Thanks. Here are the 3 new reports.
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 12:38:52 PM 4/28/2007
+ Scan result:
:mozilla.65:C:\Documents and Settings\Jim\Application Data\Mozilla\Firefox\Profiles\a4c2sc75.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Jim\Cookies\jim@2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Jim\Cookies\
[email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.87:C:\Documents and Settings\Jim\Application Data\Mozilla\Firefox\Profiles\a4c2sc75.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.90:C:\Documents and Settings\Jim\Application Data\Mozilla\Firefox\Profiles\a4c2sc75.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.91:C:\Documents and Settings\Jim\Application Data\Mozilla\Firefox\Profiles\a4c2sc75.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.101:C:\Documents and Settings\Jim\Application Data\Mozilla\Firefox\Profiles\a4c2sc75.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.102:C:\Documents and Settings\Jim\Application Data\Mozilla\Firefox\Profiles\a4c2sc75.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.103:C:\Documents and Settings\Jim\Application Data\Mozilla\Firefox\Profiles\a4c2sc75.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.104:C:\Documents and Settings\Jim\Application Data\Mozilla\Firefox\Profiles\a4c2sc75.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\Jim\Cookies\jim@advertising[1].txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.30:C:\Documents and Settings\Jim\Application Data\Mozilla\Firefox\Profiles\a4c2sc75.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Jim\Cookies\jim@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Jim\Cookies\jim@cpvfeed[1].txt -> TrackingCookie.Cpvfeed : Cleaned.
:mozilla.23:C:\Documents and Settings\Jim\Application Data\Mozilla\Firefox\Profiles\a4c2sc75.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Jim\Cookies\jim@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Jim\Cookies\jim@fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\Jim\Cookies\jim@findwhat[1].txt -> TrackingCookie.Findwhat : Cleaned.
:mozilla.74:C:\Documents and Settings\Jim\Application Data\Mozilla\Firefox\Profiles\a4c2sc75.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.75:C:\Documents and Settings\Jim\Application Data\Mozilla\Firefox\Profiles\a4c2sc75.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.76:C:\Documents and Settings\Jim\Application Data\Mozilla\Firefox\Profiles\a4c2sc75.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.77:C:\Documents and Settings\Jim\Application Data\Mozilla\Firefox\Profiles\a4c2sc75.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.78:C:\Documents and Settings\Jim\Application Data\Mozilla\Firefox\Profiles\a4c2sc75.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.79:C:\Documents and Settings\Jim\Application Data\Mozilla\Firefox\Profiles\a4c2sc75.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Jim\Cookies\
[email protected][1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Jim\Cookies\jim@hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.83:C:\Documents and Settings\Jim\Application Data\Mozilla\Firefox\Profiles\a4c2sc75.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.84:C:\Documents and Settings\Jim\Application Data\Mozilla\Firefox\Profiles\a4c2sc75.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.51:C:\Documents and Settings\Jim\Application Data\Mozilla\Firefox\Profiles\a4c2sc75.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\Jim\Cookies\jim@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.24:C:\Documents and Settings\Jim\Application Data\Mozilla\Firefox\Profiles\a4c2sc75.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.26:C:\Documents and Settings\Jim\Application Data\Mozilla\Firefox\Profiles\a4c2sc75.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.27:C:\Documents and Settings\Jim\Application Data\Mozilla\Firefox\Profiles\a4c2sc75.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.46:C:\Documents and Settings\Jim\Application Data\Mozilla\Firefox\Profiles\a4c2sc75.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.47:C:\Documents and Settings\Jim\Application Data\Mozilla\Firefox\Profiles\a4c2sc75.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.48:C:\Documents and Settings\Jim\Application Data\Mozilla\Firefox\Profiles\a4c2sc75.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.49:C:\Documents and Settings\Jim\Application Data\Mozilla\Firefox\Profiles\a4c2sc75.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.50:C:\Documents and Settings\Jim\Application Data\Mozilla\Firefox\Profiles\a4c2sc75.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
C:\Documents and Settings\Jim\Cookies\
[email protected][2].txt -> TrackingCookie.Reliablestats : Cleaned.
C:\Documents and Settings\Jim\Cookies\jim@revsci[1].txt -> TrackingCookie.Revsci : Cleaned.
C:\Documents and Settings\Jim\Cookies\
[email protected][2].txt -> TrackingCookie.Webtrendslive : Cleaned.
C:\Documents and Settings\Jim\Cookies\
[email protected][2].txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.33:C:\Documents and Settings\Jim\Application Data\Mozilla\Firefox\Profiles\a4c2sc75.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.34:C:\Documents and Settings\Jim\Application Data\Mozilla\Firefox\Profiles\a4c2sc75.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.35:C:\Documents and Settings\Jim\Application Data\Mozilla\Firefox\Profiles\a4c2sc75.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.36:C:\Documents and Settings\Jim\Application Data\Mozilla\Firefox\Profiles\a4c2sc75.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.37:C:\Documents and Settings\Jim\Application Data\Mozilla\Firefox\Profiles\a4c2sc75.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
C:\Documents and Settings\Jim\Cookies\jim@zedo[2].txt -> TrackingCookie.Zedo : Cleaned.
::Report end
----------------------------------
Logfile of HijackThis v1.99.1
Scan saved at 12:54:43 PM, on 4/28/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\FSI\F-Prot\fpavupdm.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\wwSecure.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Jim\My Documents\hijackthis\crusty.exe
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [DLCCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.micros...b?1149542373703O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} -
http://acs.pandasoft...free/asinst.cabO20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Adaptec - (no file)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: dlcc_device - Unknown owner - C:\WINDOWS\system32\dlcccoms.exe
O23 - Service: F-Prot Antivirus Update Monitor - FRISK Software - C:\Program Files\FSI\F-Prot\fpavupdm.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: spkrmon - Unknown owner - C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
O23 - Service: Washer AutoComplete (wwSecSvc) - Webroot Software, Inc. - C:\WINDOWS\system32\wwSecure.exe
--------------------------------------------
"Jim" - 07-04-28 12:52:03 Service Pack 2
ComboFix 07-04-28.V - Running from: "C:\Documents and Settings\Jim\My Documents\"
(((((((((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\jdtccvlk.dll
C:\WINDOWS\system32\klvcctdj.ini
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\DOCUME~1\Jim\APPLIC~1\Dxcknwrd.dll
C:\WINDOWS\system32\bund1\ClientBundle1.exe
C:\WINDOWS\system32\bund1\temp.txt
C:\WINDOWS\system32\bund1
((((((((((((((((((((((((((((((( Files Created from 2007-03-28 to 2007-04-28 ))))))))))))))))))))))))))))))))))
2007-04-28 12:48 <DIR> d-------- C:\Program Files\Yahoo!
2007-04-28 12:48 <DIR> d-------- C:\Program Files\CCleaner
2007-04-28 12:43 <DIR> d-------- C:\!KillBox
2007-04-28 10:45 <DIR> d-------- C:\Deckard
2007-04-28 10:05 <DIR> d-------- C:\VundoFix Backups
2007-04-27 11:16 <DIR> d-------- C:\WINDOWS\SYSTEM32\ActiveScan
2007-04-26 17:09 317,952 -ra------ C:\WINDOWS\SYSTEM32\Roboex32.dll
2007-04-26 17:09 <DIR> d-------- C:\Program Files\Qualcomm
2007-04-26 16:40 53,248 --a------ C:\WINDOWS\SYSTEM32\Process.exe
2007-04-26 16:40 51,200 --a------ C:\WINDOWS\SYSTEM32\dumphive.exe
2007-04-26 16:40 288,417 --a------ C:\WINDOWS\SYSTEM32\SrchSTS.exe
2007-04-26 16:40 1,056 --a------ C:\WINDOWS\SYSTEM32\tmp.reg
2007-04-26 16:27 <DIR> d-------- C:\Program Files\Enigma Software Group
2007-04-25 18:31 <DIR> d-------- C:\WINDOWS\network diagnostic
2007-04-25 13:36 3,968 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\AvgAsCln.sys
2007-04-25 13:26 <DIR> d-------- C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Spybot - Search & Destroy
2007-04-25 12:58 12,289,999 --------- C:\AVG7QT.DAT
2007-04-25 09:48 <DIR> d-------- C:\Program Files\Lavasoft
2007-04-25 09:48 <DIR> d-------- C:\DOCUME~1\Jim\APPLIC~1\Lavasoft
2007-04-25 09:24 1 --a------ C:\WINDOWS\SYSTEM32\ps.dat
2007-04-24 16:19 8,464 --a------ C:\WINDOWS\SYSTEM32\sporder.dll
2007-04-24 16:19 <DIR> d-------- C:\WINDOWS\SYSTEM32\micro1
2007-04-24 16:19 <DIR> d-------- C:\temp\tn3
2007-04-22 12:22 <DIR> d-------- C:\Program Files\Nero
2007-04-22 10:34 <DIR> d-------- C:\Program Files\vso
2007-04-22 10:28 <DIR> d-------- C:\Program Files\DVD Shrink
2007-04-22 10:05 <DIR> d-------- C:\Program Files\Xilisoft
2007-04-22 09:38 506,744 --a------ C:\WINDOWS\SYSTEM32\SpoonUninstall.exe
2007-04-22 09:38 2,971 --a------ C:\WINDOWS\SYSTEM32\SpoonUninstall-dBpoweramp FLAC Codec.dat
2007-04-21 12:07 161,492 --a------ C:\WINDOWS\Audio Converter Pro Uninstaller.exe
2007-04-21 12:07 <DIR> d-------- C:\Program Files\River Past
2007-04-21 12:07 <DIR> d-------- C:\Program Files\Common Files\River Past
2007-04-20 15:15 <DIR> d-------- C:\WINDOWS\SYSTEM32\DRIVERS\myrmbin
2007-04-20 15:15 <DIR> d-------- C:\WINDOWS\SYSTEM32\DRIVERS\mycodec
2007-04-20 15:15 <DIR> d-------- C:\Program Files\MyVideoConverter
2007-04-20 10:37 765,952 --a------ C:\WINDOWS\SYSTEM32\xvidcore.dll
2007-04-20 10:37 180,224 --a------ C:\WINDOWS\SYSTEM32\xvidvfw.dll
2007-04-20 10:37 <DIR> d-------- C:\Program Files\Xvid
2007-04-15 16:41 516,096 --------- C:\WINDOWS\SYSTEM32\ati2sgag.exe
2007-04-15 16:40 <DIR> d-------- C:\Program Files\ATI Technologies
2007-04-08 10:09 <DIR> d-------- C:\Program Files\Maketorrent 2
2007-04-06 16:47 70,656 --a------ C:\WINDOWS\SYSTEM32\yv12vfw.dll
2007-04-06 16:47 70,656 --a------ C:\WINDOWS\SYSTEM32\i420vfw.dll
2007-04-06 16:47 66,560 --a------ C:\WINDOWS\MOTA113.exe
2007-04-06 16:47 502,784 --a------ C:\WINDOWS\x2.64.exe
2007-04-06 16:47 471,552 --a------ C:\WINDOWS\SYSTEM32\Smab.dll
2007-04-06 16:47 27,648 --a------ C:\WINDOWS\SYSTEM32\AVSredirect.dll
2007-04-06 16:47 240,128 --a------ C:\WINDOWS\SYSTEM32\x.264.exe
2007-04-06 16:47 217,073 --a------ C:\WINDOWS\meta4.exe
2007-04-03 18:51 <DIR> d-------- C:\778e8bd50256ffb259a76a16e32949fe
2007-04-03 18:43 14,048 --------- C:\WINDOWS\SYSTEM32\spmsg2.dll
2007-04-03 17:36 <DIR> d-------- C:\Program Files\Google
2007-04-03 17:36 <DIR> d-------- C:\DOCUME~1\Jim\APPLIC~1\Google
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-04-26 17:09 -------- d--h----- C:\Program Files\installshield installation information
2007-04-26 12:54 -------- d-------- C:\Program Files\corel
2007-04-26 09:20 -------- d-------- C:\Program Files\mirc
2007-04-25 12:59 -------- d-------- C:\Program Files\daemon tools
2007-04-24 16:18 -------- d-------- C:\Program Files\noadware4
2007-04-24 16:17 -------- d-------- C:\DOCUME~1\Jim\APPLIC~1\the bat!
2007-04-22 10:36 -------- d-------- C:\DOCUME~1\Jim\APPLIC~1\vso
2007-04-22 10:34 81920 --a------ C:\DOCUME~1\Jim\APPLIC~1\ezpinst.exe
2007-04-22 10:34 7176 --a------ C:\DOCUME~1\Jim\APPLIC~1\pcouffin.cat
2007-04-22 10:34 47360 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\pcouffin.sys
2007-04-22 10:34 47360 --a------ C:\DOCUME~1\Jim\APPLIC~1\pcouffin.sys
2007-04-22 10:34 34 --a------ C:\DOCUME~1\Jim\APPLIC~1\pcouffin.log
2007-04-22 10:34 1144 --a------ C:\DOCUME~1\Jim\APPLIC~1\pcouffin.inf
2007-04-20 11:59 -------- d-------- C:\Program Files\divx
2007-04-15 15:55 628 --a------ C:\DOCUME~1\Jim\APPLIC~1\autogk.ini
2007-04-04 08:30 -------- d-------- C:\Program Files\jasc software inc
2007-04-04 08:30 -------- d-------- C:\DOCUME~1\Jim\APPLIC~1\jasc software inc
2007-03-27 00:55 524288 --a------ C:\WINDOWS\SYSTEM32\divxsm.exe
2007-03-27 00:55 3596288 --a------ C:\WINDOWS\SYSTEM32\qt-dx331.dll
2007-03-27 00:55 200704 --a------ C:\WINDOWS\SYSTEM32\ssldivx.dll
2007-03-27 00:55 1044480 --a------ C:\WINDOWS\SYSTEM32\libdivx.dll
2007-03-27 00:49 73728 --a------ C:\WINDOWS\SYSTEM32\dpl100.dll
2007-03-27 00:49 593920 --a------ C:\WINDOWS\SYSTEM32\dpugui11.dll
2007-03-27 00:49 57344 --a------ C:\WINDOWS\SYSTEM32\dpv11.dll
2007-03-27 00:49 53248 --a------ C:\WINDOWS\SYSTEM32\dpugui10.dll
2007-03-27 00:49 344064 --a------ C:\WINDOWS\SYSTEM32\dpus11.dll
2007-03-27 00:49 294912 --a------ C:\WINDOWS\SYSTEM32\dpu11.dll
2007-03-27 00:49 294912 --a------ C:\WINDOWS\SYSTEM32\dpu10.dll
2007-03-27 00:49 196608 --a------ C:\WINDOWS\SYSTEM32\dtu100.dll
2007-03-27 00:48 823296 --a------ C:\WINDOWS\SYSTEM32\divx_xx0c.dll
2007-03-27 00:48 823296 --a------ C:\WINDOWS\SYSTEM32\divx_xx07.dll
2007-03-27 00:48 802816 --a------ C:\WINDOWS\SYSTEM32\divx_xx11.dll
2007-03-27 00:48 639066 --a------ C:\WINDOWS\SYSTEM32\divx.dll
2007-03-23 06:07 583504 --------- C:\WINDOWS\SYSTEM32\xpsshhdr.dll
2007-03-23 06:07 1683280 --------- C:\WINDOWS\SYSTEM32\xpssvcs.dll
2007-03-22 20:25 124928 --------- C:\WINDOWS\SYSTEM32\prntvpt.dll
2007-03-17 06:43 292864 --a------ C:\WINDOWS\SYSTEM32\winsrv.dll
2007-03-15 12:23 497496 --a------ C:\WINDOWS\SYSTEM32\xceedzip.dll
2007-03-15 12:19 526184 --a------ C:\WINDOWS\SYSTEM32\xceedcry.dll
2007-03-08 08:36 577536 --a------ C:\WINDOWS\SYSTEM32\user32.dll
2007-03-08 08:36 40960 --a------ C:\WINDOWS\SYSTEM32\mf3216.dll
2007-03-08 08:36 281600 --a------ C:\WINDOWS\SYSTEM32\gdi32.dll
2007-03-08 06:47 1843584 --a------ C:\WINDOWS\SYSTEM32\win32k.sys
2007-03-05 16:31 -------- d-------- C:\DOCUME~1\Jim\APPLIC~1\syntrillium
2007-02-15 18:40 124472 --a------ C:\WINDOWS\SYSTEM32\divxcodecupdatechecker.exe
2007-02-05 13:17 185344 --a------ C:\WINDOWS\SYSTEM32\upnphost.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
"{02478D38-C3F9-4EFB-9B51-7695ECA05670}"="C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll"
"{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}"="C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll"
"{AE7CD045-E861-484f-8273-0445EE161910}"="C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"DLCCCATS"="rundll32 C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\DLCCtime.dll,_RunDLLEntry@16"
"ATIPTA"="\"C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe\""
"!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoDispAppearancePage"=dword:00000000
"NoColorChoice"=dword:00000000
"NoSizeChoice"=dword:00000000
"NoDispBackgroundPage"=dword:00000000
"NoDispScrSavPage"=dword:00000000
"NoDispCPL"=dword:00000000
"NoVisualStyleChoice"=dword:00000000
"NoDispSettingsPage"=dword:00000000
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoActiveDesktopChanges"=dword:00000000
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSaveSettings"=dword:00000000
"NoThemesTab"=dword:00000000
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\run]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoFavoritesMenu"=hex:00,00,00,00
"NoFind"=hex:00,00,00,00
"NoRun"=dword:00000000
"NoLogOff"=dword:00000000
"NoClose"=dword:00000000
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer\run]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}"="C:\Program Files\Qualcomm\Eudora\EuShlExt.dll"
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"{e57ce738-33e8-4c51-8354-bb4de9d215d1}"="C:\WINDOWS\system32\upnpui.dll"
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages REG_MULTI_SZ msv1_0\0\0
Security Packages REG_MULTI_SZ kerberos\0msv1_0\0schannel\0wdigest\0\0
Notification Packages REG_MULTI_SZ scecli\0\0
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^Event Planner Reminder.lnk]
"backup"="C:\\WINDOWS\\pss\\Event Planner Reminder.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\WINDOWS\\Installer\\{5D0DF1BB-D82E-4FB2-B98E-4FDE42EF7EBB}\\Shortcut_EventPlan_5D0DF1BBD82E4FB2B98E4FDE42EF7EBB.exe "
"item"="Event Planner Reminder"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk]
"backup"="C:\\WINDOWS\\pss\\InterVideo WinCinema Manager.lnkCommon Startup"
"location"="Common Startup"
"item"="InterVideo WinCinema Manager"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"=""
"hkey"="HKLM"
"command"=""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!AVG Anti-Spyware]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="avgas"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AIM]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="aim"
"hkey"="HKCU"
"command"="C:\\Program Files\\AIM\\aim.exe -cnetwait.odl"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG7_CC]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="avgcc"
"hkey"="HKLM"
"command"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NMBgMonitor"
"hkey"="HKCU"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ctfmon"
"hkey"="HKCU"
"command"="C:\\WINDOWS\\system32\\ctfmon.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTSysVol]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="CTSysVol"
"hkey"="HKLM"
"command"="C:\\Program Files\\Creative\\Sound Blaster Live! 24-bit\\Surround Mixer\\CTSysVol.exe /r"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="daemon"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\DAEMON Tools\\daemon.exe\" -lang 1033"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dlccmon.exe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="dlccmon"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Dell Photo AIO Printer 924\\dlccmon.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\F-StopW]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="F-StopW"
"hkey"="HKLM"
"command"="C:\\Program Files\\FSI\\F-Prot\\F-StopW.EXE"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IBP]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="dlccmon"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Dell Photo AIO Printer 924\\dlccmon.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InfoData]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="rdfncpgb"
"hkey"="HKLM"
"command"="rundll32.exe \"C:\\WINDOWS\\system32\\rdfncpgb.dll\",realset"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="msmsgs"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NeroCheck"
"hkey"="HKLM"
"command"="C:\\Program Files\\Common Files\\Ahead\\Lib\\NeroCheck.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NWEReboot]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"=""
"hkey"="HKLM"
"command"=""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\P17Helper]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Rundll32 P17"
"hkey"="HKLM"
"command"="Rundll32 P17.dll,P17Helper"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="qttask"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\rfagent]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="rfagent"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\RFA\\rfagent.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="UpdReg"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\UpdReg.EXE"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uvnx]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="uvnx"
"hkey"="HKLM"
"command"="c:\\windows\\system32\\uvnx.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
p2psvc REG_MULTI_SZ p2psvc\0p2pimsvc\0p2pgasvc\0PNRPSvc\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0
********************************************************************
catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer,
http://www.gmer.netRootkit scan 2007-04-28 12:54:00
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCCCATS = rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
********************************************************************
Completion time: 07-04-28 12:54:03
C:\ComboFix-quarantined-files.txt ... 07-04-28 12:54