The vundofix did not find any infected files. I looked in the system room folder and there was nothing shown in it. I did the combo fix and the log is below, i will post the new hijackthis log next.
ComboFix 07-11-19.4 - marci 2007-11-26 21:21:06.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.448 [GMT -5:00]
Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\marci\Desktop\CFScript.txt
* Created a new restore point
FILE
C:\Documents and Settings\marci\x.dat
C:\Documents and Settings\marci\z.dat
C:\n.bat
C:\WINDOWS\Fonts\svchost.exe
C:\WINDOWS\system32\btbwebkl.dll
C:\WINDOWS\system32\gjllm.ini
C:\WINDOWS\system32\gjllm.ini2
C:\WINDOWS\system32\jmllm.ini2
C:\WINDOWS\system32\lkbewbtb.ini
C:\WINDOWS\system32\qbdxdgri.ini
C:\WINDOWS\system32\rrqss.ini2
C:\WINDOWS\system32\stpgqvlf.ini
C:\x.dat
C:\z.dat
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\marci\x.dat
C:\Documents and Settings\marci\z.dat
C:\n.bat
C:\WINDOWS\system32\gjllm.ini
C:\WINDOWS\system32\gjllm.ini2
C:\WINDOWS\system32\jmllm.ini2
C:\WINDOWS\system32\lkbewbtb.ini
C:\WINDOWS\system32\qbdxdgri.ini
C:\WINDOWS\system32\rrqss.ini2
C:\WINDOWS\system32\stpgqvlf.ini
C:\x.dat
C:\z.dat
.
((((((((((((((((((((((((( Files Created from 2007-10-27 to 2007-11-27 )))))))))))))))))))))))))))))))
.
2007-11-25 19:55 d-------- C:\Documents and Settings\marci\Application Data\Uniblue
2007-11-25 19:54 d-------- C:\Program Files\Uniblue
2007-11-25 18:29 d-------- C:\Program Files\A Christmas Tree Screensaver
2007-11-24 21:21 d-------- C:\Program Files\Opera
2007-11-24 18:07 d-------- C:\Program Files\n7 Studios
2007-11-24 15:35 d-------- C:\Program Files\HT Fireman CDDVD Burner 1.4
2007-11-22 17:11 940,794 --a------ C:\WINDOWS\system32\LoopyMusic.wav
2007-11-22 17:11 146,650 --a------ C:\WINDOWS\system32\BuzzingBee.wav
2007-11-22 17:11 81,920 --a------ C:\WINDOWS\ALCFDRTM.EXE
2007-11-21 17:15 d-------- C:\Documents and Settings\greg\Application Data\AVG7
2007-11-21 08:13 d-------- C:\Documents and Settings\Administrator\Application Data\AVG7
2007-11-20 22:32 d-------- C:\Documents and Settings\marci\Application Data\AVG7
2007-11-20 22:31 d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2007-11-20 22:31 d-------- C:\Documents and Settings\All Users\Application Data\avg7
2007-11-20 22:21 d-------- C:\Documents and Settings\marci\Application Data\FrostWire
2007-11-19 23:00 6,058,496 --a------ C:\WINDOWS\system32\dllcache\ieframe.dll
2007-11-19 23:00 2,455,488 --a------ C:\WINDOWS\system32\dllcache\ieapfltr.dat
2007-11-19 23:00 991,232 --a------ C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2007-11-19 23:00 459,264 --a------ C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-11-19 23:00 383,488 --a------ C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-11-19 23:00 267,776 --a------ C:\WINDOWS\system32\dllcache\iertutil.dll
2007-11-19 23:00 63,488 --a------ C:\WINDOWS\system32\dllcache\icardie.dll
2007-11-19 23:00 52,224 --a------ C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-11-19 23:00 13,824 --a------ C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-11-18 21:00 d-------- C:\SystemRoot
2007-11-18 20:55 d-------- C:\Documents and Settings\marci\Application Data\WinBatch
2007-11-18 20:51 d-------- C:\temp
2007-11-18 15:36 d-------- C:\WINDOWS\DED53B0BB67C4244AE6AD6FD3C28D1EF.TMP
2007-11-18 13:53 d-------- C:\Program Files\FrostWire
2007-11-17 22:41 d-------- C:\Program Files\Lavasoft
2007-11-17 22:41 d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-11-17 22:15 d-------- C:\Program Files\Trend Micro
2007-11-17 22:11 d-------- C:\VundoFix Backups
2007-11-17 21:51 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2007-11-17 21:49 d-------- C:\Documents and Settings\marci\.housecall6.6
2007-11-17 21:48 d-------- C:\WINDOWS\Sun
2007-11-17 21:36 d-------- C:\Documents and Settings\Administrator\Application Data\HPQ
2007-11-17 15:36 d-------- C:\Documents and Settings\greg\Application Data\LimeWire
2007-11-17 15:35 d-------- C:\Documents and Settings\greg\Application Data\SiteAdvisor
2007-11-17 12:41 28,672 --a------ C:\WINDOWS\system32\drivers\CO_Mon.sys
2007-11-17 12:17 4,112 --a------ C:\WINDOWS\system32\tmp.reg
2007-11-17 09:07 d-------- C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com
2007-11-17 09:00 d-------- C:\Program Files\SUPERAntiSpyware
2007-11-17 09:00 d-------- C:\Documents and Settings\marci\Application Data\SUPERAntiSpyware.com
2007-11-17 09:00 d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-11-17 08:31 d-------- C:\Documents and Settings\marci\Application Data\HPQ
2007-11-17 08:12 9,503 --a------ C:\WINDOWS\system32\Config.MPF
2007-11-16 22:14 d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-11-16 22:07 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-11-16 21:45 d-------- C:\Documents and Settings\LocalService\Application Data\SiteAdvisor
2007-11-16 21:44 d-------- C:\Program Files\SiteAdvisor
2007-11-16 21:44 d-------- C:\Documents and Settings\marci\Application Data\SiteAdvisor
2007-11-16 21:44 d-------- C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2007-11-16 21:41 201,288 --a------ C:\WINDOWS\system32\drivers\mfehidk.sys
2007-11-16 21:41 79,304 --a------ C:\WINDOWS\system32\drivers\mfeavfk.sys
2007-11-16 21:41 40,488 --a------ C:\WINDOWS\system32\drivers\mfesmfk.sys
2007-11-16 21:41 35,240 --a------ C:\WINDOWS\system32\drivers\mfebopk.sys
2007-11-16 21:41 33,800 --a------ C:\WINDOWS\system32\drivers\mferkdk.sys
2007-11-16 21:40 113,952 --a------ C:\WINDOWS\system32\drivers\Mpfp.sys
2007-11-16 21:37 d-------- C:\Program Files\McAfee.com
2007-11-16 21:37 d-------- C:\Program Files\Common Files\McAfee
2007-11-16 21:36 d-------- C:\Program Files\McAfee
2007-11-16 20:55 d-------- C:\Documents and Settings\All Users\Application Data\McAfee
2007-11-16 20:49 d-------- C:\Documents and Settings\marci\Application Data\WinPatrol
2007-11-16 20:48 d-------- C:\Program Files\BillP Studios
2007-11-16 18:35 2,413 --a------ C:\Documents and Settings\greg\x.dat
2007-11-16 18:35 2,269 --a------ C:\Documents and Settings\greg\z.dat
2007-11-15 22:28 147,456 --a------ C:\WINDOWS\system32\vbzip10.dll
2007-11-15 21:08 d-------- C:\Documents and Settings\marci\Application Data\Apple Computer
2007-11-15 21:05 d-------- C:\Documents and Settings\marci\Application Data\Template
2007-11-15 21:05 0 --a------ C:\Documents and Settings\marci\Application Data\wklnhst.dat
2007-11-14 21:55 d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-11-14 07:32 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2007-11-14 07:32 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2007-11-11 21:41 d-------- C:\Program Files\QuickTime
2007-11-11 21:41 d-------- C:\Program Files\Apple Software Update
2007-11-11 21:41 d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-11-11 21:41 d-------- C:\Documents and Settings\All Users\Application Data\Apple
2007-11-11 15:54 d-------- C:\Documents and Settings\greg\Application Data\Sonic
2007-11-11 15:54 d-------- C:\Documents and Settings\greg\Application Data\Leadertech
2007-11-10 23:28 d-------- C:\Documents and Settings\marci\Application Data\Sonic
2007-11-10 23:28 d-------- C:\Documents and Settings\marci\Application Data\Leadertech
2007-11-10 21:57 d---s---- C:\Documents and Settings\greg\UserData
2007-11-10 15:32 d-------- C:\Program Files\MSXML 4.0
2007-11-10 15:30 d-------- C:\Documents and Settings\marci\Application Data\HP
2007-11-10 14:30 d-------- C:\Documents and Settings\greg\Application Data\MySpace
2007-11-10 11:51 23,040 --------- C:\WINDOWS\kb913800.exe
2007-11-10 11:50 d-------- C:\Documents and Settings\All Users\Application Data\Yahoo!
2007-11-10 11:48 d-------- C:\Program Files\Yahoo!
2007-11-09 22:27 d-------- C:\Program Files\MySpace
2007-11-09 22:27 d-------- C:\Documents and Settings\marci\Application Data\MySpace
2007-11-09 09:10 d--hs---- C:\Documents and Settings\marci\UserData
2007-11-09 09:03 d-------- C:\Documents and Settings\greg\Shared
2007-11-09 09:03 d-------- C:\Documents and Settings\greg\Incomplete
2007-11-09 09:03 d-------- C:\Documents and Settings\greg\Application Data\FrostWire
2007-11-09 09:01 d-------- C:\Documents and Settings\greg\WINDOWS
2007-11-09 09:01 d-------- C:\Documents and Settings\greg\Application Data\Symantec
2007-11-09 09:01 d-------- C:\Documents and Settings\greg\Application Data\Intuit
2007-11-09 09:01 d-------- C:\Documents and Settings\greg\Application Data\Digital Interactive Systems Corporation
2007-11-09 08:58 d-------- C:\Documents and Settings\marci\Shared
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((( snapshot@2007-11-25_12.26.18.40 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-11-25 19:05:45 26,624 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Accessibility\d6652cfc7f6018eed9f5af0ab54a5fbd\Accessibility.ni.dll
+ 2007-11-25 19:05:49 888,832 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\092bf3cc8044d2d907d217ddadaee5bf\AspNetMMCExt.ni.dll
+ 2007-11-25 19:05:50 237,568 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\e916794475f60f6fdeda5abc582ab0e0\CustomMarshalers.ni.dll
+ 2007-11-25 19:05:49 15,360 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\dfsvc\b287592c089a5c567ff52af8c9bbfd3f\dfsvc.ni.exe
+ 2007-11-25 19:05:52 880,640 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\a332a2f7f965beb9f3b2661c5b7b7920\Microsoft.Build.Engine.ni.dll
+ 2007-11-25 19:05:52 81,920 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\4f35fff09ced0739ec67374b29ca257c\Microsoft.Build.Framework.ni.dll
+ 2007-11-25 19:05:56 1,687,552 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\40c449b85be08f74666e578de70723b7\Microsoft.Build.Tasks.ni.dll
+ 2007-11-25 19:05:56 163,840 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\2892e08fb3b2dd93f88db30da4437a9f\Microsoft.Build.Utilities.ni.dll
+ 2007-11-25 19:06:00 1,720,320 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\25e198cac97b29d08c492bc5388a9fec\Microsoft.VisualBasic.ni.dll
+ 2007-11-25 19:06:01 1,003,520 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\54f291b3d674c2ea212a9244f3ba9fbd\System.Configuration.ni.dll
+ 2007-11-25 19:06:03 1,724,416 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Deployment\8b1086c976b2577a95e0e7f113caf7bf\System.Deployment.ni.dll
+ 2007-11-25 19:06:05 1,216,512 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\046eec3d74cec4cd460ff7c1842d257e\System.DirectoryServices.ni.dll
+ 2007-11-25 19:06:06 512,000 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\5449046c90901704a120252427a00033\System.DirectoryServices.Protocols.ni.dll
+ 2007-11-25 19:06:07 659,456 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\a50404715d38a9b2035dcac4d5fbf9c8\System.EnterpriseServices.ni.dll
+ 2007-11-25 19:06:07 294,912 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\a50404715d38a9b2035dcac4d5fbf9c8\System.EnterpriseServices.Wrapper.dll
+ 2007-11-25 19:06:09 729,088 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Security\8962db3b03601d2c02f3836f1e523170\System.Security.ni.dll
+ 2007-11-25 19:06:10 684,032 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Transactions\610351fe2a8d287c009a958ac852e2d0\System.Transactions.ni.dll
+ 2007-11-25 19:06:32 2,306,048 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\ab2958c06dce21c6cc3515068671c3a9\System.Web.Mobile.ni.dll
+ 2007-11-25 19:06:33 237,568 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\bede7399f09b947c9c27f702bfff7c7a\System.Web.RegularExpressions.ni.dll
+ 2007-11-25 19:06:36 1,941,504 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web.Services\0c492219b15640ed399b978141942e54\System.Web.Services.ni.dll
+ 2007-11-25 19:06:29 12,185,600 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\7a66b932276b50c95261a636d7a51f34\System.Web.ni.dll
+ 2003-12-08 17:18:00 413,696 ----a-w C:\WINDOWS\system32\A Christmas Tree.scr
- 2007-11-25 16:16:06 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2007-11-27 01:02:31 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2007-11-25 16:16:06 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2007-11-27 01:02:31 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2007-11-25 16:16:06 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2007-11-27 01:02:31 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 07:00]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-08-13 19:04]
"DW4"="C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe" [2007-03-16 07:51]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 17:43]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 23:56]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-03 02:19 C:\WINDOWS\arpwrmsg.exe]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-08 03:07 C:\WINDOWS\system32\HdAShCut.exe]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-07-19 13:06]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-07-19 13:10]
"HPHUPD08"="c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-02 01:35]
"PCDrProfiler"="" []
"HPBootOp"="C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-09-21 12:41]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPwuSchd2.exe" [2005-05-12 09:12]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-11-17 08:43]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-10-19 20:16]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-08-03 22:33]
"SiteAdvisor"="C:\Program Files\SiteAdvisor\6172\SiteAdv.exe" [2007-08-24 16:57]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-08-13 19:04]
C:\Documents and Settings\Default User\Start Menu\Programs\Startup\
Pin.lnk - C:\hp\bin\CLOAKER.EXE [2005-11-17 08:03:54]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-12 09:23:26]
Updates from HP.lnk - C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe [2005-11-17 09:03:02]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[hklm\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
S4 0312811195683926mcinstcleanup;McAfee Application Installer Cleanup (0312811195683926);C:\WINDOWS\TEMP\031281~1.EXE C:\PROGRA~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service
.
Contents of the 'Scheduled Tasks' folder
"2007-11-05 02:30:00 C:\WINDOWS\Tasks\Easy Internet Sign-up.job"
- C:\Program Files\Hewlett-Packard\SDP\HPSdpApp.exe
"2007-11-17 02:38:55 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe
"2007-11-17 02:38:53 C:\WINDOWS\Tasks\McQcTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe
"2007-11-09 04:55:52 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************
catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-26 21:22:59
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-26 21:24:01
C:\ComboFix2.txt ... 2007-11-25 12:26
.
--- E O F ---