Here is the output from Combofix. I believe the virus was called 'rootkit', but not totally sure.
I uninstalled Malwarebytes and Superantispyware before running Combofix but looks like there were a few left-over files.
Thanks again.
------------------------------------------------------------------------------------------------
ComboFix 10-09-14.01 - T 09/14/2010 22:49:50.1.1 - x86 MINIMAL
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.494.296 [GMT -7:00]
Running from: E:\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\T\LOCALS~1\Temp\SAS2.tmp
c:\docume~1\T\LOCALS~1\Temp\SAS3.tmp
c:\documents and settings\T\Local Settings\Application Data\{BAC4E0D1-FD81-498D-9BB0-CB07B3EF4D5A}
c:\documents and settings\T\Local Settings\Application Data\{BAC4E0D1-FD81-498D-9BB0-CB07B3EF4D5A}\chrome.manifest
c:\documents and settings\T\Local Settings\Application Data\{BAC4E0D1-FD81-498D-9BB0-CB07B3EF4D5A}\chrome\content\_cfg.js
c:\documents and settings\T\Local Settings\Application Data\{BAC4E0D1-FD81-498D-9BB0-CB07B3EF4D5A}\chrome\content\overlay.xul
c:\documents and settings\T\Local Settings\Application Data\{BAC4E0D1-FD81-498D-9BB0-CB07B3EF4D5A}\install.rdf
c:\documents and settings\T\Local Settings\Application Data\mdwwdwwew
c:\documents and settings\T\Local Settings\Application Data\mdwwdwwew\wbgccamuqiw.exe
c:\documents and settings\T\Local Settings\Temp\SAS2.tmp
c:\documents and settings\T\Local Settings\Temp\SAS3.tmp
c:\windows\eyiyimaxeqayofi.dll
c:\windows\ibd2uELf.dll
c:\windows\ucepiyepeteroq.dll
c:\windows\uzebukaqibiyov.dll
.
((((((((((((((((((((((((( Files Created from 2010-08-15 to 2010-09-15 )))))))))))))))))))))))))))))))
.
2010-09-14 01:57 . 2010-09-14 01:57 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-09-13 03:30 . 2010-09-13 03:30 2838 ----a-w- c:\windows\Vkenogiceyi.dat
2010-09-13 01:38 . 2010-09-13 01:38 -------- d--h--w- c:\windows\system32\WLANProfiles
2010-09-13 01:38 . 2010-09-13 01:38 -------- d-----w- C:\WLANProfiles
2010-09-13 01:38 . 2010-09-13 01:38 -------- d-----w- C:\Settings
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-15 05:25 . 2010-03-02 07:04 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [2005-05-20 1957888]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_05\bin\jusched.exe" [2005-08-27 36975]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-05-14 98304]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-05-14 536576]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-30 385024]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 53248]
"mmtask"="c:\program files\Musicmatch\Musicmatch Jukebox\mmtask.exe" [2004-09-14 53248]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2005-10-18 278528]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-01-07 155648]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-09-20 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-09-20 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-09-20 114688]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2008-04-17 98616]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2005-6-30 24576]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
2004-09-07 21:08 110592 ----a-w- c:\program files\Intel\Wireless\Bin\LgNotify.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Shareaza\\Shareaza.exe"=
"c:\\Program Files\\Kazaa Lite\\Kazaa.kpp"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
S2 SSIPDDP;SSIPDDP;c:\windows\system32\drivers\ssipddp.sys [8/27/2007 10:23 PM 54272]
S4 civu;civu;c:\windows\system32\drivers\cyrlqu.sys --> c:\windows\system32\drivers\cyrlqu.sys [?]
S4 jjkyah;jjkyah;c:\windows\system32\drivers\uuwgh.sys --> c:\windows\system32\drivers\uuwgh.sys [?]
S4 pkxxfx;pkxxfx;c:\windows\system32\drivers\slrnbxx.sys --> c:\windows\system32\drivers\slrnbxx.sys [?]
.
Contents of the 'Scheduled Tasks' folder
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyServer = http=127.0.0.1:6092
uInternet Settings,ProxyOverride = <local>
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office10\EXCEL.EXE/3000
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-PhotoShow Deluxe Media Manager - c:\progra~1\Ahead\Ahead\data\Xtras\mssysmgr.exe
HKCU-Run-TomTomHOME.exe - c:\program files\TomTom HOME 2\TomTomHOMERunner.exe
HKCU-Run-isaasxpy - c:\documents and settings\T\Local Settings\Application Data\mdwwdwwew\wbgccamuqiw.exe
HKCU-Run-Yheduxekuvaya - c:\windows\ibd2uELf.dll
HKLM-Run-ISUSPM Startup - c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
HKLM-Run-isaasxpy - c:\documents and settings\T\Local Settings\Application Data\mdwwdwwew\wbgccamuqiw.exe
HKLM-Run-Imohuga - c:\windows\eyiyimaxeqayofi.dll
HKLM-Run-Malwarebytes Anti-Malware (rootkit-scan) - c:\program files\Malwarebytes' Anti-Malware\mbam.exe
ShellExecuteHooks-{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - (no file)
AddRemove-Nero - Burning Rom!UninstallKey - c:\program files\Ahead\nero\uninstall\UNNERO.exe
AddRemove-Rainbow Sentinel Driver - c:\windows\SYSTEM32\RNBOSENT\SETUPX86.EXE
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-09-14 22:59
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(204)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
c:\program files\Intel\Wireless\Bin\LgNotify.dll
.
Completion time: 2010-09-14 23:04:41
ComboFix-quarantined-files.txt 2010-09-15 06:04
Pre-Run: 8,720,621,568 bytes free
Post-Run: 9,323,302,912 bytes free
- - End Of File - - 015ECBDA51E4D0AE97CDF67427316109