Both files were run... Here are thier logs. Thanks for the help!
ComboFix 08-06-20.4 - Kevin 2008-06-29 21:10:04.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.406 [GMT -4:00]
Running from: E:\Documents and Settings\Kevin\Desktop\ComboFix.exe
Command switches used :: E:\Documents and Settings\Kevin\Desktop\WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
E:\WINDOWS\BM9777dec1.xml
E:\WINDOWS\cookies.ini
E:\WINDOWS\pskt.ini
E:\WINDOWS\system\smvss.exe
E:\WINDOWS\system32\cbXRICut.dll
E:\WINDOWS\system32\cwxoqwrv.ini
E:\WINDOWS\system32\dcnmslkf.ini
E:\WINDOWS\system32\ddcBTklI.dll
E:\WINDOWS\system32\euybajuv.ini
E:\WINDOWS\system32\ifljabsb.ini
E:\WINDOWS\system32\IlkTBcdd.ini
E:\WINDOWS\system32\IlkTBcdd.ini2
E:\WINDOWS\system32\rugvqhag.ini
E:\WINDOWS\system32\rwhnplum.ini
K:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_IPRIP
-------\Service_Iprip
((((((((((((((((((((((((( Files Created from 2008-05-28 to 2008-06-30 )))))))))))))))))))))))))))))))
.
2008-06-29 21:14 . 2008-06-29 21:14 294 ---hs---- E:\WINDOWS\system32\dcnmslkf.ini
2008-06-29 21:14 . 2008-06-29 21:14 22 --a------ E:\WINDOWS\pskt.ini
2008-06-29 21:13 . 2008-06-29 21:13 0 --a------ E:\WINDOWS\BM9777dec1.xml
2008-06-29 21:00 . 2008-06-28 03:49 <DIR> d-------- E:\SDFix
2008-06-29 13:02 . 2008-06-29 13:02 54,156 --ah----- E:\WINDOWS\QTFont.qfn
2008-06-29 13:02 . 2008-06-29 13:02 1,409 --a------ E:\WINDOWS\QTFont.for
2008-06-29 12:27 . 2008-06-29 12:27 103,424 --a------ E:\WINDOWS\system32\wbmucb.dll
2008-06-29 12:27 . 2008-06-29 12:27 103,424 --a------ E:\WINDOWS\system32\ncynqwec.dll
2008-06-29 12:24 . 2008-06-29 12:24 82,432 --a------ E:\WINDOWS\system32\fklsmncd.dll
2008-06-29 12:22 . 2008-06-29 12:22 90,624 --a------ E:\WINDOWS\system32\bykgmleu.dll
2008-06-28 14:28 . 2008-06-28 14:28 <DIR> d-------- E:\Program Files\Trend Micro
2008-06-28 09:21 . 2008-06-28 09:21 103,424 --a------ E:\WINDOWS\system32\wcigqpbq.dll
2008-06-28 09:21 . 2008-06-28 09:21 103,424 --a------ E:\WINDOWS\system32\jesopc.dll
2008-06-28 09:16 . 2008-06-28 09:16 90,624 --a------ E:\WINDOWS\system32\gnopcfmd.dll
2008-06-24 21:43 . 2008-06-24 21:43 99,840 --a------ E:\WINDOWS\system32\nyuljxcv.dll
2008-06-20 22:00 . 2008-06-20 22:00 <DIR> d-------- E:\Program Files\Lavasoft
2008-06-20 22:00 . 2008-06-20 22:00 <DIR> d-------- E:\Program Files\Common Files\Wise Installation Wizard
2008-06-20 22:00 . 2008-06-20 22:00 <DIR> d-------- E:\Documents and Settings\All Users\Application Data\Lavasoft
2008-06-17 20:48 . 2008-06-17 20:48 <DIR> d-------- E:\Program Files\Guitar Pro 5
2008-05-31 15:09 . 2008-05-31 15:09 <DIR> d-------- E:\Documents and Settings\All Users\Application Data\ATI
2008-05-29 21:37 . 2008-05-29 21:38 <DIR> d-------- E:\WINDOWS\system32\NtmsData
2008-05-27 21:40 . 2008-05-29 20:06 <DIR> d-------- E:\Program Files\Microsoft Money Plus
2008-05-18 13:11 . 2008-05-18 13:11 <DIR> d-------- E:\Program Files\iPod
2008-05-16 11:58 . 2008-05-16 11:58 12,632 --a------ E:\WINDOWS\system32\lsdelete.exe
2008-05-12 11:03 . 2008-05-12 11:03 19,968 --a------ E:\WINDOWS\system32\atiadlxx.dll
.
b]SDFix: Version 1.198 [/b]
Run by Kevin on Sun 06/29/2008 at 09:21 PM
Microsoft Windows XP [Version 5.1.2600]
Running From: E:\SDFix
Checking Services :
Restoring Default Security Values
Restoring Default Hosts File
Rebooting
Checking Files :
No Trojan Files Found
Removing Temp Files
ADS Check :
Final Check :
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-06-29 21:26:28
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\Vax347s\Config\jdgg40]
"ujdew"=hex:20,02,00,00,25,6d,6d,5d,57,9c,d6,17,1d ,70,f3,5d,9e,ab,34,a7,f1,..
"ljej40"=hex:f6,8e,28,b0,b2,2d,e5,29,58,e7,23,d3,6 1,57,6b,23,37,15,33,0b,26,..
"ljej41"=hex:2b,8e,28,b0,ca,2d,e5,29,59,e7,22,d3,6 0,57,6b,23,37,15,33,0b,e6,..
"ljej42"=hex:2b,8e,28,b0,ca,2d,e5,29,59,e7,22,d3,6 0,57,6b,23,37,15,33,0b,e6,..
"ljej43"=hex:2b,8e,28,b0,ca,2d,e5,29,59,e7,22,d3,6 0,57,6b,23,37,15,33,0b,e6,..
"ljej44"=hex:2b,8e,28,b0,ca,2d,e5,29,59,e7,22,d3,6 0,57,6b,23,37,15,33,0b,e6,..
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\{E9F81423-211E-46B6-9AE0-38568BC5CF6F}]
"DisplayName"="Alcohol 120%"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher]
"TracesProcessed"=dword:0000004d
"TracesSuccessful"=dword:00000004
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services :
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\servic es\sharedaccess\parameters\firewallpolicy\standard profile\authorizedapplications\list]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\\system32\\sessmgr.exe"="%windir%\\syste m32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"E:\\Program Files\\Music\\BitTorrent\\bittorrent.exe"="E:\\Pro gram Files\\Music\\BitTorrent\\bittorrent.exe:*:Enabled :BitTorrent"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\servic es\sharedaccess\parameters\firewallpolicy\domainpr ofile\authorizedapplications\list]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\\system32\\sessmgr.exe"="%windir%\\syste m32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
Remaining Files :
Files with Hidden Attributes :
Thu 23 Aug 2001 10,912 A.SH. --- "E:\WINDOWS\system32\Proxy.Dll"
Sat 10 Nov 2007 4,348 A.SH. --- "E:\Documents and Settings\All Users\DRM\DRMv1.bak"
Mon 20 Aug 2007 0 A.SH. --- "E:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Tue 6 May 2008 0 A..H. --- "E:\WINDOWS\SoftwareDistribution\Download\fd026484 9c01086f3c6b505dc02dbd44\BIT3.tmp"
Tue 8 May 2007 4,348 A..H. --- "E:\Documents and Settings\Kevin\My Documents\My Music\License Backup\drmv1key.bak"
Tue 8 May 2007 20 A..H. --- "E:\Documents and Settings\Kevin\My Documents\My Music\License Backup\drmv1lic.bak"
Tue 8 May 2007 9,655 A.SH. --- "E:\Documents and Settings\Kevin\My Documents\My Music\License Backup\drmv2key.bak"
Finished!