Here is the log for Vundo Fix:
VundoFix V6.5.6
Checking Java version...
Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.
Scan started at 11:34:53 PM 7/31/2007
Listing files found while scanning....
No infected files were found.
I ran Spyware doctor, then Combo fix. Here is the Combo fix log:
ComboFix 07-07-30.2 - "Anisah" 2007-08-02 10:36:14.2 [GMT -5:00] - NTFS
Microsoft Windows XP Professional 5.1.2600.1.1252.1.1033.18.True
((((((((((((((((((((((((( Files Created from 2007-07-02 to 2007-08-02 )))))))))))))))))))))))))))))))
2007-08-01 22:42 83,024 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2007-08-01 22:42 57,424 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2007-08-01 22:42 53,840 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-08-01 22:42 39,376 --a------ C:\WINDOWS\system32\drivers\ikfileflt.sys
2007-08-01 22:42 29,264 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2007-08-01 22:41 <DIR> d-------- C:\DOCUME~1\Anisah\APPLIC~1\PC Tools
2007-08-01 22:40 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2007-08-01 22:05 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-07-31 23:34 <DIR> d-------- C:\VundoFix Backups
2007-07-30 15:56 <DIR> d-a------ C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
2007-07-30 15:54 <DIR> d-------- C:\Program Files\Kitty Luv
2007-07-29 13:29 94,416 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2007-07-29 13:29 92,848 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2007-07-29 13:29 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2007-07-29 13:29 26,624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2007-07-29 00:30 <DIR> d-------- C:\Program Files\Safer Networking
2007-07-28 10:23 1,760,645 ---hs---- C:\WINDOWS\system32\rttss.bak2
2007-07-26 12:39 6,466 ---hs---- C:\WINDOWS\system32\rttss.bak1
2007-07-26 12:34 926,352 -r-hs---- C:\WINDOWS\chhgudkA.exe
2007-07-26 12:34 171,520 --a------ C:\WINDOWS\system32\vvdiais.dll
2007-07-26 12:34 <DIR> d-------- C:\Temp\0c2
2007-07-26 12:33 <DIR> d-------- C:\Temp\brr
2007-07-26 12:33 <DIR> d-------- C:\Temp
2007-07-26 08:30 147,456 --a------ C:\WINDOWS\system32\AbsoluteHttp.dll
2007-07-26 08:30 1,392,671 --a------ C:\WINDOWS\system32\msvbvm60.dll
2007-07-26 08:30 <DIR> d-------- C:\WINDOWS\system32\FCyberAlert
2007-07-25 14:00 <DIR> d-------- C:\Program Files\iPod
2007-07-25 13:59 <DIR> d-------- C:\Program Files\iTunes
2007-07-25 13:41 <DIR> d-------- C:\Program Files\QuickTime
2007-07-25 13:38 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
2007-07-24 15:48 <DIR> d-------- C:\Program Files\Aurelon PhotoPro
2007-07-23 11:24 <DIR> d-------- C:\Program Files\support.com
2007-07-23 11:23 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Support.com
2007-07-16 09:03 <DIR> d-------- C:\DOCUME~1\Anisah\APPLIC~1\Snapfish
2007-07-16 08:32 45,152 --------- C:\WINDOWS\system32\PPCOUNIN.exe
2007-07-16 08:09 <DIR> d-------- C:\Program Files\Common Files\PeoplePC
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-08-02 08:16 --------- d-------- C:\Program Files\Spyware Doctor
2007-07-31 23:24 --------- d-------- C:\Program Files\FTM
2007-07-27 17:07 783224 --a------ C:\WINDOWS\system32\aswBoot.exe
2007-07-27 17:00 23152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2007-07-27 16:57 95608 --a------ C:\WINDOWS\system32\AVASTSS.scr
2007-07-26 18:34 --------- d-------- C:\Program Files\SpywareBlaster
2007-07-26 12:34 --------- d-------- C:\Program Files\MSN Gaming Zone
2007-07-26 10:20 --------- d-------- C:\DOCUME~1\Anisah\APPLIC~1\XnView
2007-07-25 13:38 --------- d-------- C:\Program Files\Apple Software Update
2007-07-25 13:08 --------- d-------- C:\Program Files\MSN Messenger
2007-07-25 11:12 --------- d-------- C:\Program Files\FontExpert
2007-07-23 11:26 --------- d-------- C:\Program Files\BroadJump
2007-07-20 15:35 --------- d-------- C:\DOCUME~1\Anisah\APPLIC~1\Snappy Fax 2000
2007-07-16 09:03 4329 --a------ C:\WINDOWS\mozver.dat
2007-07-16 08:32 --------- d-------- C:\Program Files\PeoplePC
2007-06-27 15:05 --------- d-------- C:\Program Files\Sony
2007-06-27 15:01 --------- d-------- C:\DOCUME~1\Anisah\APPLIC~1\Aim
2007-06-15 06:13 --------- d-------- C:\Program Files\AIM
2007-06-07 21:18 --------- d-------- C:\DOCUME~1\Anisah\APPLIC~1\Viewpoint
2007-05-02 21:50 4212 ---h----- C:\WINDOWS\system32\zllictbl.dat
2006-02-10 15:45 1740 --a------ C:\Program Files\Adobe Reader 7.0.lnk
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3964D8D6-86D0-493A-B460-A805B5401114}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{60875658-630e-4dfa-84d3-806432bdc66d}]
2007-07-26 12:34 171520 --a------ C:\WINDOWS\System32\vvdiais.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{706706E8-3111-423C-B165-69AD659F541C}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{72F6D9A2-853F-41ED-AC9F-62E1CB8E7639}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A8FB8EB3-183B-4598-924D-86F0E5E37085}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FD4AE849-FEDD-4564-A873-D3EA7592F76B}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BJCFD"="C:\Program Files\BroadJump\Client Foundation\CFD.exe" []
"Zone Labs Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-03-09 01:02]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" []
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-07-27 17:03]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2005-05-31 00:04]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ddayx]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mljhggd]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ssttr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
backup=C:\WINDOWS\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^eFax 4.1.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\eFax 4.1.lnk
backup=C:\WINDOWS\pss\eFax 4.1.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^MightyFAX Controller.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\MightyFAX Controller.lnk
backup=C:\WINDOWS\pss\MightyFAX Controller.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ymetray.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ymetray.lnk
backup=C:\WINDOWS\pss\ymetray.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Anisah^Start Menu^Programs^Startup^Firefox.lnk]
path=C:\Documents and Settings\Anisah\Start Menu\Programs\Startup\Firefox.lnk
backup=C:\WINDOWS\pss\Firefox.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
"C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast!]
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG7_CC]
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Bart Station]
C:\Program Files\PeoplePC\ISP6200\BIN\PPCOLink.exe -STATION
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eFax 4.1]
"C:\Program Files\eFax Messenger 4.1\J2GDllCmd.exe" /R
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
"c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
"C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
%systemroot%\system32\dumprep 0 -k
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDF4 Registry Controller]
"C:\Program Files\ScanSoft\PDF Professional 4.0\\RegistryController.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PuttPuttMoon.exe]
C:\DOCUME~1\Anisah\Desktop\DOWNLO~1\PUTTPU~1.EXE /r
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate]
"C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartMeSGS]
C:\Program Files\SOS Online Backup\SOS Online Backup v1.3\sosuploadagent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UnlockerAssistant]
"C:\Program Files\Unlocker\UnlockerAssistant.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
"C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe" AcPro7_0_8 -reboot 1
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{ZN}]
C:\WINDOWS\TISKY009.exe SKY009
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"YBrowser"=C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime
R2 Pctspk;PCTEL Speaker Phone;C:\WINDOWS\system32\pctspk.exe
R3 E100B;Intel(R) PRO Adapter Driver;C:\WINDOWS\System32\DRIVERS\e100b325.sys
R3 i81x;i81x;C:\WINDOWS\System32\DRIVERS\i81xnt5.sys
R3 IKFileFlt;File Filter Driver;C:\WINDOWS\System32\drivers\ikfileflt.sys
R3 IKFileSec;File Security Driver;C:\WINDOWS\System32\drivers\ikfilesec.sys
R3 IkSysFlt;System Filter Driver;C:\WINDOWS\System32\drivers\iksysflt.sys
R3 IKSysSec;System Security Driver;C:\WINDOWS\System32\drivers\iksyssec.sys
R3 MxlW2k;MxlW2k;C:\WINDOWS\System32\drivers\MxlW2k.sys
R3 Ptserlp;PCTEL Serial Device Driver for PCI;C:\WINDOWS\System32\DRIVERS\ptserlp.sys
S3 BW2NDIS5;BW2NDIS5;C:\WINDOWS\System32\Drivers\BW2NDIS5.sys
S3 iAimFP0;iAimFP0;C:\WINDOWS\System32\DRIVERS\wADV01nt.sys
S3 iAimFP1;iAimFP1;C:\WINDOWS\System32\DRIVERS\wADV02NT.sys
S3 iAimFP2;iAimFP2;C:\WINDOWS\System32\DRIVERS\wADV05NT.sys
S3 iAimFP3;iAimFP3;C:\WINDOWS\System32\DRIVERS\wSiINTxx.sys
S3 iAimFP4;iAimFP4;C:\WINDOWS\System32\DRIVERS\wVchNTxx.sys
S3 iAimTV0;iAimTV0;C:\WINDOWS\System32\DRIVERS\wATV01nt.sys
S3 iAimTV1;iAimTV1;C:\WINDOWS\System32\DRIVERS\wATV02NT.sys
S3 iAimTV2;iAimTV2;C:\WINDOWS\System32\DRIVERS\wATV03nt.sys
S3 iAimTV3;iAimTV3;C:\WINDOWS\System32\DRIVERS\wATV04nt.sys
S3 iAimTV4;iAimTV4;C:\WINDOWS\System32\DRIVERS\wCh7xxNT.sys
S3 pmxscan;Memorex USB Kernel;C:\WINDOWS\System32\DRIVERS\usbscan.sys
S3 TnIDriver;TnIDriver;\??\C:\DOCUME~1\Anisah\LOCALS~1\Temp\tni1F.tmp
S3 TUWinStylerThemeSvc;TuneUp WinStyler Theme Service;C:\Program Files\TuneUp Utilities 2004\WinStylerThemeSvc.exe
Contents of the 'Scheduled Tasks' folder
2007-07-27 22:25:26 C:\WINDOWS\Tasks\1-Click Maintenance.job - C:\Program Files\TuneUp Utilities 2004\SystemOptimizer.exe
2007-07-25 18:38:41 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
2007-08-02 05:00:01 C:\WINDOWS\Tasks\At1.job - C:\WINDOWS\System32\yk4awMYE.exe
2007-08-02 14:00:03 C:\WINDOWS\Tasks\At10.job - C:\WINDOWS\System32\yk4awMYE.exe
2007-08-02 15:00:01 C:\WINDOWS\Tasks\At11.job - C:\WINDOWS\System32\yk4awMYE.exe
2007-08-01 16:00:01 C:\WINDOWS\Tasks\At12.job - C:\WINDOWS\System32\yk4awMYE.exe
2007-08-01 17:00:05 C:\WINDOWS\Tasks\At13.job - C:\WINDOWS\System32\yk4awMYE.exe
2007-08-01 18:00:04 C:\WINDOWS\Tasks\At14.job - C:\WINDOWS\System32\yk4awMYE.exe
2007-08-01 19:00:02 C:\WINDOWS\Tasks\At15.job - C:\WINDOWS\System32\yk4awMYE.exe
2007-08-01 20:00:02 C:\WINDOWS\Tasks\At16.job - C:\WINDOWS\System32\yk4awMYE.exe
2007-08-01 21:00:01 C:\WINDOWS\Tasks\At17.job - C:\WINDOWS\System32\yk4awMYE.exe
2007-08-01 22:00:03 C:\WINDOWS\Tasks\At18.job - C:\WINDOWS\System32\yk4awMYE.exe
2007-08-01 23:00:01 C:\WINDOWS\Tasks\At19.job - C:\WINDOWS\System32\yk4awMYE.exe
2007-08-02 06:00:00 C:\WINDOWS\Tasks\At2.job
2007-08-02 00:00:00 C:\WINDOWS\Tasks\At20.job - C:\WINDOWS\System32\yk4awMYE.exe
2007-08-02 01:00:00 C:\WINDOWS\Tasks\At21.job - C:\WINDOWS\System32\yk4awMYE.exe
2007-08-02 02:00:06 C:\WINDOWS\Tasks\At22.job - C:\WINDOWS\System32\yk4awMYE.exe
2007-08-02 03:00:00 C:\WINDOWS\Tasks\At23.job - C:\WINDOWS\System32\yk4awMYE.exe
2007-08-02 04:00:16 C:\WINDOWS\Tasks\At24.job - C:\WINDOWS\System32\yk4awMYE.exe
2007-08-02 07:00:02 C:\WINDOWS\Tasks\At3.job - C:\WINDOWS\System32\yk4awMYE.exe
2007-08-02 08:00:06 C:\WINDOWS\Tasks\At4.job - C:\WINDOWS\System32\yk4awMYE.exe
2007-08-02 09:00:00 C:\WINDOWS\Tasks\At5.job - C:\WINDOWS\System32\yk4awMYE.exe
2007-08-02 10:00:00 C:\WINDOWS\Tasks\At6.job - C:\WINDOWS\System32\yk4awMYE.exe
2007-08-02 11:00:00 C:\WINDOWS\Tasks\At7.job - C:\WINDOWS\System32\yk4awMYE.exe
2007-08-02 12:00:00 C:\WINDOWS\Tasks\At8.job - C:\WINDOWS\System32\yk4awMYE.exe
2007-08-02 13:00:00 C:\WINDOWS\Tasks\At9.job - C:\WINDOWS\System32\yk4awMYE.exe
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-08-02 10:54:47
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-08-02 10:59:16
C:\ComboFix-quarantined-files.txt ... 2007-08-02 10:58
C:\ComboFix2.txt ... 2007-08-01 22:33
--- E O F ---
I can't post my hijack this in the same post, so I'll post it next. Thanks so much for your help!