Thank You - Posted below is my new ComboFix log:
ComboFix 08-12-14.04 - Melissa 2008-12-15 21:41:26.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.510.205 [GMT -7:00]
Running from: c:\documents and settings\Melissa\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Melissa\Desktop\CFScript.txt
* Created a new restore point
FILE ::
c:\program files\malwareremovalbot\malwareremovalbot.exe
c:\windows\system32\f0rb45pe.exe
c:\windows\system32\geBuRKcB.dll
c:\windows\system32\karna.dat
c:\windows\system32\oygl44yr.exe
c:\windows\system32\qomfeffe.dll
c:\windows\system32\r7q7v4nc.exe
c:\windows\system32\rrozxe.dll
c:\windows\system32\sysvxd.exe
c:\windows\Tasks\At10.job
c:\windows\Tasks\At11.job
c:\windows\Tasks\At12.job
c:\windows\Tasks\At13.job
c:\windows\Tasks\At14.job
c:\windows\Tasks\At15.job
c:\windows\Tasks\At16.job
c:\windows\Tasks\At17.job
c:\windows\Tasks\At18.job
c:\windows\Tasks\At19.job
c:\windows\Tasks\At20.job
c:\windows\Tasks\At21.job
c:\windows\Tasks\At22.job
c:\windows\Tasks\At23.job
c:\windows\Tasks\At24.job
c:\windows\Tasks\At25.job
c:\windows\Tasks\At26.job
c:\windows\Tasks\At27.job
c:\windows\Tasks\At28.job
c:\windows\Tasks\At29.job
c:\windows\Tasks\At30.job
c:\windows\Tasks\At31.job
c:\windows\Tasks\At32.job
c:\windows\Tasks\At33.job
c:\windows\Tasks\At34.job
c:\windows\Tasks\At35.job
c:\windows\Tasks\At36.job
c:\windows\Tasks\At37.job
c:\windows\Tasks\At38.job
c:\windows\Tasks\At39.job
c:\windows\Tasks\At40.job
c:\windows\Tasks\At41.job
c:\windows\Tasks\At42.job
c:\windows\Tasks\At43.job
c:\windows\Tasks\At44.job
c:\windows\Tasks\At45.job
c:\windows\Tasks\At46.job
c:\windows\Tasks\At47.job
c:\windows\Tasks\At48.job
c:\windows\Tasks\At49.job
c:\windows\Tasks\At50.job
c:\windows\Tasks\At51.job
c:\windows\Tasks\At52.job
c:\windows\Tasks\At53.job
c:\windows\Tasks\At54.job
c:\windows\Tasks\At55.job
c:\windows\Tasks\At56.job
c:\windows\Tasks\At57.job
c:\windows\Tasks\At58.job
c:\windows\Tasks\At59.job
c:\windows\Tasks\At60.job
c:\windows\Tasks\At61.job
c:\windows\Tasks\At62.job
c:\windows\Tasks\At63.job
c:\windows\Tasks\At64.job
c:\windows\Tasks\At65.job
c:\windows\Tasks\At66.job
c:\windows\Tasks\At67.job
c:\windows\Tasks\At68.job
c:\windows\Tasks\At69.job
c:\windows\Tasks\At70.job
c:\windows\Tasks\At71.job
c:\windows\Tasks\At72.job
c:\windows\Tasks\At8.job
c:\windows\Tasks\At9.job
c:\windows\Tasks\MalwareRemovalBot Scheduled Scan.job
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Tasks\At10.job
c:\windows\Tasks\At11.job
c:\windows\Tasks\At12.job
c:\windows\Tasks\At13.job
c:\windows\Tasks\At14.job
c:\windows\Tasks\At15.job
c:\windows\Tasks\At16.job
c:\windows\Tasks\At17.job
c:\windows\Tasks\At18.job
c:\windows\Tasks\At19.job
c:\windows\Tasks\At20.job
c:\windows\Tasks\At21.job
c:\windows\Tasks\At22.job
c:\windows\Tasks\At23.job
c:\windows\Tasks\At24.job
c:\windows\Tasks\At25.job
c:\windows\Tasks\At26.job
c:\windows\Tasks\At27.job
c:\windows\Tasks\At28.job
c:\windows\Tasks\At29.job
c:\windows\Tasks\At30.job
c:\windows\Tasks\At31.job
c:\windows\Tasks\At32.job
c:\windows\Tasks\At33.job
c:\windows\Tasks\At34.job
c:\windows\Tasks\At35.job
c:\windows\Tasks\At36.job
c:\windows\Tasks\At37.job
c:\windows\Tasks\At38.job
c:\windows\Tasks\At39.job
c:\windows\Tasks\At40.job
c:\windows\Tasks\At41.job
c:\windows\Tasks\At42.job
c:\windows\Tasks\At43.job
c:\windows\Tasks\At44.job
c:\windows\Tasks\At45.job
c:\windows\Tasks\At46.job
c:\windows\Tasks\At47.job
c:\windows\Tasks\At48.job
c:\windows\Tasks\At49.job
c:\windows\Tasks\At50.job
c:\windows\Tasks\At51.job
c:\windows\Tasks\At52.job
c:\windows\Tasks\At53.job
c:\windows\Tasks\At54.job
c:\windows\Tasks\At55.job
c:\windows\Tasks\At56.job
c:\windows\Tasks\At57.job
c:\windows\Tasks\At58.job
c:\windows\Tasks\At59.job
c:\windows\Tasks\At60.job
c:\windows\Tasks\At61.job
c:\windows\Tasks\At62.job
c:\windows\Tasks\At63.job
c:\windows\Tasks\At64.job
c:\windows\Tasks\At65.job
c:\windows\Tasks\At66.job
c:\windows\Tasks\At67.job
c:\windows\Tasks\At68.job
c:\windows\Tasks\At69.job
c:\windows\Tasks\At70.job
c:\windows\Tasks\At71.job
c:\windows\Tasks\At72.job
c:\windows\Tasks\At8.job
c:\windows\Tasks\At9.job
c:\windows\Tasks\MalwareRemovalBot Scheduled Scan.job
.
((((((((((((((((((((((((( Files Created from 2008-11-16 to 2008-12-16 )))))))))))))))))))))))))))))))
.
2008-12-13 21:47 . 2008-12-13 21:47 577,024 --a--c--- c:\windows\system32\dllcache\user32.dll
2008-12-13 21:42 . 2008-12-13 21:43 <DIR> d-------- c:\windows\ERUNT
2008-12-13 21:29 . 2008-12-13 22:04 <DIR> d-------- C:\SDFix
2008-12-08 22:25 . 2008-12-08 22:25 <DIR> d-------- c:\program files\Trend Micro
2008-12-08 22:22 . 2008-12-08 22:22 410,984 --a------ c:\windows\system32\deploytk.dll
2008-12-08 22:22 . 2008-12-08 22:22 73,728 --a------ c:\windows\system32\javacpl.cpl
2008-12-08 19:04 . 2008-12-08 19:06 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-12-08 19:04 . 2008-12-03 19:52 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-08 19:04 . 2008-12-03 19:52 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-12-07 21:53 . 2008-12-07 21:53 <DIR> d-------- c:\program files\SUPERAntiSpyware
2008-12-07 21:53 . 2008-12-07 21:53 <DIR> d-------- c:\documents and settings\Melissa\Application Data\SUPERAntiSpyware.com
2008-12-07 21:53 . 2008-12-07 21:53 <DIR> d-------- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2008-12-07 21:52 . 2008-12-07 21:52 <DIR> d-------- c:\program files\Common Files\Wise Installation Wizard
2008-12-02 21:20 . 2008-12-02 21:20 <DIR> d-------- c:\program files\Alwil Software
2008-12-01 01:01 . 2004-08-04 00:56 380,416 --a------ c:\windows\system32\irprops.cpl
2008-12-01 01:01 . 2004-08-04 00:56 162,304 --a------ c:\windows\system32\wuaucpl.cpl
2008-12-01 00:52 . 2004-07-17 11:40 19,528 --a------ c:\windows\
002405_.tmp
2008-11-30 23:54 . 2008-11-30 23:54 <DIR> d-------- c:\program files\CCleaner
2008-11-30 19:37 . 2004-02-10 10:50 155,648 --a------ c:\windows\system32\igfxres.dll
2008-11-30 19:22 . 2004-08-03 23:04 156,672 --a--c--- c:\windows\system32\dllcache\winzm.ime
2008-11-30 19:22 . 2004-08-03 23:04 156,672 --a--c--- c:\windows\system32\dllcache\winsp.ime
2008-11-30 19:22 . 2004-08-03 23:04 156,672 --a--c--- c:\windows\system32\dllcache\winpy.ime
2008-11-30 19:22 . 2004-08-03 23:04 79,360 --a--c--- c:\windows\system32\dllcache\winar30.ime
2008-11-30 19:22 . 2003-07-16 13:23 69,120 --a--c--- c:\windows\system32\dllcache\wingb.ime
2008-11-30 19:22 . 2004-08-03 23:04 65,536 --a--c--- c:\windows\system32\dllcache\winime.ime
2008-11-30 19:22 . 2003-07-16 13:51 41,600 --a--c--- c:\windows\system32\dllcache\weitekp9.dll
2008-11-30 19:22 . 2003-07-16 13:51 31,232 --a--c--- c:\windows\system32\dllcache\weitekp9.sys
2008-11-30 19:20 . 2003-07-16 13:22 10,129,408 --a--c--- c:\windows\system32\dllcache\hwxkor.dll
2008-11-30 19:19 . 2003-07-16 13:22 13,463,552 --a--c--- c:\windows\system32\dllcache\hwxjpn.dll
2008-11-30 19:18 . 2001-08-17 22:36 2,134,528 --a--c--- c:\windows\system32\dllcache\EXCH_smtpsnap.dll
2008-11-30 19:18 . 2001-08-17 22:36 175,104 --a--c--- c:\windows\system32\dllcache\EXCH_smtpadm.dll
2008-11-30 19:18 . 2003-07-16 13:24 19,456 --a--c--- c:\windows\system32\dllcache\agt0804.dll
2008-11-30 19:18 . 2003-07-16 13:24 19,456 --a--c--- c:\windows\system32\dllcache\agt0412.dll
2008-11-30 19:18 . 2003-07-16 13:24 19,456 --a--c--- c:\windows\system32\dllcache\agt0411.dll
2008-11-30 19:18 . 2003-07-16 13:24 19,456 --a--c--- c:\windows\system32\dllcache\agt040d.dll
2008-11-30 19:18 . 2003-07-16 13:23 19,456 --a--c--- c:\windows\system32\dllcache\agt0404.dll
2008-11-30 19:18 . 2003-07-16 13:23 19,456 --a--c--- c:\windows\system32\dllcache\agt0401.dll
2008-11-30 19:18 . 2001-08-17 22:36 5,632 --a--c--- c:\windows\system32\dllcache\EXCH_adsiisex.dll
2008-11-30 19:06 . 2008-11-30 19:06 749 -rah----- c:\windows\WindowsShell.Manifest
2008-11-30 19:06 . 2008-11-30 19:06 749 -rah----- c:\windows\system32\wuaucpl.cpl.manifest
2008-11-30 19:06 . 2008-11-30 19:06 749 -rah----- c:\windows\system32\sapi.cpl.manifest
2008-11-30 19:06 . 2008-11-30 19:06 749 -rah----- c:\windows\system32\ncpa.cpl.manifest
2008-11-30 19:06 . 2008-11-30 19:06 488 -rah----- c:\windows\system32\logonui.exe.manifest
2008-11-30 19:03 . 2004-08-04 00:56 949,248 --a------ c:\windows\system32\msdtctm.dll
2008-11-30 19:02 . 2004-08-04 00:56 1,251,840 --a------ c:\windows\system32\comsvcs.dll
2008-11-30 18:26 . 2003-07-16 13:39 1,086,182 -ra------ c:\windows\SETE8.tmp
2008-11-30 18:26 . 2003-07-16 13:30 13,608 -ra------ c:\windows\SETF4.tmp
2008-11-30 18:26 . 2003-07-16 13:54 7,046 -ra------ c:\windows\SET106.tmp
2008-11-30 16:35 . 2004-08-03 23:07 6,400 --a------ c:\windows\system32\drivers\splitter.sys
2008-11-30 16:34 . 2004-08-03 22:59 57,472 --a------ c:\windows\system32\drivers\redbook.sys
2008-11-30 16:34 . 2004-08-03 23:07 52,864 --a------ c:\windows\system32\drivers\dmusic.sys
2008-11-30 16:32 . 2004-08-04 00:56 130,048 --a------ c:\windows\system32\ksproxy.ax
2008-11-30 16:32 . 2004-08-04 00:56 4,096 --a------ c:\windows\system32\ksuser.dll
2008-11-30 16:31 . 2004-08-04 01:01 40,840 --a------ c:\windows\system32\drivers\termdd.sys
2008-11-30 16:26 . 2008-11-30 16:26 <DIR> d---s---- c:\windows\system32\config\systemprofile\History
2008-11-22 18:22 . 2008-11-22 18:22 <DIR> d-------- c:\program files\Western Digital
2008-11-22 18:21 . 2008-11-22 18:21 <DIR> d-------- c:\program files\Common Files\eSellerate
2008-11-22 18:19 . 2008-12-02 20:19 <DIR> d---s---- c:\documents and settings\All Users\Application Data\Memeo
2008-11-22 18:15 . 2008-11-22 18:15 <DIR> d-------- c:\program files\Western Digital Technologies
2008-11-17 17:04 . 2008-11-17 17:04 <DIR> d-------- c:\documents and settings\Melissa\Application Data\MalwareRemovalBot
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-09 05:22 --------- d-----w c:\program files\Java
2008-12-03 05:46 --------- d-----w c:\documents and settings\All Users\Application Data\avg8
2008-12-02 00:54 --------- d-----w c:\program files\Common Files\Symantec Shared
2008-11-23 01:22 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-17 23:07 2,002 ----a-w c:\windows\Sysvxd.exe
2008-11-15 22:34 --------- d-----w c:\program files\Windows Live Safety Center
2008-11-11 22:59 --------- d-----w c:\documents and settings\Melissa\Application Data\NLOP
.
------- Sigcheck -------
2004-08-03 23:00 29056 4448006b6bc60e6c027932cfc38d6855 c:\windows\ServicePackFiles\i386\ip6fw.sys
2004-08-03 23:00 29056 4448006b6bc60e6c027932cfc38d6855 c:\windows\SoftwareDistribution\Download\6ca7b3a8efd5a9b6f87fff395a2eb989\ip6fw.sys
2008-04-13 11:53 36608 3bb22519a194418d5fec05d800a19ad0 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\ip6fw.sys
2008-04-13 11:53 36608 3bb22519a194418d5fec05d800a19ad0 c:\windows\system32\drivers\ip6fw.sys
.
((((((((((((((((((((((((((((( snapshot@2008-12-14_23.31.45.98 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-12-16 04:48:26 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_56c.dat
+ 2008-12-16 04:48:44 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_6f8.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 1404928]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-02-10 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-02-10 118784]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-18 81000]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-08 136600]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-07-23 15:28 352256 c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\services.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-12-02 110160]
R1 SASDIFSV;SASDIFSV;\??\c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2008-11-17 8944]
R1 SASKUTIL;SASKUTIL;\??\c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2008-11-17 55024]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-12-02 20560]
S3 SASENUM;SASENUM;\??\c:\program files\SUPERAntiSpyware\SASENUM.SYS [2008-11-17 7408]
.
Contents of the 'Scheduled Tasks' folder
2008-12-15 c:\windows\Tasks\At3.job
- c:\windows\system32\f0Rb45Pe.exe []
2008-12-15 c:\windows\Tasks\At4.job
- c:\windows\system32\f0Rb45Pe.exe []
2008-12-15 c:\windows\Tasks\At5.job
- c:\windows\system32\f0Rb45Pe.exe []
2008-12-15 c:\windows\Tasks\At6.job
- c:\windows\system32\f0Rb45Pe.exe []
2008-12-15 c:\windows\Tasks\At7.job
- c:\windows\system32\f0Rb45Pe.exe []
2008-12-16 c:\windows\Tasks\XoftSpySE 2.job
- c:\program files\XoftSpySE\XoftSpy.exe []
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com
uInternet Connection Wizard,ShellNext = hxxp://products.webroot.com/disp0201.php?pc=64002&rc=3029&oc=11&ps=T&mjv=3&mnv=5&bld=198&sid=&lang=en
FF - ProfilePath - c:\documents and settings\Melissa\Application Data\Mozilla\Firefox\Profiles\c95nf8gi.default\
FF - prefs.js: browser.startup.homepage - hxxp://go.microsoft.com/fwlink/?LinkId=69157
FF - plugin: c:\program files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeploytk.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npjp2.dll
FF - plugin: c:\program files\Microsoft Silverlight\2.0.30523.8\npctrl.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeploytk.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-12-15 21:48:38
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(616)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Cisco Systems\VPN Client\cvpnd.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
.
**************************************************************************
.
Completion time: 2008-12-15 21:53:24 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-16 04:53:20
ComboFix2.txt 2008-12-15 06:32:40
Pre-Run: 57,830,338,560 bytes free
Post-Run: 57,821,102,080 bytes free
323 --- E O F --- 2008-10-27 02:53:48