows\system32\drivers\sscdbhk5.sys
2011-07-15 19:37 . 2004-07-14 16:28 23545 ----a-w- c:\windows\system32\drivers\ssrtln.sys
2011-07-15 19:37 . 2011-07-15 19:37 -------- d-----w- c:\program files\Sonic
2011-07-15 12:16 . 2011-07-15 12:16 -------- d-----w- c:\documents and settings\Elizabeth\Application Data\Template
2011-07-15 12:06 . 2011-07-15 12:06 -------- d-sh--w- c:\windows\ftpcache
2011-07-15 12:06 . 2011-07-15 12:06 -------- d-----w- c:\documents and settings\Pam\Application Data\Template
2011-07-15 11:25 . 2011-07-15 11:25 -------- d-----w- c:\documents and settings\Owner\Application Data\Template
2011-07-15 11:18 . 2011-07-16 09:54 -------- d-----w- c:\program files\Microsoft Works
2011-07-01 22:11 . 2011-07-01 22:18 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2011-07-01 12:20 . 2011-07-01 12:20 -------- d-----w- c:\program files\Common Files\Java
2011-07-01 12:19 . 2011-07-01 12:19 -------- d-----w- c:\windows\Sun
2011-07-01 12:19 . 2011-07-01 12:19 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-07-01 12:19 . 2011-07-01 12:18 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-07-01 12:18 . 2011-07-01 12:18 -------- d-----w- c:\program files\Java
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-18 20:06 . 2011-05-16 00:33 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-07-07 00:52 . 2011-05-29 01:45 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-07-07 00:52 . 2011-05-29 01:45 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-06-02 14:02 . 2004-08-12 14:09 1858944 ----a-w- c:\windows\system32\win32k.sys
2011-05-29 01:48 . 2011-05-29 01:48 709456 ----a-w- c:\windows\is-T45LP.exe
2011-05-21 22:53 . 2011-03-06 22:34 92112 ----a-w- c:\windows\system32\drivers\tmtdi.sys
2011-05-21 22:53 . 2011-02-06 20:49 80464 ----a-w- c:\windows\system32\drivers\tmactmon.sys
2011-05-21 22:53 . 2011-02-06 20:49 64080 ----a-w- c:\windows\system32\drivers\tmevtmgr.sys
2011-05-21 22:53 . 2011-02-06 20:49 189520 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2011-05-02 15:31 . 2010-11-19 04:02 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-04-29 17:25 . 2004-08-12 14:04 151552 ----a-w- c:\windows\system32\schannel.dll
2011-04-29 16:19 . 2004-08-12 14:00 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-26 11:07 . 2004-08-12 14:09 293376 ----a-w- c:\windows\system32\winsrv.dll
2011-04-26 11:07 . 2004-08-12 13:56 33280 ----a-w- c:\windows\system32\csrsrv.dll
2011-04-25 16:11 . 2004-08-12 14:09 916480 ----a-w- c:\windows\system32\wininet.dll
2011-04-25 16:11 . 2004-08-12 13:59 43520 ------w- c:\windows\system32\licmgr10.dll
2011-04-25 16:11 . 2004-08-12 13:58 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-04-25 12:01 . 2004-08-12 13:57 385024 ----a-w- c:\windows\system32\html.iec
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Trend Micro Titanium"="c:\program files\Trend Micro\Titanium\UIFramework\uiWinMgr.exe" [2011-02-17 1111568]
"Trend Micro Client Framework"="c:\program files\Trend Micro\UniClient\UiFrmWrk\UIWatchDog.exe" [2011-02-10 116752]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTSysVol]
2003-09-17 16:43 57344 ----a-w- c:\program files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EasyLinkAdvisor]
2007-03-15 23:16 454784 ----a-w- c:\program files\Linksys EasyLink Advisor\LinksysAgent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
2005-09-20 15:32 77824 ----a-w- c:\windows\system32\hkcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
2005-09-20 15:36 114688 ----a-w- c:\windows\system32\igfxpers.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]
2005-09-20 15:35 94208 ----a-w- c:\windows\system32\igfxtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2011-04-08 17:59 254696 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
2000-05-11 07:00 90112 ------w- c:\windows\Updreg.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfcCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxs08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqfxt08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgplgtupl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgpc01.exe"=
"c:\\Program Files\\HP\\HP Software Update\\HPWUCli.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\smart web printing\\SmartWebPrintExe.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\{7E0E61CC-1C99-429D-BEA7-C4DD5B898D2A}\\setup\\hpznui01.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management
.
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [7/12/2011 4:55 PM 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [7/12/2011 4:55 PM 67664]
R2 AdvancedSystemCareService;Advanced SystemCare Service;c:\program files\IObit\Advanced SystemCare 4\ASCService.exe [5/22/2011 6:27 PM 353168]
R2 Amsp;Trend Micro Solution Platform;c:\program files\Trend Micro\AMSP\coreServiceShell.exe [5/21/2011 6:04 PM 188272]
R2 IMFservice;IMF Service;c:\program files\IObit\IObit Malware Fighter\IMFsrv.exe [6/3/2011 6:35 PM 821080]
R2 tmevtmgr;tmevtmgr;c:\windows\system32\drivers\tmevtmgr.sys [2/6/2011 3:49 PM 64080]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 2:16 PM 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [12/7/2010 1:41 PM 136176]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [12/7/2010 1:41 PM 136176]
S3 nosGetPlusHelper;getPlus(R) Helper 3004;c:\windows\System32\svchost.exe -k nosGetPlusHelper [8/12/2004 9:06 AM 14336]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [8/12/2004 9:06 AM 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 2:16 PM 753504]
S4 FileMonitor;FileMonitor;c:\program files\IObit\IObit Malware Fighter\Drivers\wxp_x86\FileMonitor.sys [6/25/2011 1:32 PM 239472]
.
--- Other Services/Drivers In Memory ---
.
*Deregistered* - IPVNMon
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
WINRM REG_MULTI_SZ WINRM
nosGetPlusHelper REG_MULTI_SZ nosGetPlusHelper
.
Contents of the 'Scheduled Tasks' folder
.
2011-07-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-12-07 18:41]
.
2011-07-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-12-07 18:41]
.
2011-07-20 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-789336058-113007714-682003330-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-11-05 17:33]
.
2011-07-20 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-789336058-113007714-682003330-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-11-05 17:33]
.
2011-07-20 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-789336058-113007714-682003330-1005.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-11-05 17:33]
.
2011-07-19 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-789336058-113007714-682003330-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-11-05 17:33]
.
2011-07-20 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-789336058-113007714-682003330-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-11-05 17:33]
.
2011-07-15 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-789336058-113007714-682003330-1005.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-11-05 17:33]
.
2011-07-20 c:\windows\Tasks\User_Feed_Synchronization-{BFAAFD48-D974-4DEC-A133-C4B2198E1E76}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 10:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = iexplore
TCP: DhcpNameServer = 192.168.0.1
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.
- - - - ORPHANS REMOVED - - - -
.
MSConfigStartUp-RecoverFromReboot - c:\windows\Temp\RecoverFromReboot.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2011-07-20 18:01
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(808)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
.
Completion time: 2011-07-20 18:06:35
ComboFix-quarantined-files.txt 2011-07-20 23:06
.
Pre-Run: 36,295,467,008 bytes free
Post-Run: 36,477,050,880 bytes free
.
Here is logfile--- - I am going to leave computer ' on ' tonight to see if it sends out emails again.
thanks for your help.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
.
- - End Of File - - 0AB50A2FA6036E9EB0B4CC29B2F6F291