And the ComboFix log:
ComboFix 07-11-08.1 - Jim Benedict 2007-11-14 20:53:41.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.582 [GMT -5:00]
Running from: C:\Documents and Settings\Jim Benedict\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\ddeeg.ini
C:\WINDOWS\system32\ddeeg.ini2
C:\WINDOWS\system32\geedd.dll
.
((((((((((((((((((((((((( Files Created from 2007-10-15 to 2007-11-15 )))))))))))))))))))))))))))))))
.
2007-11-14 18:13 24,576 --a------ C:\WINDOWS\system32\VundoFixSVC.exe
2007-11-14 17:43 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2007-11-14 13:11 85,056 --a------ C:\WINDOWS\system32\onycrdhj.dll
2007-11-14 13:05 145,984 --a------ C:\WINDOWS\system32\sfgssnxq.dll
2007-11-14 08:18 <DIR> d-------- C:\Program Files\Lavasoft
2007-11-14 08:18 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-11-14 08:17 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-11-13 23:38 <DIR> d-------- C:\VundoFix Backups
2007-11-13 20:59 <DIR> d-------- C:\Program Files\Common Files\Java
2007-11-13 20:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Rabio
2007-11-13 20:46 <DIR> d-------- C:\Program Files\Cool
2007-11-13 20:43 <DIR> d-------- C:\Documents and Settings\Jim Benedict\Application Data\Grisoft
2007-11-13 20:14 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-11-13 19:17 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2007-11-13 19:12 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-11-13 11:08 145,984 --a------ C:\WINDOWS\system32\daavufvx.dll
2007-11-12 17:15 <DIR> d-------- C:\Program Files\SpyGuardPro
2007-11-12 17:15 24,064 --a------ C:\WINDOWS\system32\msxml3a.dll
2007-11-12 17:12 <DIR> d-------- C:\WINDOWS\system32\rMa02yy
2007-11-12 17:12 <DIR> d-------- C:\Temp\abW9
2007-11-12 17:12 36,352 --a------ C:\WINDOWS\system32\iifgdcb.dll
2007-11-11 10:55 61,480 --a------ C:\Documents and Settings\Jim Benedict\GoToAssistDownloadHelper.exe
2007-11-10 15:09 <DIR> d-------- C:\Program Files\iTunes
2007-11-10 15:09 <DIR> d-------- C:\Program Files\iPod
2007-11-10 15:05 <DIR> d-------- C:\Program Files\QuickTime
2007-10-27 18:50 <DIR> d-------- C:\Program Files\My Book
2007-10-27 18:50 <DIR> d-------- C:\Program Files\Common Files\ArcSoft
2007-10-27 18:50 <DIR> d-------- C:\Documents and Settings\Jim Benedict\Application Data\ArcSoft
2007-10-27 18:50 212,480 --------- C:\WINDOWS\PCDLIB32.DLL
2007-10-27 18:50 11,776 --------- C:\WINDOWS\system32\drivers\afc.sys
2007-10-27 18:47 <DIR> d-------- C:\Program Files\Western Digital Technologies
2007-10-27 18:47 339,968 --a------ C:\WINDOWS\system32\WDBtnMgr.exe
2007-10-27 13:17 <DIR> d-------- C:\WINDOWS\system32\NtmsData
2007-10-27 00:12 <DIR> d---s---- C:\Documents and Settings\Jim Benedict\UserData
2007-10-26 22:46 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-10-26 22:45 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2007-10-26 22:45 <DIR> d-------- C:\Documents and Settings\Jim Benedict\Application Data\SUPERAntiSpyware.com
2007-10-26 22:33 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-10-26 21:39 <DIR> d-------- C:\Program Files\AntispyStorm
2007-10-26 21:15 <DIR> d-------- C:\Program Files\Trend Micro
2007-10-26 20:23 5,128 --a------ C:\WINDOWS\system32\tmp.reg
2007-10-26 10:58 4 --a------ C:\WINDOWS\system32\stfv.bin
2007-10-26 10:56 <DIR> d-------- C:\WINDOWS\system32\acespy
2007-10-26 10:36 12 --a------ C:\WINDOWS\system32\dpqaqlqx.bin
2007-10-26 10:35 13,824 --------- C:\WINDOWS\plite731.exe
2007-10-26 10:35 41 --------- C:\WINDOWS\plite731_uninstaller_.bat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-14 23:10 --------- d-----w C:\Program Files\McAfee
2007-11-14 23:06 --------- d-----w C:\Documents and Settings\LocalService\Application Data\SiteAdvisor
2007-11-14 05:56 --------- d-----w C:\Program Files\Dl_cats
2007-11-14 02:01 --------- d-----w C:\Program Files\Java
2007-11-11 16:38 --------- d-----w C:\Program Files\SiteAdvisor
2007-10-27 23:50 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-10-26 03:34 8,460,288 ----a-w C:\WINDOWS\system32\dllcache\shell32.dll
2007-09-28 12:26 --------- d-----w C:\Program Files\Apple Software Update
2007-09-28 12:25 --------- d-----w C:\Program Files\Common Files\Apple
2007-09-28 12:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
2007-08-22 12:55 96,256 ------w C:\WINDOWS\system32\dllcache\inseng.dll
2007-08-22 12:55 665,600 ------w C:\WINDOWS\system32\dllcache\wininet.dll
2007-08-22 12:55 617,984 ------w C:\WINDOWS\system32\dllcache\urlmon.dll
2007-08-22 12:55 55,808 ----a-w C:\WINDOWS\system32\dllcache\extmgr.dll
2007-08-22 12:55 532,480 ----a-w C:\WINDOWS\system32\dllcache\mstime.dll
2007-08-22 12:55 474,112 ------w C:\WINDOWS\system32\dllcache\shlwapi.dll
2007-08-22 12:55 449,024 ------w C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-08-22 12:55 39,424 ------w C:\WINDOWS\system32\dllcache\pngfilt.dll
2007-08-22 12:55 357,888 ------w C:\WINDOWS\system32\dllcache\dxtmsft.dll
2007-08-22 12:55 3,064,832 ------w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-08-22 12:55 251,904 ----a-w C:\WINDOWS\system32\dllcache\iepeers.dll
2007-08-22 12:55 205,824 ------w C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-08-22 12:55 16,384 ----a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-08-22 12:55 151,040 ----a-w C:\WINDOWS\system32\dllcache\cdfview.dll
2007-08-22 12:55 146,432 ----a-w C:\WINDOWS\system32\dllcache\msrating.dll
2007-08-22 12:55 1,498,112 ------w C:\WINDOWS\system32\dllcache\shdocvw.dll
2007-08-22 12:55 1,054,208 ----a-w C:\WINDOWS\system32\dllcache\danim.dll
2007-08-22 12:55 1,022,976 ------w C:\WINDOWS\system32\dllcache\browseui.dll
2007-08-21 10:19 18,432 ----a-w C:\WINDOWS\system32\dllcache\iedw.exe
2007-08-21 06:15 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-08-21 06:15 683,520 ----a-w C:\WINDOWS\system32\dllcache\inetcomm.dll
.
((((((((((((((((((((((((((((( snapshot_2007-11-13_22.31.37.06 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-11-14 13:18:30 1,038,336 ----a-r C:\WINDOWS\Installer\{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}\Icon0E6AB9FC.exe
+ 2007-11-14 13:18:30 178,688 ----a-r C:\WINDOWS\Installer\{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}\Icon0E6AB9FC1.exe
+ 2007-11-14 13:18:30 171,008 ----a-r C:\WINDOWS\Installer\{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}\IconDED53B0B.exe
+ 2007-11-14 13:18:30 8,704 ----a-r C:\WINDOWS\Installer\{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}\IconDED53B0B1.exe
+ 2007-07-11 18:37:26 6,272 ----a-w C:\WINDOWS\system32\drivers\AWRTPD.sys
+ 2007-08-07 17:58:08 8,320 ----a-w C:\WINDOWS\system32\drivers\AWRTRD.sys
+ 2007-08-07 17:56:58 9,344 ----a-w C:\WINDOWS\system32\drivers\NSDriver.sys
+ 2007-04-13 19:19:52 7,680 ----a-w C:\WINDOWS\system32\lsdelete.exe
- 2007-09-28 05:19:39 18,089,592 ----a-w C:\WINDOWS\system32\MRT.exe
+ 2007-11-02 07:12:57 18,238,072 ----a-w C:\WINDOWS\system32\MRT.exe
- 2006-12-19 21:52:18 8,453,632 ------w C:\WINDOWS\system32\shell32.dll
+ 2007-10-26 03:34:01 8,460,288 ----a-w C:\WINDOWS\system32\shell32.dll
- 2007-08-21 10:13:33 350,720 ----a-w C:\WINDOWS\system32\xpsp3res.dll
+ 2007-10-29 10:04:03 350,720 ----a-w C:\WINDOWS\system32\xpsp3res.dll
+ 2007-11-15 02:01:28 16,384 ----atw C:\WINDOWS\temp\Perflib_Perfdata_be8.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4CB8F4B4-5F66-4D9E-BC3B-184596A58824}]
2007-11-12 17:12 36352 --a------ C:\WINDOWS\system32\iifgdcb.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5C2A9795-B130-4622-B036-BDCAD28602DC}]
2007-11-12 11:50 397312 --a------ C:\Program Files\Cool\Cool.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2004-09-13 17:33]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-30 15:59]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-05 22:05]
"PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe" [2004-04-11 21:15]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2005-09-01 18:24]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 17:19]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-12-06 02:05]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 11:44]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 11:44]
"MimBoot"="C:\PROGRA~1\MUSICM~1\MUSICM~2\mimboot.exe" [2005-09-08 20:20]
"MMTray"="C:\PROGRA~1\MUSICM~1\MUSICM~2\mm_tray.exe" [2005-09-08 20:20]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2006-06-21 12:14]
"Corel Photo Downloader"="C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe" [2005-08-31 12:06]
"DLCDCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCDtime.dll" [2005-06-07 13:39]
"dlcdmon.exe"="C:\Program Files\Dell Photo AIO Printer 944\dlcdmon.exe" [2005-07-22 14:45]
"MemoryCardManager"="C:\Program Files\Dell Photo AIO Printer 944\memcard.exe" [2005-06-27 12:05]
"MskAgentexe"="C:\Program Files\McAfee\MSK\MskAgent.exe" [2007-01-17 17:30]
"SiteAdvisor"="C:\Program Files\SiteAdvisor\6172\SiteAdv.exe" [2007-02-08 21:39]
"plite731"="C:\WINDOWS\plite731.exe" [2007-10-26 10:35]
"Windows Update Check"="C:\WINDOWS\system32\syslodr.exe" []
"WD Button Manager"="WDBtnMgr.exe" [2007-10-27 18:47 C:\WINDOWS\system32\WDBtnMgr.exe]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-10-19 20:16]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-11-02 18:36]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 04:25]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
"204cf6ef"="C:\WINDOWS\system32\onycrdhj.dll" [2007-11-14 13:11]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 06:00]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 10:09]
"ISMPack8"="C:\Program Files\ISM2\ISMPack8.exe" []
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-07-30 03:52:00]
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe [2004-12-22 14:42:22]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2005-11-22 19:40:06]
QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2007-01-10 17:16:27]
WD Backup Monitor.lnk - C:\Program Files\My Book\WD Backup\uBBMonitor.exe [2007-10-27 18:50:10]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{4CB8F4B4-5F66-4D9E-BC3B-184596A58824}"= C:\WINDOWS\system32\iifgdcb.dll [2007-11-12 17:12 36352]
[HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="C:\\WINDOWS\\system32\\vvgeowbv.exe,C:\\WINDOWS\\system32\\userinit.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\iifgdcb]
iifgdcb.dll 2007-11-12 17:12 36352 C:\WINDOWS\system32\iifgdcb.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
C:\Program Files\Intel\Wireless\Bin\LgNotify.dll 2004-09-07 17:08 110592 C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\geedd.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
R3 dlcd_device;dlcd_device;C:\WINDOWS\system32\dlcdcoms.exe -service
S3 SQLAgent$MICROSOFTBCM;SQLAgent$MICROSOFTBCM;C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlagent.EXE -i MICROSOFTBCM
.
Contents of the 'Scheduled Tasks' folder
"2007-11-06 00:36:06 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-03-03 13:19:15 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe
"2007-07-01 05:00:11 C:\WINDOWS\Tasks\McQcTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe
.
**************************************************************************
catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-11-14 21:01:34
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-14 21:06:04 - machine was rebooted
C:\ComboFix2.txt ... 2007-11-14 19:16
C:\ComboFix3.txt ... 2007-11-14 00:59
.
--- E O F ---