O.K. I ran combofix and hijackthis. Here are the logs:
ComboFix 08-02-20.2 - Marty 2008-02-20 8:56:39.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.52 [GMT -5:00]
Running from: C:\Documents and Settings\Marty\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\ddabc.dll
C:\Documents and Settings\LocalService\Application Data\NetMon
C:\Documents and Settings\LocalService\Application Data\NetMon\domains.txt
C:\Documents and Settings\LocalService\Application Data\NetMon\log.txt
C:\Documents and Settings\Marty\Application Data\STEM32~1
C:\Documents and Settings\Marty\Application Data\STEM32~1\??stem32\
C:\Documents and Settings\Marty\Start Menu\Programs\Internet Speed Monitor
C:\Documents and Settings\Marty\Start Menu\Programs\Internet Speed Monitor\Check Now.lnk
C:\Documents and Settings\Marty\Start Menu\Programs\Internet Speed Monitor\Uninstall.lnk
C:\Documents and Settings\NetworkService\Application Data\NetMon
C:\Documents and Settings\NetworkService\Application Data\NetMon\domains.txt
C:\Documents and Settings\NetworkService\Application Data\NetMon\log.txt
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\agomkjhu.dll
C:\WINDOWS\system32\bbdlgkit.dll
C:\WINDOWS\system32\bdfnffwl.dll
C:\WINDOWS\system32\bmmmmmms.ini
C:\WINDOWS\system32\bszip.dll
C:\WINDOWS\system32\cbadd.ini
C:\WINDOWS\system32\cbadd.ini2
C:\WINDOWS\system32\ddabc.dll
C:\WINDOWS\system32\dgbcxlgu.dll
C:\WINDOWS\system32\drivers\fad.sys
C:\WINDOWS\system32\fjxqkalx.dll
C:\WINDOWS\system32\kcaqcghf.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\onnnupjq.ini
C:\WINDOWS\system32\racle~1
C:\WINDOWS\system32\uglxcbgd.ini
C:\WINDOWS\system32\xcogebof.ini
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_DOMAINSERVICE
-------\DomainService
((((((((((((((((((((((((( Files Created from 2008-01-20 to 2008-02-20 )))))))))))))))))))))))))))))))
.
2008-02-17 23:40 . 2008-02-17 23:40 15,360 --a------ C:\WINDOWS\system32\ctfmon .exe
2008-02-17 23:38 . 2008-02-17 23:38 <DIR> d-------- C:\Program Files\MSXML 6.0
2008-02-17 23:34 . 2008-02-17 23:34 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2008-02-17 23:25 . 2008-02-17 23:25 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2008-02-17 23:25 . 2008-02-17 23:31 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2008-02-17 22:48 . 2007-12-06 21:21 6,066,176 --------- C:\WINDOWS\system32\dllcache\ieframe.dll
2008-02-17 22:48 . 2007-06-30 22:31 2,455,488 --------- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-02-17 22:48 . 2007-06-30 22:36 991,232 --------- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-02-17 22:48 . 2007-12-06 21:21 459,264 --------- C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-02-17 22:48 . 2007-12-06 21:21 383,488 --------- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-02-17 22:48 . 2007-12-06 21:21 267,776 --------- C:\WINDOWS\system32\dllcache\iertutil.dll
2008-02-17 22:48 . 2007-12-06 21:21 63,488 --------- C:\WINDOWS\system32\dllcache\icardie.dll
2008-02-17 22:48 . 2007-12-06 21:21 52,224 --------- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-02-17 22:48 . 2007-12-06 06:00 13,824 --------- C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-02-17 10:30 . 2008-02-17 10:30 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-02-16 18:19 . 2007-07-09 08:09 584,192 --------- C:\WINDOWS\system32\dllcache\rpcrt4.dll
2008-02-16 18:11 . 2008-02-18 01:37 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2008-02-16 18:11 . 2008-02-17 23:50 30,590 --a------ C:\WINDOWS\system32\pavas.ico
2008-02-16 18:11 . 2008-02-17 23:50 2,550 --a------ C:\WINDOWS\system32\Uninstall.ico
2008-02-16 18:11 . 2008-02-17 23:50 1,406 --a------ C:\WINDOWS\system32\Help.ico
2008-02-16 16:42 . 2008-02-16 16:42 <DIR> d-------- C:\Documents and Settings\Marty\Application Data\Grisoft
2008-02-16 16:42 . 2008-02-16 16:42 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-16 16:42 . 2007-05-30 07:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-02-14 18:13 . 2004-08-04 00:56 21,504 --a------ C:\WINDOWS\system32\hidserv.dll
2008-02-14 18:13 . 2004-08-03 22:58 14,848 --a------ C:\WINDOWS\system32\drivers\kbdhid.sys
2008-02-14 18:12 . 2004-08-03 23:08 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2008-02-14 13:43 . 2007-03-08 10:36 577,536 --a------ C:\WINDOWS\system32\dllcache\user32.dll
2008-02-14 13:41 . 2008-02-14 13:41 <DIR> d-------- C:\WINDOWS\ERUNT
2008-02-13 17:16 . 2008-02-18 00:00 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-02-13 17:16 . 2008-02-13 17:16 <DIR> d-------- C:\Documents and Settings\Marty\Application Data\SUPERAntiSpyware.com
2008-02-13 17:16 . 2008-02-13 17:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-02-13 17:15 . 2008-02-13 17:15 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-02-13 10:03 . 2008-02-17 22:39 <DIR> d-------- C:\VundoFix Backups
2008-02-11 13:30 . 2008-02-11 13:33 4,792 --a------ C:\WINDOWS\system32\tmp.reg
2008-02-11 13:27 . 2005-07-17 10:41 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Symantec
2008-02-11 13:27 . 2005-07-17 10:31 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Jasc Software Inc
2008-02-11 13:27 . 2005-07-17 10:31 <DIR> d--h----- C:\Documents and Settings\Administrator\Application Data\Gtek
2008-02-11 13:16 . 2008-02-19 21:35 <DIR> d-------- C:\hijack
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-17 08:28 --------- d-----w C:\Program Files\iTunes
2008-02-15 02:40 --------- d-----w C:\Program Files\Symantec
2008-02-14 23:29 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-02-13 21:02 --------- d-----w C:\Program Files\RcvSystem
2008-02-13 14:03 --------- d-----w C:\Program Files\Dell Support
2008-01-21 16:02 --------- d-----w C:\Program Files\QuickTime
2008-01-04 20:51 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee
2008-01-04 20:49 --------- d-----w C:\Program Files\McAfee
2008-01-04 20:49 --------- d-----w C:\Program Files\Common Files\Cisco Systems
2008-01-04 20:44 --------- d-----w C:\Program Files\Common Files\McAfee
2008-01-04 12:29 --------- d-----w C:\Program Files\MUSICMATCH
2007-12-26 14:50 --------- d-----w C:\Program Files\iPod
2007-12-26 14:50 --------- d-----w C:\Documents and Settings\Marty\Application Data\Apple Computer
2007-12-26 14:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-12-26 14:47 --------- d-----w C:\Program Files\Apple Software Update
2007-12-26 14:46 --------- d-----w C:\Program Files\Common Files\Apple
2007-12-26 14:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
.
<pre>
----a-w 1,404,928 2008-02-13 18:03:48 C:\Program Files\Analog Devices\Core\smax4pnp .exe
----a-w 81,920 2008-02-13 18:04:28 C:\Program Files\Common Files\InstallShield\UpdateService\issch .exe
----a-w 221,184 2008-02-13 18:03:55 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe
----a-w 218,240 2008-01-05 21:26:42 C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt .exe
----a-w 86,016 2008-02-11 18:43:11 C:\Program Files\Dell\Media Experience\DMXLauncher .exe
----a-w 306,688 2008-02-13 13:59:39 C:\Program Files\Dell Support\DSAgnt .exe
----a-w 49,152 2008-02-13 15:46:07 C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd .exe
----a-w 233,472 2008-02-11 18:43:17 C:\Program Files\HP\hpcoretech\hpcmpmgr .exe
----a-w 221,184 2008-02-13 18:03:49 C:\Program Files\Intel\Modem Event Monitor\IntelMEM .exe
----a-w 267,048 2008-02-16 21:38:20 C:\Program Files\iTunes\iTunesHelper .exe
----a-w 136,768 2008-02-13 15:46:15 C:\Program Files\McAfee\Common Framework\UdaterUI .exe
----a-w 112,216 2008-02-13 15:46:14 C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT .EXE
----a-w 1,694,208 2008-02-13 14:06:58 C:\Program Files\Messenger\msmsgs .exe
----a-w 53,248 2008-01-03 21:35:46 C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mmtask .exe
----a-w 286,720 2008-02-11 22:53:04 C:\Program Files\QuickTime\qttask .exe
----a-w 286,720 2008-02-11 22:53:05 C:\Program Files\QuickTime\qttask .exe
----a-w 286,720 2008-02-11 22:53:05 C:\Program Files\QuickTime\qttask .exe
----a-w 286,720 2008-02-11 22:53:06 C:\Program Files\QuickTime\qttask .exe
----a-w 286,720 2008-02-11 22:53:08 C:\Program Files\QuickTime\qttask .exe
----a-w 286,720 2008-02-11 22:53:09 C:\Program Files\QuickTime\qttask .exe
----a-w 286,720 2008-02-11 22:53:11 C:\Program Files\QuickTime\qttask .exe
----a-w 286,720 2008-02-11 22:53:12 C:\Program Files\QuickTime\qttask .exe
----a-w 286,720 2008-02-11 22:53:13 C:\Program Files\QuickTime\qttask .exe
----a-w 286,720 2008-02-11 22:53:13 C:\Program Files\QuickTime\qttask .exe
----a-w 286,720 2008-02-11 22:53:14 C:\Program Files\QuickTime\qttask .exe
----a-w 286,720 2008-02-11 22:53:14 C:\Program Files\QuickTime\qttask .exe
----a-w 286,720 2008-02-11 22:53:15 C:\Program Files\QuickTime\qttask .exe
----a-w 286,720 2008-02-11 22:53:15 C:\Program Files\QuickTime\qttask .exe
----a-w 286,720 2008-02-11 22:53:16 C:\Program Files\QuickTime\qttask .exe
----a-w 286,720 2008-02-11 22:53:16 C:\Program Files\QuickTime\qttask .exe
----a-w 286,720 2008-02-11 22:53:16 C:\Program Files\QuickTime\qttask .exe
----a-w 286,720 2008-02-11 22:53:17 C:\Program Files\QuickTime\qttask .exe
----a-w 26,112 2008-02-11 18:43:00 C:\Program Files\Real\RealPlayer\RealPlay .exe
----a-w 15,360 2008-02-18 04:40:59 C:\WINDOWS\system32\ctfmon .exe
----a-w 126,976 2008-02-11 18:42:47 C:\WINDOWS\system32\hkcmd .exe
----a-w 155,648 2008-02-11 21:46:25 C:\WINDOWS\system32\igfxtray .exe
----a-w 127,035 2008-02-11 21:46:31 C:\WINDOWS\system32\dla\tfswctrl .exe
----a-w 176,128 2008-02-11 21:46:52 C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09 .exe
</pre>
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="C:\Program Files\Dell Support\DSAgnt.exe" [ ]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [ ]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [ ]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-02-20 08:51 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [ ]
"IntelMeM"="C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe" [ ]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [ ]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [ ]
"HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe" [ ]
"ShStatEXE"="C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.exe" [2008-02-20 09:02 112216]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas .exe" [ ]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [2000-01-21 03:15:54 65588]
QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2004-11-11 11:59:36 806912]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
.
Contents of the 'Scheduled Tasks' folder
"2008-02-13 15:14:58 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-02-20 09:09:05
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
C:\Program Files\McAfee\Common Framework\naPrdMgr.exe
C:\WINDOWS\system32\fxssvc.exe
.
**************************************************************************
.
Completion time: 2008-02-20 9:13:53 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-20 14:13:43
.
2008-02-20 02:40:07 --- E O F ---
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:17:41 AM, on 2/20/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\explorer.exe
C:\hijack\Lemon Head.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.accuweath...0...&traveler=0O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas .exe" /minimized
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoft...free/asinst.cabO20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
--
End of file - 3818 bytes