In my search for rundll32 I found the following:
rundll32 in C:\I386
RUNDLL32.EXE-3D2B6136.PF IN C:\WINDOWS\Prefetch
RUNDLL32.EXE-405E817D.PF IN C:\WINDOWS\Prefetch
RUNDLL32.EXE-5EDFBB4F.PF IN C:\WINDOWS\Prefetch
rundll32 in C:\WINDOWS\SYSTEM32
rundll32 in C:\Program Files\MUSICMATCH\Musicmatch Jukebox
COMBOFIX LOG:
"Lisa Gassmann" - 07-02-12 10:36:39 Service Pack 2
ComboFix 07-02-11 - Running from: "C:\Documents and Settings\Lisa Gassmann\Desktop"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\bszip.dll
((((((((((((((((((((((((((((((( Files Created from 2007-01-12 to 2007-02-12 ))))))))))))))))))))))))))))))))))
2007-02-11 17:11 <DIR> d-------- C:\WINDOWS\SYSTEM32\ActiveScan
2007-02-11 15:06 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2007-02-11 15:06 <DIR> d-------- C:\DOCUME~1\LISAGA~1\Application Data\SUPERAntiSpyware.com
2007-02-11 15:06 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\SUPERAntiSpyware.com
2007-02-11 15:05 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-02-10 22:49 3,968 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\AvgAsCln.sys
2007-02-10 22:49 <DIR> d-------- C:\Program Files\AVG Anti-Spyware 7.5
2007-02-10 22:11 999,245 --ahs---- C:\WINDOWS\SYSTEM32\hjjlm.bak2
2007-02-10 20:00 990,117 --ahs---- C:\WINDOWS\SYSTEM32\hjjlm.bak1
2007-02-10 15:34 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\ParetoLogic Anti-Spyware
2007-02-10 12:37 <DIR> d-------- C:\Program Files\Windows Live Safety Center
2007-02-10 12:24 <DIR> d-------- C:\Program Files\Enigma Software Group
2007-02-10 12:04 <DIR> d-------- C:\DOCUME~1\LISAGA~1\.housecall6.6
2007-02-10 01:48 <DIR> d-------- C:\Program Files\CCleaner
2007-02-10 01:45 <DIR> d-------- C:\Program Files\MSConfig CleanUp
2007-02-10 01:12 <DIR> d-------- C:\Program Files\Windows Defender
2007-02-10 00:09 28,672 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\CO_Mon.sys
2007-02-10 00:09 <DIR> d-------- C:\DOCUME~1\LISAGA~1\Application Data\WholeSecurity
2007-02-09 23:41 <DIR> d-a------ C:\DOCUME~1\ALLUSE~1\Application Data\TEMP
2007-02-09 22:22 51,072 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\ikhlayer.sys
2007-02-09 22:22 30,592 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\ikhfile.sys
2007-02-09 22:21 <DIR> d-------- C:\Program Files\Spyware Doctor
2007-02-09 22:21 <DIR> d-------- C:\DOCUME~1\LISAGA~1\Application Data\PC Tools
2007-02-09 21:51 <DIR> d-------- C:\Program Files\Western Digital Technologies
2007-02-09 03:53 <DIR> d-------- C:\DOCUME~1\LISAGA~1\Application Data\ImgBurn
2007-02-09 00:56 <DIR> d-------- C:\DOCUME~1\LISAGA~1\Application Data\DVD Flick
2007-02-09 00:54 <DIR> d-------- C:\Program Files\DVD Flick
2007-02-08 20:21 0 --a------ C:\WINDOWS\SYSTEM32\sysupdate.exe
2007-02-08 17:59 5,306 --a------ C:\WINDOWS\SYSTEM32\systemupdate.exe
2007-02-08 17:14 87,608 --a------ C:\DOCUME~1\LISAGA~1\Application Data\ezpinst.exe
2007-02-08 17:14 47,360 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\pcouffin.sys
2007-02-08 17:14 47,360 --a------ C:\DOCUME~1\LISAGA~1\Application Data\pcouffin.sys
2007-02-08 17:14 <DIR> d-------- C:\DOCUME~1\LISAGA~1\Application Data\Vso
2007-02-08 16:51 <DIR> d-------- C:\Program Files\MagicISO
2007-02-04 22:51 <DIR> d-------- C:\Program Files\Free iPod Video Converter
2007-02-04 22:45 <DIR> d-------- C:\Program Files\intelliScore Polyphonic WAV to MIDI Converter Demo
2007-02-04 17:51 <DIR> d-------- C:\DOCUME~1\LISAGA~1\Application Data\RipIt4Me
2007-01-29 18:15 <DIR> d-------- C:\DOCUME~1\LISAGA~1\Application Data\InstallShield
2007-01-26 22:48 94,263 --a------ C:\WINDOWS\DLA.EXE
2007-01-26 22:48 89,264 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\DRVMCDB.SYS
2007-01-26 22:48 61,500 --a------ C:\WINDOWS\SYSTEM32\DLAAPI_W.DLL
2007-01-26 22:48 5,660 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\DLACDBHM.SYS
2007-01-26 22:48 40,544 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\DRVNDDM.SYS
2007-01-26 22:48 22,684 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\DLARTL_N.SYS
2007-01-26 22:42 <DIR> d-------- C:\WINDOWS\SYSTEM32\dla
2007-01-26 22:34 <DIR> d-------- C:\Intel
2007-01-26 19:19 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Adobe
2007-01-23 21:46 40,960 --a------ C:\WINDOWS\SYSTEM32\dlcqvs.dll
2007-01-23 21:46 344,064 --a------ C:\WINDOWS\SYSTEM32\dlcqcoin.dll
2007-01-23 21:45 991,232 --a------ C:\WINDOWS\SYSTEM32\dlcqusb1.dll
2007-01-23 21:45 983,121 --a------ C:\WINDOWS\SYSTEM32\dlcqgf.dll
2007-01-23 21:45 94,208 --a------ C:\WINDOWS\SYSTEM32\dlcqpplc.dll
2007-01-23 21:45 86,016 --a------ C:\WINDOWS\SYSTEM32\dlcqcub.dll
2007-01-23 21:45 77,824 --a------ C:\WINDOWS\SYSTEM32\DLCQcfg.dll
2007-01-23 21:45 73,728 --a------ C:\WINDOWS\SYSTEM32\dlcqcu.dll
2007-01-23 21:45 696,320 --a------ C:\WINDOWS\SYSTEM32\dlcqhbn3.dll
2007-01-23 21:45 692,224 --a------ C:\WINDOWS\SYSTEM32\dlcqdrs.dll
2007-01-23 21:45 684,032 --a------ C:\WINDOWS\SYSTEM32\dlcqcomc.dll
2007-01-23 21:45 65,536 --a------ C:\WINDOWS\SYSTEM32\dlcqcaps.dll
2007-01-23 21:45 643,072 --a------ C:\WINDOWS\SYSTEM32\dlcqpmui.dll
2007-01-23 21:45 61,440 --a------ C:\WINDOWS\SYSTEM32\dlcqcnv4.dll
2007-01-23 21:45 585,728 --a------ C:\WINDOWS\SYSTEM32\dlcqlmpm.dll
2007-01-23 21:45 537,480 --a------ C:\WINDOWS\SYSTEM32\dlcqcoms.exe
2007-01-23 21:45 454,656 --a------ C:\WINDOWS\SYSTEM32\dlcqutil.dll
2007-01-23 21:45 421,888 --a------ C:\WINDOWS\SYSTEM32\dlcqcomm.dll
2007-01-23 21:45 413,696 --a------ C:\WINDOWS\SYSTEM32\dlcqinpa.dll
2007-01-23 21:45 397,312 --a------ C:\WINDOWS\SYSTEM32\dlcqiesc.dll
2007-01-23 21:45 385,928 --a------ C:\WINDOWS\SYSTEM32\dlcqih.exe
2007-01-23 21:45 381,832 --a------ C:\WINDOWS\SYSTEM32\dlcqcfg.exe
2007-01-23 21:45 36,864 --a------ C:\WINDOWS\SYSTEM32\dlcqcur.dll
2007-01-23 21:45 323,584 --a------ C:\WINDOWS\SYSTEM32\DLCQhcp.dll
2007-01-23 21:45 274,432 --a------ C:\WINDOWS\SYSTEM32\DLCQinst.dll
2007-01-23 21:45 188,416 --a------ C:\WINDOWS\SYSTEM32\dlcqgrd.dll
2007-01-23 21:45 176,128 --a------ C:\WINDOWS\SYSTEM32\dlcqinsb.dll
2007-01-23 21:45 176,128 --a------ C:\WINDOWS\SYSTEM32\dlcqins.dll
2007-01-23 21:45 163,840 --a------ C:\WINDOWS\SYSTEM32\dlcqprox.dll
2007-01-23 21:45 139,264 --a------ C:\WINDOWS\SYSTEM32\dlcqjswr.dll
2007-01-23 21:45 106,496 --a------ C:\WINDOWS\SYSTEM32\dlcqinsr.dll
2007-01-23 21:45 1,224,704 --a------ C:\WINDOWS\SYSTEM32\dlcqserv.dll
2007-01-23 21:45 <DIR> d-------- C:\Program Files\Dell Photo AIO Printer 966
2007-01-23 21:13 <DIR> d-------- C:\DOCUME~1\LISAGA~1\Application Data\Corel
2007-01-23 21:10 <DIR> d-------- C:\Program Files\Corel
2007-01-23 21:10 <DIR> d-------- C:\Program Files\Common Files\Corel
2007-01-23 20:38 <DIR> d-------- C:\Program Files\DellConnect
2007-01-23 20:24 <DIR> d--hs---- C:\WINDOWS\CSC
2007-01-23 14:20 <DIR> d-------- C:\DOCUME~1\LISAGA~1\Application Data\DellFaxCtr
2007-01-23 14:12 <DIR> d-------- C:\Program Files\dl_cats
2007-01-23 14:11 87,040 --a------ C:\WINDOWS\SYSTEM32\wiafbdrv.dll
2007-01-23 14:11 15,104 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\usbscan.sys
2007-01-23 14:06 <DIR> d-------- C:\Program Files\Abbyy FineReader 6.0 Sprint
2007-01-23 14:04 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\BVRP Software
2007-01-23 14:03 98,345 --a------ C:\WINDOWS\SYSTEM32\IMHOST32.DLL
2007-01-23 14:03 40,960 --a------ C:\WINDOWS\SYSTEM32\DLPRMON.DLL
2007-01-23 14:03 339,968 --a------ C:\WINDOWS\SYSTEM32\IMGMAN32.DLL
2007-01-23 14:03 32,768 --a------ C:\WINDOWS\SYSTEM32\DLPMONUI.DLL
2007-01-23 14:02 <DIR> d-------- C:\Program Files\Dell PC Fax
2007-01-23 14:02 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\DellFaxCtr
2007-01-22 18:23 <DIR> d-------- C:\DOCUME~1\LISAGA~1\Application Data\WinRAR
2007-01-22 18:09 765,952 --a------ C:\WINDOWS\SYSTEM32\xvidcore.dll
2007-01-22 18:09 180,224 --a------ C:\WINDOWS\SYSTEM32\xvidvfw.dll
2007-01-22 18:09 <DIR> d-------- C:\Program Files\Xvid
2007-01-15 19:47 <DIR> d-------- C:\Program Files\uTorrent
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-02-11 17:57 -------- d-------- C:\Program Files\phonetray
2007-02-09 22:15 -------- d-------- C:\Program Files\spywareblaster
2007-02-08 23:38 33 --a------ C:\DOCUME~1\LISAGA~1\Application Data\pcouffin.log
2007-02-08 23:38 1144 --a------ C:\DOCUME~1\LISAGA~1\Application Data\pcouffin.inf
2007-02-08 23:38 1074 --a------ C:\DOCUME~1\LISAGA~1\Application Data\pcouffin.cat
2007-02-08 17:46 -------- d-------- C:\Program Files\turbotax
2007-02-08 17:42 -------- d--h----- C:\Program Files\installshield installation information
2007-02-08 15:54 -------- d-------- C:\DOCUME~1\LISAGA~1\Application Data\ahead
2007-02-05 14:24 -------- d-------- C:\Program Files\yahoo!
2007-02-05 14:24 -------- d-------- C:\Program Files\Common Files\scanner
2007-02-05 14:22 -------- d-------- C:\Program Files\Common Files\adobe
2007-02-05 14:21 -------- d-------- C:\Program Files\evideoshare
2007-02-04 17:39 -------- d-------- C:\Program Files\dvdfab
2007-01-31 17:41 -------- d-------- C:\Program Files\quicktime
2007-01-31 17:40 -------- d-------- C:\Program Files\apple software update
2007-01-31 17:09 -------- d-------- C:\Program Files\bodog poker
2007-01-29 18:23 -------- d-------- C:\Program Files\quicken
2007-01-26 22:48 -------- d-------- C:\Program Files\sonic
2007-01-26 19:16 -------- d-------- C:\DOCUME~1\LISAGA~1\Application Data\adobeum
2007-01-23 21:45 -------- d-------- C:\Program Files\dell
2007-01-19 17:07 -------- d-------- C:\DOCUME~1\LISAGA~1\Application Data\adobe
2007-01-07 00:37 -------- d-------- C:\Program Files\webshots
2007-01-07 00:37 -------- d-------- C:\DOCUME~1\LISAGA~1\Application Data\webshots
2007-01-06 13:31 -------- d-------- C:\Program Files\Common Files\answerworks 4.0
2007-01-03 20:43 -------- d-------- C:\Program Files\kodak picture cd
2006-12-07 00:40 2362184 --a------ C:\WINDOWS\SYSTEM32\wmvcore.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"MSKAGENTEXE"="c:\\PROGRA~1\\mcafee\\SPAMKI~1\\mskagent.exe"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"SUPERAntiSpyware"="C:\\Program Files\\SUPERAntiSpyware\\SUPERAntiSpyware.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"VSOCheckTask"="\"C:\\PROGRA~1\\McAfee.com\\VSO\\mcmnhdlr.exe\" /checktask"
"MCAgentExe"="c:\\PROGRA~1\\mcafee.com\\agent\\mcagent.exe"
"MCUpdateExe"="c:\\PROGRA~1\\mcafee.com\\agent\\mcupdate.exe"
"VirusScan Online"="C:\\Program Files\\McAfee.com\\VSO\\mcvsshld.exe"
"MPSExe"="c:\\PROGRA~1\\mcafee.com\\mps\\mscifapp.exe /embedding"
"CTSysVol"="C:\\Program Files\\Creative\\Sound Blaster Live! 24-bit\\Surround Mixer\\CTSysVol.exe /r"
"MSKDetectorExe"="C:\\PROGRA~1\\McAfee\\SPAMKI~1\\MSKDetct.exe /startup"
"MSKAGENTEXE"="C:\\PROGRA~1\\mcafee\\SPAMKI~1\\mskagent.exe"
"OASClnt"="C:\\Program Files\\McAfee.com\\VSO\\oasclnt.exe"
"MPFExe"="C:\\PROGRA~1\\McAfee.com\\PERSON~1\\MpfTray.exe"
"DLCQCATS"="rundll32 C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\DLCQtime.dll,_RunDLLEntry@16"
"!AVG Anti-Spyware"="\"C:\\Program Files\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
"Windows"="rundll32.exe"
"UpdReg"="C:\\WINDOWS\\UpdReg.EXE"
"PinnacleDriverCheck"="C:\\WINDOWS\\system32\\PSDrvCheck.exe -CheckReg"
"P17Helper"="Rundll32 P17.dll,P17Helper"
"IntelMeM"="C:\\Program Files\\Intel\\Modem Event Monitor\\IntelMEM.exe"
"IgfxTray"="C:\\WINDOWS\\system32\\igfxtray.exe"
"igfxpers"="C:\\WINDOWS\\system32\\igfxpers.exe"
"igfxhkcmd"="C:\\WINDOWS\\system32\\hkcmd.exe"
"HotKeysCmds"="C:\\WINDOWS\\system32\\hkcmd.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices]
"Windows"="rundll32.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"UleadBurningHelper"=dword:00000002
"ose"=dword:00000003
"NetSvc"=dword:00000003
"MDM"=dword:00000002
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{BFACBC52-B6D2-4F84-A486-37A921169F28}"=""
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"="Microsoft AntiMalware ShellExecuteHook"
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=""
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Spyware Doctor"="\"C:\\Program Files\\Spyware Doctor\\swdoctor.exe\" /Q"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"Spyware Doctor"="\"C:\\Program Files\\Spyware Doctor\\swdoctor.exe\" /Q"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=hex(2):43,3a,5c,57,49,4e,44,4f,57,53,5c,52,65,73,6f,75,72,\
63,65,73,5c,54,68,65,6d,65,73,5c,52,6f,79,61,6c,65,5c,52,6f,79,61,6c,65,2e,\
6d,73,73,74,79,6c,65,73,00
"InstallTheme"=hex(2):43,3a,5c,57,49,4e,44,4f,57,53,5c,52,65,73,6f,75,72,63,65,\
73,5c,54,68,65,6d,65,73,5c,52,6f,79,61,6c,65,2e,74,68,65,6d,65,00
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Ad-Aware.job
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\McAfee.com Scan for Viruses - My Computer (GASSMANN-Lisa Gassmann).job
C:\WINDOWS\tasks\MP Scheduled Scan.job
C:\WINDOWS\tasks\Spybot - Search & Destroy.job
********************************************************************
catchme 0.1 W2K/XP - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.netscanning hidden processes ...
cmd.exe [9944]
scanning hidden services ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCQCATS = rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCQtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hidden files ...
scan completed successfully
hidden processes: 1
hidden services: 0
hidden files: 0
********************************************************************
Completion time: 07-02-12 10:46:58
Hijack this log:
Logfile of HijackThis v1.99.1
Scan saved at 1:25:15 PM, on 2/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\system32\dlcqcoms.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
C:\Program Files\PhoneTray\PhoneTray.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\PROGRA~1\mcafee.com\mps\mscifapp.exe
C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe
C:\PROGRA~1\mcafee\SPAMKI~1\mskagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
c:\program files\mcafee.com\agent\mcagent.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\hkcmd.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\IncrediMail\bin\IncMail.exe
C:\PROGRA~1\INCRED~1\bin\IMApp.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Lisa Gassmann\My Documents\scanning stuff\crusty.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = dynhost.inetcam.com;register.inetcam.com;127.0.0.1
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~3\tools\iesdsg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~3\tools\iesdpb.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [MPSExe] c:\PROGRA~1\mcafee.com\mps\mscifapp.exe /embedding
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\mcafee\SPAMKI~1\mskagent.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [DLCQCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCQtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [Windows] rundll32.exe
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\RunServices: [Windows] rundll32.exe
O4 - HKCU\..\Run: [MSKAGENTEXE] c:\PROGRA~1\mcafee\SPAMKI~1\mskagent.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: MasterCook: Select Image - C:\Program Files\MasterCook 9\Web\MCIEContext.hta
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~3\tools\iesdpb.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) -
http://downloads.ewi...oOnlineScan.cabO16 - DPF: {231B1C6E-F934-42A2-92B6-C2FEFEC24276} (yucsetreg Class) - C:\Program Files\Yahoo!\common\yucconfig.dll
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) -
http://security.syma...bin/AvSniff.cabO16 - DPF: {2E12FB00-546B-4EE3-9CC2-057BF02E1C17} (Webshots Multiple Media Uploader - Container) -
http://community.web...wsaxcontrol.cabO16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) -
http://cdn.scan.onec...lscbase9602.cabO16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
http://security.syma...n/bin/cabsa.cabO16 - DPF: {78AEEDE8-7345-4FB5-A8FE-4BFF16EF25FC} (McAfee Virtual Technician Control Class) -
http://us-download.m...ted/mvt/mvt.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoft...free/asinst.cabO16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) -
http://community.web...otoUploader.CABO20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: dlcq_device - - C:\WINDOWS\system32\dlcqcoms.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: PhoneTray - Unknown owner - C:\Program Files\PhoneTray\PhoneTray.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
Also, the CCleaner wanted to know if I wanted to keep a backup of what it cleaned. I didn't know so I said yes, should I delete it or keep it?
Thanks so much!
Lisa