Thank you so much, evilfantasy! I have followed your instructions. I used HijackThis on what you specified, and here is my ComboFixer Log:
ComboFix 08-11-04.02 - Mina 2008-11-04 19:39:19.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.932.81.1033.18.484 [GMT -8:00]
Running from: c:\documents and settings\Mina\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\bold.log
c:\documents and settings\Mina\Cookies\vypygej._dl
c:\windows\system32\_000006_.tmp.dll
.
((((((((((((((((((((((((( Files Created from 2008-10-05 to 2008-11-05 )))))))))))))))))))))))))))))))
.
2008-11-04 14:23 . 2008-11-04 14:23 410,976 --a------ c:\windows\system32\deploytk.dll
2008-11-04 03:35 . 2008-11-04 03:35 <DIR> d-------- c:\program files\CCleaner
2008-11-04 00:27 . 2008-11-04 00:27 <DIR> d-------- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2008-11-04 00:26 . 2008-11-04 00:26 <DIR> d-------- c:\program files\SUPERAntiSpyware
2008-11-04 00:26 . 2008-11-04 00:26 <DIR> d-------- c:\documents and settings\Mina\Application Data\SUPERAntiSpyware.com
2008-11-04 00:20 . 2008-11-04 00:20 <DIR> d-------- c:\program files\Common Files\Wise Installation Wizard
2008-11-02 20:22 . 2008-11-04 19:36 9,203 --a------ c:\windows\system32\Config.MPF
2008-11-02 20:21 . 2006-03-03 08:07 143,360 --a------ c:\windows\system32\dunzip32.dll
2008-11-02 20:18 . 2007-11-22 06:44 201,320 --a------ c:\windows\system32\drivers\mfehidk.sys
2008-11-02 20:18 . 2007-07-13 06:20 113,952 --a------ c:\windows\system32\drivers\Mpfp.sys
2008-11-02 20:18 . 2007-11-22 06:44 79,304 --a------ c:\windows\system32\drivers\mfeavfk.sys
2008-11-02 20:18 . 2007-12-02 12:51 40,488 --a------ c:\windows\system32\drivers\mfesmfk.sys
2008-11-02 20:18 . 2007-11-22 06:44 35,240 --a------ c:\windows\system32\drivers\mfebopk.sys
2008-11-02 20:18 . 2007-11-22 06:44 33,832 --a------ c:\windows\system32\drivers\mferkdk.sys
2008-11-02 20:17 . 2008-11-02 20:17 <DIR> d-------- c:\program files\McAfee.com
2008-11-02 20:17 . 2008-11-02 20:18 <DIR> d-------- c:\program files\Common Files\McAfee
2008-11-02 20:16 . 2008-11-02 23:43 <DIR> d-------- c:\program files\McAfee
2008-11-02 20:04 . 2008-11-02 20:22 <DIR> d-------- c:\documents and settings\All Users\Application Data\McAfee
2008-10-29 00:06 . 2008-10-29 00:28 <DIR> d-------- c:\documents and settings\Mina\Application Data\T-Time Preferences
2008-10-23 10:36 . 2008-10-15 08:34 337,408 --------- c:\windows\system32\dllcache\netapi32.dll
2008-10-21 11:22 . 2008-10-21 11:22 19,116 --a------ c:\documents and settings\All Users\Application Data\fuze.dat
2008-10-21 11:22 . 2008-10-21 11:22 18,864 --a------ c:\windows\system32\ijycej.com
2008-10-21 11:22 . 2008-10-21 11:22 17,365 --a------ c:\windows\apymawe._dl
2008-10-21 11:22 . 2008-10-21 11:22 16,852 --a------ c:\windows\system32\nepunufura.dl
2008-10-21 11:22 . 2008-10-21 11:22 15,981 --a------ c:\documents and settings\Mina\Application Data\qypocive.exe
2008-10-21 11:22 . 2008-10-21 11:22 15,595 --a------ c:\windows\system32\cokuk.com
2008-10-21 11:22 . 2008-10-21 11:22 15,310 --a------ c:\windows\lily.sys
2008-10-21 11:22 . 2008-10-21 11:22 15,215 --a------ c:\windows\vyzidyzu.ban
2008-10-21 11:22 . 2008-10-21 11:22 14,621 --a------ c:\documents and settings\Mina\Application Data\aqimu.scr
2008-10-21 11:22 . 2008-10-21 11:22 12,603 --a------ c:\windows\xigepefuhe.inf
2008-10-21 11:22 . 2008-10-21 11:22 11,455 --a------ c:\windows\fovapot.reg
2008-10-21 11:22 . 2008-10-21 11:22 10,189 --a------ c:\windows\emifipis._sy
2008-10-14 11:12 . 2008-08-14 02:11 2,189,184 --------- c:\windows\system32\dllcache\ntoskrnl.exe
2008-10-14 11:12 . 2008-08-14 02:09 2,145,280 --------- c:\windows\system32\dllcache\ntkrnlmp.exe
2008-10-14 11:12 . 2008-08-14 01:33 2,066,048 --------- c:\windows\system32\dllcache\ntkrnlpa.exe
2008-10-14 11:12 . 2008-08-14 01:33 2,023,936 --------- c:\windows\system32\dllcache\ntkrpamp.exe
2008-10-14 11:12 . 2008-09-15 04:12 1,846,400 --------- c:\windows\system32\dllcache\win32k.sys
2008-10-14 11:12 . 2008-09-08 02:41 333,824 --------- c:\windows\system32\dllcache\srv.sys
2008-10-13 01:37 . 2008-11-02 02:03 <DIR> d-------- c:\documents and settings\Mina\Incomplete
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-04 22:30 --------- d-----w c:\program files\WildTangent
2008-11-04 22:25 --------- d-----w c:\program files\Java
2008-11-04 21:21 --------- d-----w c:\documents and settings\Mina\Application Data\WTablet
2008-11-02 21:27 2,864 ----a-w c:\windows\system32\winsock.dll
2008-11-02 21:27 2,864 ----a-w c:\windows\system32\dllcache\winsock.dll
2008-11-02 05:24 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
2008-10-27 10:25 --------- d-----w c:\documents and settings\Mina\Application Data\CoreFTP
2008-10-22 23:10 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2008-10-22 23:10 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
2008-10-21 19:22 12,553 ----a-w c:\program files\Common Files\elezu._dl
2008-10-10 22:11 --------- d-----w c:\program files\LimeWire
2008-09-24 22:04 --------- d-----w c:\program files\iriver
2008-09-24 17:00 --------- d-----w c:\documents and settings\LocalService\Application Data\WTablet
2008-09-22 22:19 --------- d-----w c:\documents and settings\Mina\Application Data\Malwarebytes
2008-09-22 22:19 --------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2008-09-15 12:12 1,846,400 ----a-w c:\windows\system32\win32k.sys
2008-09-11 04:04 --------- d-----w c:\documents and settings\All Users\Application Data\SYSTEMAX Software Development
2008-09-08 10:41 333,824 ----a-w c:\windows\system32\drivers\srv.sys
2008-09-07 21:52 --------- d-----w c:\program files\CoreFTP
2008-08-20 05:30 666,112 ----a-w c:\windows\system32\wininet.dll
2008-08-20 05:30 666,112 ------w c:\windows\system32\dllcache\wininet.dll
2008-08-20 05:30 619,520 ------w c:\windows\system32\dllcache\urlmon.dll
2008-08-20 05:30 3,067,904 ------w c:\windows\system32\dllcache\mshtml.dll
2008-08-20 05:30 1,499,136 ------w c:\windows\system32\dllcache\shdocvw.dll
2008-08-14 10:09 2,145,280 ----a-w c:\windows\system32\ntoskrnl.exe
2008-08-14 10:04 138,496 ------w c:\windows\system32\dllcache\afd.sys
2008-08-14 09:33 2,023,936 ----a-w c:\windows\system32\ntkrnlpa.exe
1999-07-07 00:00 6 -csh--r c:\windows\@@desktop.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ModemOnHold"="c:\program files\NetWaiting\netWaiting.exe" [2003-09-10 20480]
"DellSupport"="c:\progra~1\DELLSU~1\DSAgnt.exe" [2006-08-28 395776]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"Zinio DLM"="c:\program files\Zinio\ZinioReader.exe" [2008-04-30 3874886]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-12-13 98304]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-12-13 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-12-13 118784]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 761947]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2005-12-19 1347584]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2006-08-03 1032192]
"CTSVolFE.exe"="c:\program files\Creative\Mixer\CTSVolFE.exe" [2005-02-23 57344]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2007-05-02 184320]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2004-02-25 176128]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd.exe" [2003-08-04 49152]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 241664]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-10 208952]
"IMEKRMIG6.1"="c:\windows\ime\imkr6_1\IMEKRMIG.EXE" [2004-08-10 44032]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-10 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-10 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-10 455168]
"Corel Painter Essentials 21a"="c:\program files\Corel\Corel Painter Essentials 2\registration.exe" [2004-03-18 733184]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2007-11-15 286720]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2007-11-15 267048]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"ddoctorv2"="c:\program files\Comcast\Desktop Doctor\bin\sprtcmd.exe" [2008-04-24 202560]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-04 136600]
"SigmatelSysTrayApp"="stsystra.exe" [2006-03-24 c:\windows\stsystra.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]
Device Detector 3.lnk - c:\program files\Olympus\DeviceDetector\DevDtct2.exe [2008-01-11 118784]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-11-20 24576]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2003-09-16 237568]
Service Manager.lnk - c:\program files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2005-05-03 81920]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= c:\windows\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= c:\windows\Resources\Themes\Royale.theme
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-07-23 16:28 352256 c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Dell\\MediaDirect\\PCMService.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\AIM\\AIM Pro\\aimpro.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
R2 JavaQuickStarterService;Java Quick Starter;c:\program files\Java\jre6\bin\jqs.exe [2008-11-04 152984]
R3 wacommousefilter;Wacom Mouse Filter Driver;c:\windows\system32\DRIVERS\wacommousefilter.sys [2006-02-14 5632]
R3 wacomvhid;Wacom Virtual Hid Driver;c:\windows\system32\DRIVERS\wacomvhid.sys [2006-11-15 6272]
S3 VNUSB;VN Series Device;c:\windows\system32\DRIVERS\VNUSB.sys [2006-04-07 38496]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
\Shell\AutoRun\command - E:\setup.exe
*Newly Created Service* - JAVAQUICKSTARTERSERVICE
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder
2008-11-04 c:\windows\Tasks\At1.job
- c:\windows\system32\2Bj1asxC.exe []
2008-11-02 c:\windows\Tasks\At10.job
- c:\windows\system32\2Bj1asxC.exe []
2008-11-02 c:\windows\Tasks\At11.job
- c:\windows\system32\2Bj1asxC.exe []
2008-11-02 c:\windows\Tasks\At12.job
- c:\windows\system32\2Bj1asxC.exe []
2008-11-02 c:\windows\Tasks\At13.job
- c:\windows\system32\2Bj1asxC.exe []
2008-11-02 c:\windows\Tasks\At14.job
- c:\windows\system32\2Bj1asxC.exe []
2008-11-04 c:\windows\Tasks\At15.job
- c:\windows\system32\2Bj1asxC.exe []
2008-11-02 c:\windows\Tasks\At16.job
- c:\windows\system32\2Bj1asxC.exe []
2008-11-02 c:\windows\Tasks\At17.job
- c:\windows\system32\2Bj1asxC.exe []
2008-11-03 c:\windows\Tasks\At18.job
- c:\windows\system32\2Bj1asxC.exe []
2008-11-03 c:\windows\Tasks\At19.job
- c:\windows\system32\2Bj1asxC.exe []
2008-11-04 c:\windows\Tasks\At2.job
- c:\windows\system32\2Bj1asxC.exe []
2008-11-03 c:\windows\Tasks\At20.job
- c:\windows\system32\2Bj1asxC.exe []
2008-11-03 c:\windows\Tasks\At21.job
- c:\windows\system32\2Bj1asxC.exe []
2008-11-03 c:\windows\Tasks\At22.job
- c:\windows\system32\2Bj1asxC.exe []
2008-11-03 c:\windows\Tasks\At23.job
- c:\windows\system32\2Bj1asxC.exe []
2008-11-04 c:\windows\Tasks\At24.job
- c:\windows\system32\2Bj1asxC.exe []
2008-11-04 c:\windows\Tasks\At3.job
- c:\windows\system32\2Bj1asxC.exe []
2008-11-04 c:\windows\Tasks\At4.job
- c:\windows\system32\2Bj1asxC.exe []
2008-11-04 c:\windows\Tasks\At49.job
- c:\windows\system32\3Gpj7leJ.exe []
2008-11-04 c:\windows\Tasks\At5.job
- c:\windows\system32\2Bj1asxC.exe []
2008-11-04 c:\windows\Tasks\At50.job
- c:\windows\system32\3Gpj7leJ.exe []
2008-11-04 c:\windows\Tasks\At51.job
- c:\windows\system32\3Gpj7leJ.exe []
2008-11-04 c:\windows\Tasks\At52.job
- c:\windows\system32\3Gpj7leJ.exe []
2008-11-04 c:\windows\Tasks\At53.job
- c:\windows\system32\3Gpj7leJ.exe []
2008-11-04 c:\windows\Tasks\At54.job
- c:\windows\system32\3Gpj7leJ.exe []
2008-11-02 c:\windows\Tasks\At55.job
- c:\windows\system32\3Gpj7leJ.exe []
2008-11-02 c:\windows\Tasks\At56.job
- c:\windows\system32\3Gpj7leJ.exe []
2008-11-02 c:\windows\Tasks\At57.job
- c:\windows\system32\3Gpj7leJ.exe []
2008-11-02 c:\windows\Tasks\At58.job
- c:\windows\system32\3Gpj7leJ.exe []
2008-11-02 c:\windows\Tasks\At59.job
- c:\windows\system32\3Gpj7leJ.exe []
2008-11-04 c:\windows\Tasks\At6.job
- c:\windows\system32\2Bj1asxC.exe []
2008-11-02 c:\windows\Tasks\At60.job
- c:\windows\system32\3Gpj7leJ.exe []
2008-11-02 c:\windows\Tasks\At61.job
- c:\windows\system32\3Gpj7leJ.exe []
2008-11-02 c:\windows\Tasks\At62.job
- c:\windows\system32\3Gpj7leJ.exe []
2008-11-04 c:\windows\Tasks\At63.job
- c:\windows\system32\3Gpj7leJ.exe []
2008-11-02 c:\windows\Tasks\At64.job
- c:\windows\system32\3Gpj7leJ.exe []
2008-11-02 c:\windows\Tasks\At65.job
- c:\windows\system32\3Gpj7leJ.exe []
2008-11-03 c:\windows\Tasks\At66.job
- c:\windows\system32\3Gpj7leJ.exe []
2008-11-03 c:\windows\Tasks\At67.job
- c:\windows\system32\3Gpj7leJ.exe []
2008-11-03 c:\windows\Tasks\At68.job
- c:\windows\system32\3Gpj7leJ.exe []
2008-11-03 c:\windows\Tasks\At69.job
- c:\windows\system32\3Gpj7leJ.exe []
2008-11-02 c:\windows\Tasks\At7.job
- c:\windows\system32\2Bj1asxC.exe []
2008-11-03 c:\windows\Tasks\At70.job
- c:\windows\system32\3Gpj7leJ.exe []
2008-11-03 c:\windows\Tasks\At71.job
- c:\windows\system32\3Gpj7leJ.exe []
2008-11-04 c:\windows\Tasks\At72.job
- c:\windows\system32\3Gpj7leJ.exe []
2008-11-02 c:\windows\Tasks\At8.job
- c:\windows\system32\2Bj1asxC.exe []
2008-11-02 c:\windows\Tasks\At9.job
- c:\windows\system32\2Bj1asxC.exe []
2008-11-03 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]
2008-11-03 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-MsnMsgr - c:\program files\MSN Messenger\MsnMsgr.Exe
HKLM-Run-<NO NAME> - (no file)
.
------- Supplementary Scan -------
.
FireFox -: Profile - c:\documents and settings\Mina\Application Data\Mozilla\Firefox\Profiles\
0bxenldk.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.google.com
FF -: plugin - c:\documents and settings\Mina\Application Data\Mozilla\Firefox\Profiles\
0bxenldk.default\extensions\
[email protected]\platform\WINNT_x86-msvc\plugins\npmnqmp07076007.dll
FF -: plugin - c:\program files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF -: plugin - c:\program files\iTunes\Mozilla Plugins\npitunes.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npunagi2.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-11-04 19:42:07
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-11-04 19:44:07
ComboFix-quarantined-files.txt 2008-11-05 03:44:01
Pre-Run: 57,165,721,600 bytes free
Post-Run: 57,190,223,872 bytes free
300 --- E O F --- 2008-10-24 17:25:18