Here are the results for the Vundo Fix:
C:\windows\system32\ljjgfdb.dll
Here is part one results for the combo-fix:
ComboFix 08-03-10.1 - Thomas Family 2008-03-10 16:37:25.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1526 [GMT -7:00]
Running from: C:\Documents and Settings\Thomas Family\My Documents\Downloads\Combo-Fix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\LocalService\Application Data\NetMon
C:\Documents and Settings\LocalService\Application Data\NetMon\domains.txt
C:\Documents and Settings\LocalService\Application Data\NetMon\log.txt
C:\Program Files\network monitor
C:\Program Files\outlook
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\Temp\sanR24
C:\Temp\sanR24\lDii.log
C:\temp\tn3
C:\WINDOWS\b.exe
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\bahwjpci.dll
C:\WINDOWS\system32\bszip.dll
C:\WINDOWS\system32\cmd.com
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\drivers\tdii.sys
C:\WINDOWS\system32\exxocvkk.dll
C:\WINDOWS\system32\ljjgfdb.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\netstat.com
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\ping.com
C:\WINDOWS\system32\qqtss.ini
C:\WINDOWS\system32\qqtss.ini2
C:\WINDOWS\system32\regedit.com
C:\WINDOWS\system32\sstqq.dll
C:\WINDOWS\system32\taskkill.com
C:\WINDOWS\system32\tasklist.com
C:\WINDOWS\system32\tracert.com
C:\winlogon.exe
C:\x.dat
C:\z.dat
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_CMDSERVICE
-------\LEGACY_NETWORK_MONITOR
-------\LEGACY_TDII
-------\Network Monitor
-------\tdii
((((((((((((((((((((((((( Files Created from 2008-02-10 to 2008-03-10 )))))))))))))))))))))))))))))))
.
2008-03-10 16:18 . 2008-03-10 16:26 <DIR> d-------- C:\VundoFix Backups
2008-03-08 17:54 . 2006-10-04 07:06 1,197,294 --------- C:\WINDOWS\system32\dllcache\sysmain.sdb
2008-03-08 17:54 . 2006-10-04 07:06 764,868 --------- C:\WINDOWS\system32\dllcache\apph_sp.sdb
2008-03-08 17:54 . 2006-10-04 07:06 217,118 --------- C:\WINDOWS\system32\dllcache\apphelp.sdb
2008-03-08 17:53 . 2008-03-08 17:53 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2008-03-08 17:51 . 2008-03-08 17:51 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2008-03-08 17:51 . 2008-03-08 17:52 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2008-03-08 13:03 . 2008-03-08 13:03 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-03-08 13:00 . 2008-03-10 08:00 <DIR> d-------- C:\Documents and Settings\Thomas Family\Application Data\AVG7
2008-03-08 13:00 . 2008-03-08 16:14 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg7
2008-03-08 13:00 . 2008-03-08 13:00 110,592 --a------ C:\WINDOWS\system32\avgfwafu.dll
2008-03-08 12:55 . 2008-03-08 12:55 <DIR> d-------- C:\Documents and Settings\Thomas Family\Application Data\Grisoft
2008-03-08 12:54 . 2008-03-08 12:54 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-03-08 12:54 . 2007-05-30 05:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-03-08 11:35 . 2008-03-08 11:35 <DIR> d-------- C:\Program Files\Live_TV
2008-03-08 11:19 . 2008-03-08 11:19 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\Yahoo!
2008-03-08 11:09 . 2008-03-08 11:09 134 --a------ C:\n.bat
2008-03-08 11:08 . 2008-03-08 11:08 <DIR> d-------- C:\WINDOWS\system32\typ2
2008-03-08 11:08 . 2008-03-08 11:21 <DIR> d-------- C:\WINDOWS\system32\sbc2
2008-03-08 11:08 . 2008-03-08 11:08 <DIR> d-------- C:\WINDOWS\system32\lows8
2008-03-08 11:08 . 2008-03-09 11:33 <DIR> d-------- C:\WINDOWS\system32\iDlo18
2008-03-08 11:08 . 2008-03-09 11:33 <DIR> d-------- C:\WINDOWS\system32\ech5
2008-03-08 11:08 . 2008-03-09 11:33 <DIR> d-------- C:\WINDOWS\system32\dr6
2008-03-08 11:08 . 2008-03-10 16:37 <DIR> d-------- C:\Temp
2008-03-08 10:31 . 2008-03-08 16:15 <DIR> d-------- C:\Documents and Settings\Thomas Family\Shared
2008-03-05 09:01 . 2008-03-05 09:01 <DIR> d-------- C:\Program Files\Microsoft Reader
2008-03-05 09:01 . 2007-01-30 16:06 60,944 --a------ C:\WINDOWS\DASShp.dll
2008-03-01 17:41 . 2008-03-01 17:41 <DIR> d-------- C:\Program Files\Project64 1.6
2008-02-28 16:33 . 2008-02-28 16:33 <DIR> d-------- C:\WINDOWS\Sun
2008-02-23 01:08 . 2008-02-23 01:08 <DIR> d-------- C:\Documents and Settings\Thomas Family\Application Data\Yahoo!
2008-02-23 01:08 . 2008-02-23 01:08 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-02-23 01:06 . 2008-02-23 01:06 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-02-23 00:32 . 2008-02-23 00:32 <DIR> d-------- C:\Documents and Settings\Thomas Family\Application Data\HP
2008-02-23 00:23 . 2008-02-23 00:23 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\HP
2008-02-23 00:21 . 2008-02-23 00:21 <DIR> d-------- C:\Program Files\Common Files\HP
2008-02-23 00:19 . 2008-02-23 00:19 <DIR> d-------- C:\Program Files\Hewlett-Packard
2008-02-23 00:18 . 2008-02-23 00:18 <DIR> d-------- C:\Program Files\Common Files\Hewlett-Packard
2008-02-23 00:15 . 2005-03-22 05:48 77,824 -ra------ C:\WINDOWS\system32\hpzids01.dll
2008-02-23 00:15 . 2005-10-27 17:24 49,664 -ra------ C:\WINDOWS\system32\drivers\HPZid412.sys
2008-02-23 00:15 . 2005-10-14 23:42 46,592 --a------ C:\WINDOWS\system32\hpzll43a.dll
2008-02-23 00:15 . 2005-10-27 17:24 16,496 -ra------ C:\WINDOWS\system32\drivers\HPZipr12.sys
2008-02-23 00:15 . 2004-08-03 23:58 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2008-02-23 00:15 . 2004-08-03 23:58 15,104 --a------ C:\WINDOWS\system32\dllcache\usbscan.sys
2008-02-23 00:14 . 2005-03-14 13:03 278,584 --a------ C:\WINDOWS\system32\HPZidr12.dll
2008-02-23 00:14 . 2005-03-14 13:05 204,800 --a------ C:\WINDOWS\system32\HPZipr12.dll
2008-02-23 00:14 . 2005-03-08 12:55 94,208 --a------ C:\WINDOWS\system32\HPZipt12.dll
2008-02-23 00:14 . 2005-03-14 13:05 69,632 --a------ C:\WINDOWS\system32\HPZipm12.exe
2008-02-23 00:14 . 2005-03-14 14:39 65,536 --a------ C:\WINDOWS\system32\HPZinw12.exe
2008-02-23 00:14 . 2005-03-08 12:55 57,344 --a------ C:\WINDOWS\system32\HPZisn12.dll
2008-02-23 00:13 . 2008-02-23 00:19 <DIR> d-------- C:\Program Files\HP
2008-02-23 00:13 . 2004-08-04 00:08 26,496 --a------ C:\WINDOWS\system32\dllcache\usbstor.sys
2008-02-23 00:11 . 2008-02-23 00:31 109,191 --a------ C:\WINDOWS\hpoins08.dat
2008-02-23 00:11 . 2006-01-24 00:11 7,577 --------- C:\WINDOWS\hpomdl08.dat
2008-02-23 00:01 . 2004-08-04 00:01 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2008-02-23 00:01 . 2004-08-04 00:01 25,856 --a------ C:\WINDOWS\system32\dllcache\usbprint.sys
2008-02-13 17:15 . 2008-03-04 17:16 20,480 --a------ C:\WINDOWS\system32\H@tKeysH@@k.DLL
2008-02-13 17:13 . 2008-02-13 17:13 <DIR> d-------- C:\Program Files\WinAce
2008-02-10 17:49 . 2008-02-10 17:49 <DIR> d--h----- C:\Documents and Settings\All Users\Application Data\{0E8E33D8-193A-414A-A909-0F101A142D26}
2008-02-10 17:37 . 2008-02-10 17:37 <DIR> d-------- C:\Program Files\Stardock Games
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-09 16:57 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-09 16:57 --------- d-----w C:\Program Files\Dell
2008-03-09 16:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\CyberLink
2008-03-05 16:00 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-02-24 01:57 --------- d-----w C:\Documents and Settings\Thomas Family\Application Data\Roxio
2008-02-23 08:06 --------- d-----w C:\Program Files\Yahoo!
2008-02-23 07:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\Sonic
2008-02-07 07:24 --------- d-----w C:\Documents and Settings\Thomas Family\Application Data\CyberLink
2008-02-07 07:16 --------- d-----w C:\Program Files\Microsoft ActiveSync
2008-02-07 03:32 --------- d--h--r C:\Documents and Settings\Thomas Family\Application Data\SecuROM
2008-02-07 03:21 --------- d-----w C:\Program Files\Sierra Entertainment
2008-02-07 02:58 --------- d-----w C:\Program Files\Microsoft Games
2008-02-07 02:46 --------- d-----w C:\Program Files\Ground Control II
2008-02-06 06:44 --------- d-----w C:\Documents and Settings\Thomas Family\Application Data\EVEMon
2008-02-05 20:39 --------- d-----w C:\Program Files\MSXML 4.0
2008-02-05 14:00 --------- d-----w C:\Program Files\Google
2008-02-05 02:21 --------- d-----w C:\Program Files\Executive Software
2008-02-05 02:21 --------- d-----w C:\Documents and Settings\Thomas Family\Application Data\Leadertech
2008-02-05 01:58 --------- d-----w C:\Program Files\Stardock
2008-02-05 00:51 --------- d-----w C:\Documents and Settings\All Users\Application Data\nView_Profiles
2008-01-30 00:29 --------- d-----w C:\WINDOWS\system32\config\systemprofile\Application Data\Roxio
2008-01-30 00:29 --------- d-----w C:\Documents and Settings\LocalService\Application Data\Roxio
2008-01-30 00:29 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Roxio
2008-01-30 00:26 --------- d-----w C:\Program Files\Microsoft Plus! Photo Story 2 LE
2008-01-30 00:26 --------- d-----w C:\Program Files\Microsoft Plus! Digital Media Edition
2008-01-30 00:25 --------- d-----w C:\Program Files\MUSICMATCH
2008-01-30 00:24 --------- d-----w C:\Program Files\Dell Support Center
2008-01-30 00:24 --------- d-----w C:\Program Files\Common Files\supportsoft
2008-01-30 00:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\SupportSoft
2008-01-30 00:22 --------- d-----w C:\Program Files\Common Files\Adobe
2008-01-30 00:21 --------- d-----w C:\Program Files\Dell DataSafe Online
2008-01-30 00:20 --------- d-----w C:\Program Files\Roxio
2008-01-30 00:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\Roxio
2008-01-30 00:15 --------- d-----w C:\Program Files\Common Files\SureThing Shared
2008-01-30 00:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\InstallShield
2008-01-30 00:14 --------- d-----w C:\Program Files\Common Files\Sonic Shared
2008-01-30 00:14 --------- d-----w C:\Program Files\Common Files\Roxio Shared
2008-01-30 00:13 --------- d-----w C:\Program Files\Sigmatel
2008-01-30 00:09 --------- d-----w C:\Program Files\Logitech
2008-01-30 00:09 --------- d-----w C:\Program Files\Common Files\Logitech
2008-01-30 00:09 --------- d-----w C:\Program Files\AGEIA Technologies
2008-01-30 00:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\Dell
2008-01-30 00:07 --------- d-----w C:\WINDOWS\system32\config\systemprofile\Application Data\InstallShield
2008-01-30 00:07 --------- d-----w C:\Program Files\Creative Live! Cam
2008-01-30 00:07 --------- d-----w C:\Program Files\Creative
2008-01-30 00:07 --------- d-----w C:\Program Files\Common Files\Reallusion
2008-01-30 00:07 --------- d-----w C:\Program Files\Common Files\Creative
2008-01-30 00:07 --------- d-----w C:\Documents and Settings\Thomas Family\Application Data\InstallShield
2008-01-30 00:07 --------- d-----w C:\Documents and Settings\Administrator\Application Data\InstallShield
2008-01-30 00:06 21,393 ----a-w C:\WINDOWS\system32\drivers\AegisP.sys
2008-01-30 00:06 21,393 ----a-w C:\WINDOWS\AegisP.sys
2008-01-30 00:06 --------- d-----w C:\WINDOWS\system32\config\systemprofile\Application Data\Intel
2008-01-30 00:06 --------- d-----w C:\Program Files\Intel, Inc
2008-01-30 00:06 --------- d-----w C:\Documents and Settings\Thomas Family\Application Data\Intel
2008-01-30 00:06 --------- d-----w C:\Documents and Settings\NetworkService\Application Data\Intel
2008-01-30 00:06 --------- d-----w C:\Documents and Settings\LocalService\Application Data\Intel
2008-01-30 00:06 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Intel
2008-01-30 00:05 --------- d-----w C:\Program Files\Intel
2008-01-30 00:05 --------- d-----w C:\Documents and Settings\All Users\Application Data\Intel
2008-01-30 00:02 --------- d-----w C:\Program Files\Java
2008-01-30 00:01 --------- d-----w C:\Program Files\Common Files\Java
2008-01-29 23:59 --------- d-----w C:\Program Files\MSXML 6.0
2008-01-29 23:27 --------- d-----w C:\Program Files\Synaptics
2008-01-29 23:19 7,339 ----a-w C:\WINDOWS\system32\drivers\1028_Dell_XPS_M1730.mrk
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F19E9E26-0751-4211-8DFE-390E78FDF702}]
C:\Program Files\MSN\xucif89104.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 04:00 15360]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2007-08-30 18:43 4670704]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-11-05 17:43 8491008]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 02:25 6731312]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-03-08 13:00 579072]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-03-08 13:00 219136]
C:\Documents and Settings\Thomas Family\Start Menu\Programs\Startup\
Yahoo! Widgets.lnk - C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe [2007-12-11 15:34:48 3746856]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Intel PROSet Wireless.lnk - C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe [2007-07-25 15:30:36 974848]
Logitech LCD Manager.lnk - C:\WINDOWS\Installer\{F7511FE7-BA89-4939-B2EF-A3F287B0F298}\NewShortcut1.E8BD1F6A_63E9_4BC3_8DF5_1E24A65D44C8.exe [2008-01-29 17:09:26 22486]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 02:01:04 83360]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WB]
C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\fastload.dll 2001-12-20 23:34 24576 C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\fastload.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\xxywuss]
xxywuss.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=wbsys.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Sierra Entertainment\\World in Conflict\\wic.exe"=
"C:\\Program Files\\Sierra Entertainment\\World in Conflict\\wic_online.exe"=
"C:\\Program Files\\Sierra Entertainment\\World in Conflict\\wic_ds.exe"=
"C:\\Program Files\\Stardock Games\\Sins of a Solar Empire\\Sins of a Solar Empire.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\WINDOWS\\system32\\java.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=
R1 DLARTL_M;DLARTL_M;C:\WINDOWS\system32\Drivers\DLARTL_M.SYS [2006-08-11 09:35]
R3 DXEC02;DXEC02;C:\WINDOWS\system32\drivers\dxec02.sys [2006-11-02 11:31]
R3 OEM02Dev;Creative Camera OEM002 Driver;C:\WINDOWS\system32\DRIVERS\OEM02Dev.sys [2007-08-28 13:54]
R3 OEM02Vfx;Creative Camera OEM002 Video VFX Driver;C:\WINDOWS\system32\DRIVERS\OEM02Vfx.sys [2007-08-28 13:55]
R3 physX32;physX32;C:\WINDOWS\system32\DRIVERS\physX32.sys [2007-06-26 10:15]
S3 gAGP440p;gAGP440p;C:\DOCUME~1\THOMAS~1\LOCALS~1\Temp\gAGP440p.sys []
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-03-10 16:43:04
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Edited by Lost in cyber space, 10 March 2008 - 06:04 PM.