I forgot to mention that I ran ComboFix since the symptoms were similar to the previous case and ComboFix did not delete any files. Here is the log:
ComboFix 08-02-22 - Administrator 2008-02-21 16:45:43.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1510 [GMT -8:00]
Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-01-22 to 2008-02-22 )))))))))))))))))))))))))))))))
.
2008-02-20 04:41 . 2008-02-20 04:41 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\AVSMedia
2008-02-20 04:40 . 2008-02-20 04:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\AVS4YOU
2008-02-20 04:37 . 2008-02-20 05:01 <DIR> d-------- C:\Program Files\Common Files\AVSMedia
2008-02-20 04:36 . 2007-02-27 19:36 524,288 --a------ C:\WINDOWS\system32\xvidcore.dll
2008-02-20 04:36 . 2007-02-27 19:36 413,760 --a------ C:\WINDOWS\system32\mpg4c32.dll
2008-02-20 04:36 . 2007-02-27 19:36 261,632 --a------ C:\WINDOWS\system32\mcdvd_32.dll
2008-02-20 04:36 . 2007-02-27 19:36 156,910 --a------ C:\WINDOWS\WMSysPr8.prx
2008-02-20 04:36 . 2007-02-27 19:36 139,264 --a------ C:\WINDOWS\system32\xvidvfw.dll
2008-02-20 04:36 . 2007-02-27 19:36 82,944 --a------ C:\WINDOWS\system32\vct3216.acm
2008-02-20 04:36 . 2007-02-27 19:36 81,920 --a------ C:\WINDOWS\system32\AC3ACM.acm
2008-02-20 04:36 . 2007-02-27 19:36 53,248 --a------ C:\WINDOWS\system32\xvid.ax
2008-02-20 04:36 . 2007-02-27 19:36 38,912 --a------ C:\WINDOWS\system32\alf2cd.acm
2008-02-20 04:36 . 2007-02-27 19:36 24,576 --a------ C:\WINDOWS\system32\msxml3a.dll
2008-02-20 04:36 . 2007-02-27 19:36 13,239 --a------ C:\WINDOWS\system32\Scg726.acm
2008-02-19 18:04 . 2008-02-19 18:04 <DIR> d-------- C:\Program Files\Windows Media Components
2008-02-18 18:09 . 2008-02-19 03:09 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-02-18 18:09 . 2008-02-18 18:09 1,409 --a------ C:\WINDOWS\QTFont.for
2008-02-18 17:15 . 2008-02-18 17:15 <DIR> d-------- C:\Documents and Settings\Administrator\.DownloadManager
2008-02-18 04:31 . 2008-02-21 14:57 <DIR> d-------- C:\Program Files\Solveig Multimedia
2008-02-11 15:30 . 2008-02-11 15:30 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-02-11 15:26 . 2008-02-12 03:14 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-02-11 15:26 . 2008-02-11 15:26 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com
2008-02-10 02:11 . 2008-02-10 02:26 691,545 --a------ C:\WINDOWS\unins000.exe
2008-02-10 02:11 . 2008-02-10 02:27 6,456 --a------ C:\WINDOWS\unins000.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2008-02-22 00:49 66,490,400 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-02-22 00:48 3,064,864 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-02-22 00:48 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Free Download Manager
2008-02-22 00:45 --------- d-----w C:\Program Files\GetRight
2008-02-22 00:14 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Skype
2008-02-22 00:05 --------- d-----w C:\Documents and Settings\Administrator\Application Data\skypePM
2008-02-21 13:50 897,920 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-02-21 13:50 291,056 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-02-21 11:59 --------- d-----w C:\WINDOWS\system32\config\systemprofile\Applicati on Data\SolidDocuments
2008-02-20 20:00 61,596 ----a-w C:\WINDOWS\Internet Logs\vsmon_2nd_2008_02_20_02_34_51_small.dmp.zip
2008-02-20 11:34 --------- d-----w C:\Program Files\Common Files\Adobe
2008-02-20 10:59 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-20 10:58 --------- d-----w C:\Program Files\Ulead Systems
2008-02-20 10:58 --------- d-----w C:\Documents and Settings\All Users\Application Data\Ulead Systems
2008-02-20 10:54 --------- d-----w C:\Program Files\Common Files\Ulead Systems
2008-02-20 10:22 6,078,976 ----a-w C:\WINDOWS\Internet Logs\xDBB6.tmp
2008-02-20 10:22 3,945,984 ----a-w C:\WINDOWS\Internet Logs\xDBB5.tmp
2008-02-20 00:14 512 ----a-w C:\ScanSectorLog.dat
2008-02-19 22:31 --------- d-----w C:\Documents and Settings\Administrator\Application Data\SolidDocuments
2008-02-19 11:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-02-15 14:00 3,181,568 ----a-w C:\WINDOWS\Internet Logs\xDB10.tmp
2008-02-14 10:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-14 10:44 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2008-02-11 23:26 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-02-10 23:28 5,826,560 ----a-w C:\WINDOWS\Internet Logs\xDBF.tmp
2008-02-10 23:16 5,826,048 ----a-w C:\WINDOWS\Internet Logs\xDBE.tmp
2008-02-10 23:16 2,685,952 ----a-w C:\WINDOWS\Internet Logs\xDBD.tmp
2008-02-10 10:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-10 10:40 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-02-10 10:15 4,922,368 ----a-w C:\WINDOWS\Internet Logs\xDB1F.tmp
2008-02-10 03:56 5,807,104 ----a-w C:\WINDOWS\Internet Logs\xDBC.tmp
2008-01-28 10:31 5,783,552 ----a-w C:\WINDOWS\Internet Logs\xDBB.tmp
2008-01-26 03:45 14,219,376 ----a-w C:\WINDOWS\Internet Logs\tvDebug.zip
2008-01-24 23:53 5,778,432 ----a-w C:\WINDOWS\Internet Logs\xDBA.tmp
2008-01-24 23:44 3,806,720 ----a-w C:\WINDOWS\Internet Logs\xDB69.tmp
2008-01-20 11:43 --------- d-----w C:\Program Files\Winamp
2008-01-12 12:13 3,844,096 ----a-w C:\WINDOWS\Internet Logs\xDB9.tmp
2008-01-06 01:46 4,835,840 ----a-w C:\WINDOWS\Internet Logs\xDB63.tmp
2007-12-31 02:52 --------- d-----w C:\Program Files\Bonjour
2007-12-31 02:29 --------- d-----w C:\Program Files\Common Files\Macrovision Shared
2007-12-14 09:06 3,815,936 ----a-w C:\WINDOWS\Internet Logs\xDB2E.tmp
2007-11-22 10:56 62,344 ----a-w C:\Documents and Settings\Administrator\Application Data\GDIPFONTCACHEV1.DAT
2007-11-22 00:14 3,887,104 ----a-w C:\WINDOWS\Internet Logs\xDBF7.tmp
2007-11-19 20:00 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
2007-10-05 07:10 2,833,408 ----a-w C:\WINDOWS\Internet Logs\xDB9E.tmp
2007-08-03 09:44 2,696,192 ----a-w C:\WINDOWS\Internet Logs\xDB8.tmp
2007-07-07 23:00 5,095,424 ----a-w C:\WINDOWS\Internet Logs\xDB7.tmp
2007-06-03 05:38 315,904 ----a-w C:\WINDOWS\Internet Logs\xDBBE.tmp
2007-05-27 10:07 109,568 ----a-w C:\WINDOWS\Internet Logs\xDB4.tmp
2007-05-26 03:14 324,096 ----a-w C:\WINDOWS\Internet Logs\xDB5.tmp
2007-05-26 02:19 4,868,608 ----a-w C:\WINDOWS\Internet Logs\xDB6.tmp
2007-05-21 03:36 18,181,860 ----a-w C:\WINDOWS\Internet Logs\vsmon_on_demand_2007_05_19_22_36_34_full.dmp. zip
2007-05-20 05:36 1,849,856 ----a-w C:\WINDOWS\Internet Logs\xDB81.tmp
2007-04-06 21:48 18,101,484 ----a-w C:\WINDOWS\Internet Logs\vsmon_on_demand_2007_04_06_01_25_39_full.dmp. zip
2007-04-06 08:25 1,059,840 ----a-w C:\WINDOWS\Internet Logs\xDBAC.tmp
2007-03-22 21:13 18,054,361 ----a-w C:\WINDOWS\Internet Logs\vsmon_on_demand_2007_03_22_03_27_31_full.dmp. zip
2007-03-22 10:27 3,132,928 ----a-w C:\WINDOWS\Internet Logs\xDBE2.tmp
2007-03-22 10:25 4,648,960 ----a-w C:\WINDOWS\Internet Logs\xDBE3.tmp
2006-08-23 01:03 2,694,656 ----a-w C:\WINDOWS\Internet Logs\xDB3.tmp
2006-06-24 00:29 2,036,736 ----a-w C:\WINDOWS\Internet Logs\xDB2.tmp
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 08:24 1694208]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe" [2006-11-16 19:04 139264]
"Second Copy"="C:\Program Files\SecCopy\SecCopy.exe" [2006-01-09 12:45 915456]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56 15360]
"Free Download Manager"="C:\Program Files\Free Download Manager\fdm.exe" [2006-04-29 09:22 1990703]
"ÆÇµµ¶óTV¹Ì´Ï"="C:\Program Files\PandoraTVMini\MiniUpdate.exe" [ ]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2007-11-12 15:48 21760296]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 19:05 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"SMSERIAL"="sm56hlpr.exe" [2005-06-06 01:40 544768 C:\WINDOWS\sm56hlpr.exe]
"SoundMAXPnP"="C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" [2003-05-29 15:28 790528]
"SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" [2003-05-30 08:42 585728]
"PRONoMgr.exe"="C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe" [2003-03-11 15:24 86016]
"NWEReboot"="" []
"Ptipbmf"="ptipbmf.dll" [2003-06-19 23:06 118784 C:\WINDOWS\system32\ptipbmf.dll]
"WinFaxAppPortStarter"="wfxsnt40.exe" [2000-02-14 16:36 43008 C:\WINDOWS\system32\WFXSNT40.EXE]
"ScreenPrint32"="C:\Program Files\ScreenPrint32 v3\ScreenPrint32.exe" [2003-05-15 19:36 446464]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-02-23 15:45 278528]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-06-18 11:55 282624]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 03:00 132496]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 15:40 155648]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-03-08 23:02 919280]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1 \DW\dwtrig20.exe" [2005-04-25 12:45 36040]
C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\
HotSync Manager.lnk - C:\Program Files\Palm\HOTSYNC.EXE [2003-03-17 17:50:26 299008]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe [2006-10-31 16:24:24 49254]
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-06-07 16:43:05 113664]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 21:05:26 29696]
Device Detector 3.lnk - C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe [2006-12-19 02:29:07 118784]
GetRight - Tray Icon.lnk - C:\Program Files\GetRight\getright.exe [2007-07-12 00:23:00 2301952]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 00:01:04 83360]
Post-itr Software Notes Lite.lnk - C:\Program Files\3M\PSNLite\PsnLite.exe [2004-10-15 14:26:54 2080768]
[hkey_local_machine\software\microsoft\windows\curr entversion\explorer\shellexecutehooks]
"{A213B520-C6C2-11d0-AF9D-008029E1027E}"= C:\Program Files\Symantec\WinFax\WfxSeh32.Dll [1998-07-27 03:54 38400]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
R1 CloneCD;CloneCD I/O Driver;C:\WINDOWS\system32\drivers\CloneCD.sys [2000-08-25 14:52]
R2 wfxsvc;WinFax PRO;C:\WINDOWS\system32\WFXSVC.EXE [2000-02-14 16:36]
S2 IcRecUsb;IC Recorder Driver;C:\WINDOWS\system32\Drivers\IcRecUsb.sys [2001-10-01 23:37]
S3 ATIPCXXX;ATI Parental control device;C:\WINDOWS\system32\DRIVERS\atipcxxx.sys [2001-08-17 04:49]
S3 ATIVRVXX;ATI Rage Theatre Video (ATIRTCAP);C:\WINDOWS\system32\DRIVERS\atirtcap.sy s [2001-08-17 04:49]
S3 ATIVXSXX;ATI Audio Crossbar (ATIVXBAR);C:\WINDOWS\system32\DRIVERS\ativxbar.sy s [2001-08-17 04:49]
S3 VNUSB;VN Series Device;C:\WINDOWS\system32\DRIVERS\VNUSB.sys [2006-04-07 17:06]
.
************************************************** ************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-02-21 16:49:09
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
.
Completion time: 2008-02-21 16:50:48
ComboFix2.txt 2008-02-13 09:18:40