I've been using notepad every time, but this time it finally worked! Here is the log:
ComboFix 07-11-30.7 - rollin 2007-11-30 15:55:07.10 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.171 [GMT -6:00]
Running from: C:\Documents and Settings\rollin\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\rollin\Desktop\CFScript.txt
* Created a new restore point
FILE
C:\WINDOWS\SYSTEM32\btyhvdet.ini
C:\WINDOWS\SYSTEM32\kccvrstq.ini
C:\WINDOWS\SYSTEM32\kmoqquov.ini
C:\WINDOWS\SYSTEM32\ljrnfywl.ini
C:\WINDOWS\SYSTEM32\mcrh.tmp
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\SYSTEM32\btyhvdet.ini
C:\WINDOWS\SYSTEM32\kccvrstq.ini
C:\WINDOWS\SYSTEM32\kmoqquov.ini
C:\WINDOWS\SYSTEM32\ljrnfywl.ini
C:\WINDOWS\SYSTEM32\mcrh.tmp
.
((((((((((((((((((((((((( Files Created from 2007-10-28 to 2007-11-30 )))))))))))))))))))))))))))))))
.
2007-11-27 16:49 . 2007-11-27 16:49 885 --a------ C:\backup.reg
2007-11-27 16:45 . 2007-11-27 16:45 126,976 --a------ C:\zip.exe
2007-11-27 16:45 . 2007-11-27 16:45 845 --a------ C:\avexport.bat
2007-11-26 14:52 . 2007-11-26 14:52 <DIR> d-------- C:\WINDOWS\SYSTEM32\Kaspersky Lab
2007-11-26 14:52 . 2007-11-26 14:52 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-11-21 14:54 . 2007-09-24 23:31 69,632 --a------ C:\WINDOWS\SYSTEM32\javacpl.cpl
2007-11-21 14:53 . 2007-11-21 14:54 <DIR> d-------- C:\Program Files\Java
2007-11-21 14:49 . 2007-11-21 14:49 <DIR> d-------- C:\Program Files\Common Files\Java
2007-11-21 14:46 . 2007-11-21 14:46 0 --a------ C:\WINDOWS\mozver.dat
2007-11-21 09:44 . 2007-11-26 19:10 <DIR> d-------- C:\VundoFix Backups
2007-11-20 07:40 . 2007-11-20 16:10 <DIR> d-------- C:\Program Files\EsetOnlineScanner
2007-11-18 11:54 . 2007-11-18 11:54 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-11-18 11:53 . 2007-11-19 08:03 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2007-11-18 11:53 . 2007-11-18 11:53 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-11-18 11:53 . 2007-11-18 11:53 <DIR> d-------- C:\Documents and Settings\rollin\Application Data\SUPERAntiSpyware.com
2007-11-16 10:36 . 2007-11-17 11:50 401 --a------ C:\WINDOWS\wininit.ini
2007-11-16 10:21 . 2007-11-16 10:21 0 --a------ C:\WINDOWS\nsreg.dat
2007-11-06 08:38 . 2006-06-06 14:20 241,721 --a------ C:\WINDOWS\SYSTEM32\HPBMINI.DLL
2007-11-06 08:38 . 2007-02-13 20:23 103,424 --a------ C:\WINDOWS\SYSTEM32\hpzpnp.dll
2007-11-06 08:38 . 2004-10-16 05:31 61,440 --a------ C:\WINDOWS\SYSTEM32\HPNRA.EXE
2007-11-06 08:38 . 2006-05-11 18:15 52,736 --a------ C:\WINDOWS\SYSTEM32\HPZIPM12.DLL
2007-11-06 08:38 . 2006-05-11 18:15 43,520 --a------ C:\WINDOWS\SYSTEM32\HPZINW12.DLL
2007-11-06 08:38 . 2006-11-16 19:16 38,912 --a------ C:\WINDOWS\SYSTEM32\HPBPRO.DLL
2007-11-06 08:38 . 2006-11-16 19:15 25,600 --a------ C:\WINDOWS\SYSTEM32\HPBOID.DLL
2007-11-06 08:38 . 2006-11-02 19:32 18,747 --a------ C:\WINDOWS\SYSTEM32\hpceac06.hpi
2007-11-06 08:37 . 2007-11-06 08:37 <DIR> d-------- C:\HP LJ4x50 Series
2007-10-12 08:48 . 2007-10-12 08:48 37 --a------ C:\WINDOWS\PVX.INI
2007-10-10 07:21 . 2007-07-09 07:16 582,656 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\rpcrt4.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-30 14:13 --------- d-----w C:\Program Files\Symantec AntiVirus
2007-11-16 17:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-10-29 14:04 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-10-29 13:50 --------- d-----w C:\Program Files\FedEx
2007-10-26 03:34 8,460,288 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\shell32.dll
2007-08-21 17:44 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE
2007-08-21 17:44 249,856 ------w C:\WINDOWS\Setup1.exe
2007-08-21 16:20 60,968 ----a-w C:\Documents and Settings\rollin\GoToAssistDownloadHelper.exe
2007-08-21 06:15 683,520 ----a-w C:\WINDOWS\SYSTEM32\inetcomm.dll
2007-08-21 06:15 683,520 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\inetcomm.dll
2007-08-20 10:04 824,832 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wininet.dll
2007-08-20 10:04 671,232 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\mstime.dll
2007-08-20 10:04 63,488 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\icardie.dll
2007-08-20 10:04 6,058,496 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\ieframe.dll
2007-08-20 10:04 52,224 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\msfeedsbs.dll
2007-08-20 10:04 477,696 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\mshtmled.dll
2007-08-20 10:04 459,264 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\msfeeds.dll
2007-08-20 10:04 44,544 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\iernonce.dll
2007-08-20 10:04 384,512 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\iedkcs32.dll
2007-08-20 10:04 383,488 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\ieapfltr.dll
2007-08-20 10:04 3,584,512 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\mshtml.dll
2007-08-20 10:04 27,648 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\jsproxy.dll
2007-08-20 10:04 267,776 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\iertutil.dll
2007-08-20 10:04 232,960 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\webcheck.dll
2007-08-20 10:04 230,400 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\ieaksie.dll
2007-08-20 10:04 214,528 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\dxtrans.dll
2007-08-20 10:04 193,024 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\msrating.dll
2007-08-20 10:04 153,088 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\ieakeng.dll
2007-08-20 10:04 132,608 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\extmgr.dll
2007-08-20 10:04 124,928 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\advpack.dll
2007-08-20 10:04 105,984 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\url.dll
2007-08-20 10:04 102,400 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\occache.dll
2007-08-20 10:04 1,152,000 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\urlmon.dll
2007-08-17 10:21 625,152 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\iexplore.exe
2007-08-17 10:20 63,488 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\ie4uinit.exe
2007-08-17 10:20 13,824 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\ieudinit.exe
2007-08-17 07:34 161,792 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\ieakui.dll
2007-08-08 22:30 19,456 ----a-w C:\WINDOWS\SYSTEM32\OnlineScannerLang.dll
2007-08-03 00:11 253,952 ----a-w C:\WINDOWS\SYSTEM32\OnlineScannerDLLA.dll
2007-08-03 00:11 241,664 ----a-w C:\WINDOWS\SYSTEM32\OnlineScannerDLLW.dll
2007-06-07 17:49 2 ----a-w C:\Documents and Settings\administrator.GO4B\WSSEMAPHORES.dat
.
((((((((((((((((((((((((((((( snapshot@2007-11-19_ 7.52.31.10 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-11-08 22:59:01 136,704 ----a-w C:\WINDOWS\catchme.exe
+ 2007-11-27 09:58:11 140,288 ----a-w C:\WINDOWS\catchme.exe
- 2004-01-16 13:42:47 24,670 ----a-w C:\WINDOWS\SYSTEM32\java.exe
+ 2007-09-25 04:30:28 135,168 ----a-w C:\WINDOWS\SYSTEM32\java.exe
- 2004-01-16 13:42:47 28,768 ----a-w C:\WINDOWS\SYSTEM32\javaw.exe
+ 2007-09-25 04:30:30 135,168 ----a-w C:\WINDOWS\SYSTEM32\javaw.exe
+ 2007-09-25 05:31:42 139,264 ----a-w C:\WINDOWS\SYSTEM32\javaws.exe
+ 2005-05-24 18:27:16 213,048 ----a-w C:\WINDOWS\SYSTEM32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 21:47:20 94,208 ----a-w C:\WINDOWS\SYSTEM32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 21:49:54 950,272 ----a-w C:\WINDOWS\SYSTEM32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
+ 2007-07-27 21:49:02 196,683 ----a-w C:\WINDOWS\SYSTEM32\lnod32apiA.dll
+ 2007-07-27 21:49:02 225,355 ----a-w C:\WINDOWS\SYSTEM32\lnod32apiW.dll
+ 2005-12-06 02:25:22 139,264 ----a-w C:\WINDOWS\SYSTEM32\lnod32umc.dll
+ 2005-12-05 19:37:10 106,496 ----a-w C:\WINDOWS\SYSTEM32\lnod32upd.dll
+ 2007-06-11 20:34:34 2,115,816 ----a-w C:\WINDOWS\SYSTEM32\Macromed\Flash\NPSWF32.dll
+ 2007-06-11 20:34:40 190,696 ----a-w C:\WINDOWS\SYSTEM32\Macromed\Flash\NPSWF32_FlashUtil.exe
+ 2007-11-20 15:37:24 45,218 ----a-w C:\WINDOWS\SYSTEM32\Macromed\Flash\uninstall_plugin.exe
+ 2007-06-13 17:10:34 77,824 ----a-w C:\WINDOWS\SYSTEM32\OnlineScannerUninstaller.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 10:24]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:56]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AdaptecDirectCD"="C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-12-17 12:28]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2004-09-15 14:22]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2005-06-02 08:21]
"vptray"="C:\PROGRA~1\SYMANT~2\VPTray.exe" [2005-06-23 18:27]
"StatusClient"="C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe" [2002-12-16 16:51]
"TomcatStartup"="C:\Program Files\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe" [2003-03-31 19:28]
"OrderReminder"="C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder\OrderReminder.exe" [2006-01-20 10:46]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-09-20 08:35]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-09-20 08:32]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-09-20 08:36]
"Synchronization Manager"="C:\WINDOWS\system32\mobsync.exe" [2004-08-04 01:56]
"NA1Messenger"="C:\UPS\WSTD\PolicyMgr\NA1Msgr.exe" [2007-03-23 22:24]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe [2007-01-24 09:57:12]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 09:05:56]
UPS WorldShip Messaging Utility.lnk - C:\UPS\WSTD\Messages\WSTDMessaging.exe [2007-02-07 02:33:26]
UPS WorldShip PLD Reminder Utility.lnk - C:\UPS\WSTD\wstdPldReminder.exe [2007-02-07 01:27:28]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
R2 ASFAgent;ASF Agent;C:\Program Files\Intel\ASF Agent\ASFAgent.exe
R2 AsfAlrt;AsfAlrt;\??\C:\WINDOWS\System32\drivers\AsfAlrt.sys
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 Pml Driver HPZ12 Net Driver HPZ12
.
**************************************************************************
catchme 0.3.1318 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-11-30 15:59:26
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
Completion time: 2007-11-30 16:00:31
C:\ComboFix2.txt ... 2007-11-30 08:25
C:\ComboFix3.txt ... 2007-11-19 07:59
.
--- E O F ---