Fresh logs, both run in safe mode. Thanks!
COMBOFIX
ComboFix 07-10-18.6 - Shael Sokolowski 2007-10-18 16:49:29.6 - NTFSx86 MINIMAL
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.821 [GMT -4:00]
Running from: C:\Documents and Settings\Shael Sokolowski\Desktop\ComboFix.exe
.
((((((((((((((((((((((((( Files Created from 2007-09-18 to 2007-10-18 )))))))))))))))))))))))))))))))
.
2007-10-17 10:06 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-10-16 11:06 <DIR> d-------- C:\Program Files\Trend Micro
2007-10-16 11:04 <DIR> d-------- C:\WINDOWS\SYSTEM32\Kaspersky Lab
2007-10-16 11:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-10-15 01:42 386,560 --a------ C:\Documents and Settings\Shael Sokolowski\rBot-ud.exe
2007-10-13 22:17 62,464 --a------ C:\Documents and Settings\Shael Sokolowski\special.exe
2007-10-13 21:08 339,968 --a------ C:\Documents and Settings\Shael Sokolowski\fukj00-ud.exe
2007-10-13 09:29 56,329 --a------ C:\Documents and Settings\Shael Sokolowski\server.exe
2007-10-11 19:07 24,576 --a------ C:\WINDOWS\SYSTEM32\VundoFixSVC.exe
2007-10-11 18:48 154,112 --a------ C:\WINDOWS\SYSTEM32\ali.exe
2007-10-10 23:49 <DIR> d-------- C:\Program Files\Windows Live Safety Center
2007-10-10 22:54 <DIR> d-------- C:\WINDOWS\ERUNT
2007-10-10 01:39 584,192 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\rpcrt4.dll
2007-10-09 22:56 552 --a------ C:\WINDOWS\SYSTEM32\d3d8caps.dat
2007-10-09 11:09 195,096 --a------ C:\WINDOWS\SYSTEM32\lvci1110.dll
2007-10-09 11:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Logishrd
2007-10-03 13:02 401,408 --a------ C:\WINDOWS\SYSTEM32\pvmjpg30.dll
2007-10-03 13:02 44,544 --a------ C:\WINDOWS\SYSTEM32\msxml4a.dll
2007-10-03 12:57 196,096 --a------ C:\WINDOWS\SYSTEM32\macd32.dll
2007-10-03 12:57 138,752 --a------ C:\WINDOWS\SYSTEM32\mase32.dll
2007-10-03 12:57 136,192 --a------ C:\WINDOWS\SYSTEM32\mamc32.dll
2007-10-03 12:57 57,856 --a------ C:\WINDOWS\SYSTEM32\masd32.dll
2007-10-03 12:57 27,648 --a------ C:\WINDOWS\SYSTEM32\ma32.dll
2007-10-03 12:56 171,520 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\MarvinBus.sys
2007-10-03 12:56 41,219 --a------ C:\WINDOWS\RSETPATH.exe
2007-10-03 12:56 14,165 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\Pclepci.sys
2007-10-03 12:54 49,152 --a------ C:\WINDOWS\SYSTEM32\PCLEGetGuid.dll
2007-10-03 12:53 <DIR> d-------- C:\Program Files\Pinnacle
2007-10-03 12:53 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Pinnacle Studio
2007-10-03 12:50 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Pinnacle
2007-10-03 12:49 <DIR> d-------- C:\Documents and Settings\Shael Sokolowski\Application Data\InstallShield
2007-10-03 11:46 36,352 --a------ C:\WINDOWS\SYSTEM32\iifeedd.dll
2007-10-03 00:48 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\CyberLink
2007-10-02 23:59 <DIR> d-------- C:\Documents and Settings\Shael Sokolowski\Application Data\Ulead Systems
2007-10-02 23:49 <DIR> d-------- C:\Program Files\Common Files\InterVideo
2007-10-02 23:49 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\InterVideo
2007-10-02 23:49 210,456 --a------ C:\WINDOWS\SYSTEM32\IVIresizeW7.dll
2007-10-02 23:49 206,360 --a------ C:\WINDOWS\SYSTEM32\IVIresizeA6.dll
2007-10-02 23:49 198,168 --a------ C:\WINDOWS\SYSTEM32\IVIresizeP6.dll
2007-10-02 23:49 198,168 --a------ C:\WINDOWS\SYSTEM32\IVIresizeM6.dll
2007-10-02 23:49 194,072 --a------ C:\WINDOWS\SYSTEM32\IVIresizePX.dll
2007-10-02 23:49 26,136 --a------ C:\WINDOWS\SYSTEM32\IVIresize.dll
2007-10-02 23:48 <DIR> d-------- C:\Program Files\Windows Media Components
2007-10-02 23:47 <DIR> d-------- C:\Program Files\Ulead Systems
2007-10-02 23:47 <DIR> d-------- C:\Program Files\Common Files\Ulead Systems
2007-10-02 23:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Ulead Systems
2007-10-02 21:59 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\CyberLink
2007-10-02 21:45 <DIR> d-------- C:\Program Files\SmartSound Software
2007-10-02 21:45 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SmartSound Software Inc
2007-09-21 13:21 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-18 20:47 --------- d-----w C:\Program Files\Symantec AntiVirus
2007-10-18 13:26 --------- d-----w C:\Program Files\LogMeIn
2007-10-17 14:30 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-10-12 13:48 --------- d-----w C:\Program Files\Microsoft IntelliPoint
2007-10-10 05:49 --------- d-----w C:\Program Files\RegClean
2007-10-09 16:47 --------- d-----w C:\Program Files\Common Files\LogiShrd
2007-10-09 15:07 --------- d-----w C:\Program Files\Logitech
2007-10-03 18:52 --------- d-----w C:\Program Files\Java
2007-10-03 18:32 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-10-03 18:32 --------- d-----w C:\Program Files\iPod
2007-10-03 18:30 --------- d-----w C:\Program Files\DivX
2007-10-03 18:27 --------- d-----w C:\Program Files\Mobile Action
2007-10-03 01:59 --------- d-----w C:\Documents and Settings\Shael Sokolowski\Application Data\CyberLink
2007-10-03 01:48 --------- d-----w C:\Program Files\CyberLink
2007-09-30 15:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\Ahead
2007-08-22 12:55 96,256 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\inseng.dll
2007-08-22 12:55 665,600 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\wininet.dll
2007-08-22 12:55 617,984 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\urlmon.dll
2007-08-22 12:55 55,808 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\extmgr.dll
2007-08-22 12:55 532,480 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\mstime.dll
2007-08-22 12:55 474,112 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\shlwapi.dll
2007-08-22 12:55 449,024 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\mshtmled.dll
2007-08-22 12:55 39,424 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\pngfilt.dll
2007-08-22 12:55 357,888 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\dxtmsft.dll
2007-08-22 12:55 3,064,832 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\mshtml.dll
2007-08-22 12:55 251,904 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\iepeers.dll
2007-08-22 12:55 205,824 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\dxtrans.dll
2007-08-22 12:55 16,384 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\jsproxy.dll
2007-08-22 12:55 151,040 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\cdfview.dll
2007-08-22 12:55 146,432 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\msrating.dll
2007-08-22 12:55 1,498,112 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\shdocvw.dll
2007-08-22 12:55 1,054,208 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\danim.dll
2007-08-22 12:55 1,022,976 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\browseui.dll
2007-08-21 10:19 18,432 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\iedw.exe
2007-08-21 06:15 683,520 ----a-w C:\WINDOWS\SYSTEM32\inetcomm.dll
2007-08-21 06:15 683,520 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\inetcomm.dll
2007-07-30 23:19 92,504 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\cdm.dll
2007-07-30 23:19 92,504 ----a-w C:\WINDOWS\SYSTEM32\cdm.dll
2007-07-30 23:19 549,720 ----a-w C:\WINDOWS\SYSTEM32\wuapi.dll
2007-07-30 23:19 549,720 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wuapi.dll
2007-07-30 23:19 53,080 ----a-w C:\WINDOWS\SYSTEM32\wuauclt.exe
2007-07-30 23:19 53,080 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wuauclt.exe
2007-07-30 23:19 43,352 ----a-w C:\WINDOWS\SYSTEM32\wups2.dll
2007-07-30 23:19 325,976 ----a-w C:\WINDOWS\SYSTEM32\wucltui.dll
2007-07-30 23:19 325,976 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wucltui.dll
2007-07-30 23:19 271,224 ----a-w C:\WINDOWS\SYSTEM32\mucltui.dll
2007-07-30 23:19 207,736 ----a-w C:\WINDOWS\SYSTEM32\muweb.dll
2007-07-30 23:19 203,096 ----a-w C:\WINDOWS\SYSTEM32\wuweb.dll
2007-07-30 23:19 203,096 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wuweb.dll
2007-07-30 23:19 1,712,984 ----a-w C:\WINDOWS\SYSTEM32\wuaueng.dll
2007-07-30 23:19 1,712,984 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wuaueng.dll
2007-07-30 23:18 33,624 ----a-w C:\WINDOWS\SYSTEM32\wups.dll
2007-07-30 23:18 33,624 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wups.dll
2007-07-19 00:44 465,432 ----a-w C:\WINDOWS\SYSTEM32\LVUI2RC.dll
2007-07-19 00:43 490,008 ----a-w C:\WINDOWS\SYSTEM32\LVUI2.dll
2007-07-19 00:40 416,280 ----a-w C:\WINDOWS\SYSTEM32\lvcodec2.dll
2007-07-18 23:55 19,344 ----a-w C:\WINDOWS\SYSTEM32\Repository.reg
2006-08-25 02:09 273,449 ----a-w C:\Documents and Settings\Shael Sokolowski\Shael Sokolowski.zip
2005-08-01 22:18 487,424 ----a-w C:\Documents and Settings\Shael Sokolowski\chatlnk.exe
2005-05-05 22:32:11 56 --sh--r C:\WINDOWS\SYSTEM32\81911F3CE5.sys
2007-07-02 04:13:09 848 -csha-w C:\WINDOWS\SYSTEM32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((( snapshot@2007-10-17_10.14.12.84 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-10-10 17:15:32 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE
+ 2007-10-18 07:40:16 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE
- 2007-10-11 03:04:17 16,736,256 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000001\ntuser.dat
+ 2007-10-18 17:10:35 16,822,272 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000001\ntuser.dat
- 2007-10-11 03:04:17 212,992 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000002\UsrClass.dat
+ 2007-10-18 17:10:35 212,992 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000002\UsrClass.dat
- 2007-10-17 04:46:50 93,774 ----a-w C:\WINDOWS\SYSTEM32\PERFC009.DAT
+ 2007-10-18 20:52:27 93,774 ----a-w C:\WINDOWS\SYSTEM32\PERFC009.DAT
- 2007-10-17 04:46:50 494,096 ----a-w C:\WINDOWS\SYSTEM32\PERFH009.DAT
+ 2007-10-18 20:52:27 494,096 ----a-w C:\WINDOWS\SYSTEM32\PERFH009.DAT
- 2007-10-17 14:13:17 12,924 ----a-w C:\WINDOWS\SYSTEM32\tablet.dat
+ 2007-10-18 19:34:40 12,924 ----a-w C:\WINDOWS\SYSTEM32\tablet.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2B0B81EA-6955-4E8E-AD51-ACC76C42198E}]
C:\WINDOWS\system32\pmnnm.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{564C99EE-3072-495D-9BCC-C752A3D40D17}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9DCBC996-2B91-45B3-A75C-192E89BBD324}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AA195F2A-DC90-4F28-BD83-F985ADE2A23A}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F4571007-000C-40E6-A1F5-A03E3B3D7DAD}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe" [2004-03-23 13:16]
"CTSysVol"="C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe" [2003-09-17 11:43]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-12-06 02:05]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2004-06-09 20:31]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2004-08-02 19:36]
"LogMeIn GUI"="C:\Program Files\LogMeIn\x86\LogMeInSystray.exe" [2007-04-17 14:03]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2005-12-04 17:39]
"CoolSwitch"="C:\WINDOWS\system32\taskswitch.exe" [2002-03-19 18:30]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-04-27 11:25]
"LogitechCommunicationsManager"="C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-07-25 16:02]
"LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam\Quickcam.exe" [2007-07-25 16:06]
"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2004-08-04 06:00]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Bandook"="C:\WINDOWS\system32\ali.exe" [2007-10-17 00:48]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 06:00]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce]
"*Bandook"=C:\WINDOWS\system32\ali.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Post-itr Software Notes Lite.lnk - C:\Program Files\3M\PSNLite\PsnLite.exe [2004-06-02 14:04:58]
TabUserW.exe.lnk - C:\WINDOWS\SYSTEM32\WTablet\TabUserW.exe [2007-04-18 13:14:57]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"StartMenuLogOff"=1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\iifeedd]
iifeedd.dll 2007-10-03 11:46 36352 C:\WINDOWS\SYSTEM32\iifeedd.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Shael Sokolowski^Start Menu^Programs^Startup^PowerReg Scheduler.exe]
path=C:\Documents and Settings\Shael Sokolowski\Start Menu\Programs\Startup\PowerReg Scheduler.exe
backup=C:\WINDOWS\pss\PowerReg Scheduler.exeStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
"C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Spyware Protection]
"C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APL]
"C:\Program Files\ACT\ACT for Win 7\APL.exe"