Here is combofix:
ComboFix 08-03-14.4 - Dad 2008-03-17 17:18:11.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1503 [GMT -5:00]
Running from: C:\Documents and Settings\Dad\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Dad\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!FILE ::
C:\Documents and Settings\Dad\My Documents\Dad's\Katana\agreement.hta
C:\Documents and Settings\Dad\My Documents\Dad's\Katana\bill_of_sale.hta
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Dad\My Documents\Dad's\Katana\agreement.hta
C:\Documents and Settings\Dad\My Documents\Dad's\Katana\bill_of_sale.hta
.
((((((((((((((((((((((((( Files Created from 2008-02-17 to 2008-03-17 )))))))))))))))))))))))))))))))
.
2008-03-17 08:06 . 2008-03-17 08:06 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-03-17 08:06 . 2008-03-17 08:06 <DIR> d-------- C:\Documents and Settings\Dad\Application Data\Malwarebytes
2008-03-17 08:06 . 2008-03-17 08:06 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-03-16 19:03 . 2008-03-16 19:03 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-03-16 19:03 . 2008-03-16 19:03 <DIR> d-------- C:\WINDOWS\LastGood
2008-03-16 19:03 . 2008-03-16 19:03 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-03-15 22:49 . 2008-03-15 22:49 <DIR> d-------- C:\Program Files\Alwil Software
2008-03-15 22:49 . 2007-12-04 07:04 837,496 --a------ C:\WINDOWS\system32\aswBoot.exe
2008-03-15 22:49 . 2004-01-09 03:13 380,928 --a------ C:\WINDOWS\system32\actskin4.ocx
2008-03-15 22:49 . 2007-12-04 06:54 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr
2008-03-15 22:49 . 2007-12-04 08:55 94,544 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2008-03-15 22:49 . 2007-12-04 08:56 93,264 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2008-03-15 22:49 . 2007-12-04 08:51 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2008-03-15 22:49 . 2007-12-04 08:49 26,624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2008-03-15 22:49 . 2007-12-04 08:53 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2008-03-15 22:19 . 2008-03-15 22:20 317 --a------ C:\Documents and Settings\Dad\.exe
2008-03-15 21:11 . 2008-03-15 21:11 <DIR> d-------- C:\Deckard
2008-03-14 16:46 . 2008-03-14 16:46 <DIR> d-------- C:\Documents and Settings\Dad\Application Data\Nova Development
2008-03-12 19:55 . 2008-03-12 19:55 <DIR> d-------- C:\Program Files\Trend Micro
2008-03-11 11:41 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-03-11 11:41 . 2007-07-30 19:19 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-03-10 17:41 . 2008-03-10 17:41 <DIR> d-------- C:\Documents and Settings\Logan\Application Data\Grisoft
2008-03-10 17:39 . 2008-03-10 17:39 <DIR> d-------- C:\Documents and Settings\Jeremy\Application Data\Grisoft
2008-03-10 17:37 . 2008-03-10 17:37 <DIR> d-------- C:\Documents and Settings\Adam\Application Data\Grisoft
2008-03-10 17:35 . 2008-03-10 17:35 <DIR> d-------- C:\Documents and Settings\Kristen\Application Data\Grisoft
2008-03-10 17:29 . 2008-03-10 17:29 <DIR> d-------- C:\Documents and Settings\Mom & Dad\Application Data\Grisoft
2008-03-10 17:15 . 2008-03-10 17:15 <DIR> d-------- C:\Program Files\Windows Installer Clean Up
2008-03-10 17:14 . 2008-03-10 17:14 <DIR> d-------- C:\Program Files\MSECACHE
2008-03-10 15:59 . 2008-03-10 15:59 <DIR> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-03-10 02:29 . 2007-06-05 10:56 44,928 --a------ C:\WINDOWS\system32\drivers\SDTHOOK.SYS
2008-03-10 02:15 . 2008-03-16 08:48 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2008-03-10 02:15 . 2008-03-10 02:15 30,590 --a------ C:\WINDOWS\system32\pavas.ico
2008-03-10 02:15 . 2008-03-10 02:15 2,550 --a------ C:\WINDOWS\system32\Uninstall.ico
2008-03-10 02:15 . 2008-03-10 02:15 1,406 --a------ C:\WINDOWS\system32\Help.ico
2008-03-09 18:22 . 2008-03-12 19:36 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-03-09 18:22 . 2008-03-09 18:22 <DIR> d-------- C:\Documents and Settings\Dad\Application Data\SUPERAntiSpyware.com
2008-03-09 18:22 . 2008-03-09 18:22 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-03-09 18:21 . 2008-03-09 18:21 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-03-09 16:31 . 2008-03-09 16:31 <DIR> d-------- C:\Documents and Settings\Dad\Application Data\Grisoft
2008-03-09 16:30 . 2008-03-09 16:30 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-03-09 16:30 . 2007-05-30 07:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-02-21 01:40 . 2008-02-21 01:43 <DIR> d-------- C:\Program Files\Windows Live Safety Center
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-17 16:42 --------- d-----w C:\Documents and Settings\Adam\Application Data\AOL
2008-03-16 03:20 317 ----a-w C:\Documents and Settings\Dad\.exe
2008-03-10 08:31 --------- d-----w C:\Program Files\QuickTime
2008-03-10 08:25 --------- d-----w C:\Program Files\Digital Line Detect
2008-03-10 08:21 --------- d-----w C:\Program Files\Common Files\aolshare
2008-03-10 08:20 --------- d-----w C:\Program Files\BAE
2008-03-10 08:20 --------- d-----w C:\Program Files\AOL 9.0
2008-03-10 08:20 --------- d-----w C:\Program Files\America Online 9.0
2008-03-09 23:19 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-06 22:35 --------- d-----w C:\Program Files\Spyware Doctor
2008-03-03 23:36 --------- d-----w C:\Documents and Settings\Kristen\Application Data\LimeWire
2008-02-28 23:17 83,584 -c--a-w C:\Documents and Settings\Mom & Dad\Application Data\GDIPFONTCACHEV1.DAT
2008-02-25 23:19 --------- d-----w C:\Program Files\LimeWire
2008-02-25 22:53 --------- d-----w C:\Documents and Settings\Mom & Dad\Application Data\LimeWire
2008-02-21 16:48 --------- d-----w C:\Program Files\McAfee
2008-02-21 16:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee
2008-01-31 01:37 --------- d-----w C:\Program Files\DIGStream
2008-01-30 22:02 --------- d-----w C:\Program Files\XoftSpySE
2008-01-30 21:56 --------- d-----w C:\Program Files\Viewpoint
2008-01-30 21:56 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-01-24 22:55 --------- d-----w C:\Program Files\Guitar Pro 5
2008-01-21 13:43 --------- d-----w C:\Documents and Settings\Jeremy\Application Data\CyberLink
2008-01-11 05:53 44,544 ----a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
2007-12-19 23:01 347,136 ----a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll
2007-12-18 09:51 179,584 ------w C:\WINDOWS\system32\dllcache\mrxdav.sys
2007-09-10 15:15 72,336 -c--a-w C:\Documents and Settings\Kristen\Application Data\GDIPFONTCACHEV1.DAT
2007-09-05 23:46 72,336 -c----w C:\Documents and Settings\Adam\Application Data\GDIPFONTCACHEV1.DAT
2007-02-26 22:09 71,400 -c--a-w C:\Documents and Settings\Logan\Application Data\GDIPFONTCACHEV1.DAT
2006-10-06 18:27 71,400 -c--a-w C:\Documents and Settings\Jeremy\Application Data\GDIPFONTCACHEV1.DAT
2007-01-07 19:17 88 -csh--r C:\WINDOWS\system32\E546349AF4.sys
2007-04-23 21:00 4,184 -csha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((( snapshot@2008-03-15_21.47.06.26 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-05-24 17:27:16 213,048 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 20:47:20 94,208 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 20:49:54 950,272 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
+ 2008-03-16 23:58:07 16,384 ----atw C:\WINDOWS\TEMP\Perflib_Perfdata_5b0.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24 1694208]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 05:00 15360]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-03-12 19:36 1481968]
"AOL Fast Start"="C:\Program Files\AOL 9.0\AOL.exe" [2007-04-18 01:49 50736]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-10-14 20:49 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-10-14 20:46 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-10-14 20:50 114688]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-09-08 05:20 122940]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd.exe" [2003-06-25 11:24 49152]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2003-06-26 18:50 212992]
"iTunesHelper"="C:\Documents and Settings\Kristen\My Documents\iTunesHelper.exe" [2005-12-20 21:54 278528]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 03:12 94208]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-09-29 14:01 67584]
"HostManager"="C:\Program Files\Common Files\AOL\1154635686\ee\AOLSoftware.exe" [2007-05-25 12:16 42032]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"EverioService"="C:\Program Files\CyberLink\PCM4Everio\EverioService.exe" [2006-11-22 22:10 151552]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-12-28 20:39 155648]
"MMTray"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [2006-09-18 14:46 110592]
"MimBoot"="C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe" [2006-09-18 14:46 8192]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 04:25 6731312]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 07:00 79224]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [ ]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-07-31 07:17:13 24576]
Event Reminder.lnk - C:\Program Files\PrintMaster 16\pmremind.exe [2004-01-20 12:10:38 339968]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2003-07-07 01:20:40 233472]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL 2008-03-12 19:36 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"McShield"=2 (0x2)
"aolavupd"=2 (0x2)
"MpfService"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe"=
"C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Documents and Settings\\Kristen\\My Documents\\iTunes.exe"=
"C:\\Program Files\\Common Files\\AOL\\1154635686\\ee\\aolsoftware.exe"=
"C:\\Program Files\\CyberLink\\PCM4Everio\\PCM4Everio.exe"=
"C:\\Program Files\\CyberLink\\PCM4Everio\\EverioService.exe"=
"C:\\Program Files\\AOL 9.0\\waol.exe"=
S3 msloop;Microsoft Loopback Adapter Driver;C:\WINDOWS\system32\DRIVERS\loop.sys [2001-08-17 13:53]
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-03-17 17:19:43
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-03-17 17:20:18
ComboFix-quarantined-files.txt 2008-03-17 22:20:16
ComboFix2.txt 2008-03-16 03:23:10
ComboFix3.txt 2008-03-16 02:47:35
.
2008-03-13 00:34:53 --- E O F ---