AVS4YOU Software Navigator 1.2, I think is a converter for video files. I don't use it, should I uninstall it?
I followed your direction, although since your second post, before this last post I ran a trend micro scan yo remove some files and used Vundofix to remove the last remaining file which doesn't do much because it comes back everytime under a new file name. But I do a scan everyday and remove what I can because I suspect it might infect other files or programs if I don't, so hopefully that didn't compromise the instructions you gave me.
Here is the Moveit log, when it asked if I wanted to reboot now I clicked on "no" because I had not yet saved the log. I then copied the log into a notepadfile and saved it then rebooted my computer immeadiately after. Here is the log;
LoadLibrary failed for C:\WINDOWS\system32\drpxmgkr.dll
C:\WINDOWS\system32\drpxmgkr.dll NOT unregistered.
C:\WINDOWS\system32\drpxmgkr.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\system32\acuxjotl.dll
C:\WINDOWS\system32\acuxjotl.dll NOT unregistered.
C:\WINDOWS\system32\acuxjotl.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\system32\lvsoeril.dll
C:\WINDOWS\system32\lvsoeril.dll NOT unregistered.
C:\WINDOWS\system32\lvsoeril.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\system32\ycjymujj.dll
C:\WINDOWS\system32\ycjymujj.dll NOT unregistered.
C:\WINDOWS\system32\ycjymujj.dll moved successfully.
C:\WINDOWS\system32\wacdd.ini2 moved successfully.
File/Folder C:\WINDOWS\system32\ddcaw.dll not found.
LoadLibrary failed for C:\WINDOWS\system32\pyehckaj.dll
C:\WINDOWS\system32\pyehckaj.dll NOT unregistered.
C:\WINDOWS\system32\pyehckaj.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\system32\uakmtpdt.dll
C:\WINDOWS\system32\uakmtpdt.dll NOT unregistered.
C:\WINDOWS\system32\uakmtpdt.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\system32\pqjviemy.dll
C:\WINDOWS\system32\pqjviemy.dll NOT unregistered.
C:\WINDOWS\system32\pqjviemy.dll moved successfully.
C:\WINDOWS\system32\tvyxx.ini2 moved successfully.
C:\WINDOWS\system32\ooppo.ini2 moved successfully.
LoadLibrary failed for C:\WINDOWS\system32\rrbesjrx.dll
C:\WINDOWS\system32\rrbesjrx.dll NOT unregistered.
C:\WINDOWS\system32\rrbesjrx.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\system32\xgoqhvjs.dll
C:\WINDOWS\system32\xgoqhvjs.dll NOT unregistered.
C:\WINDOWS\system32\xgoqhvjs.dll moved successfully.
C:\WINDOWS\system32\gjlnn.ini2 moved successfully.
LoadLibrary failed for C:\WINDOWS\system32\xvvjbvrt.dll
C:\WINDOWS\system32\xvvjbvrt.dll NOT unregistered.
C:\WINDOWS\system32\xvvjbvrt.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\system32\rmywatww.dll
C:\WINDOWS\system32\rmywatww.dll NOT unregistered.
C:\WINDOWS\system32\rmywatww.dll moved successfully.
C:\WINDOWS\system32\bdccf.ini2 moved successfully.
C:\WINDOWS\system32\xwyay.ini2 moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\opnlklk.dll
C:\WINDOWS\system32\opnlklk.dll NOT unregistered.
C:\WINDOWS\system32\opnlklk.dll moved successfully.
C:\WINDOWS\system32\kmpoq.ini2 moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\opnonli.dll
C:\WINDOWS\system32\opnonli.dll NOT unregistered.
C:\WINDOWS\system32\opnonli.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\iifddef.dll
C:\WINDOWS\system32\iifddef.dll NOT unregistered.
File move failed. C:\WINDOWS\system32\iifddef.dll scheduled to be moved on reboot.
[Custom Input]
< C:\WINDOWS\system32\drpxmgkr.dll >
File/Folder C:\WINDOWS\system32\drpxmgkr.dll not found.
< C:\WINDOWS\system32\acuxjotl.dll >
File/Folder C:\WINDOWS\system32\acuxjotl.dll not found.
< C:\WINDOWS\system32\lvsoeril.dll >
File/Folder C:\WINDOWS\system32\lvsoeril.dll not found.
< C:\WINDOWS\system32\ycjymujj.dll >
File/Folder C:\WINDOWS\system32\ycjymujj.dll not found.
< C:\WINDOWS\system32\wacdd.ini2 >
File/Folder C:\WINDOWS\system32\wacdd.ini2 not found.
< C:\WINDOWS\system32\ddcaw.dll >
File/Folder C:\WINDOWS\system32\ddcaw.dll not found.
< C:\WINDOWS\system32\pyehckaj.dll >
File/Folder C:\WINDOWS\system32\pyehckaj.dll not found.
< C:\WINDOWS\system32\uakmtpdt.dll >
File/Folder C:\WINDOWS\system32\uakmtpdt.dll not found.
< C:\WINDOWS\system32\pqjviemy.dll >
File/Folder C:\WINDOWS\system32\pqjviemy.dll not found.
< C:\WINDOWS\system32\tvyxx.ini2 >
File/Folder C:\WINDOWS\system32\tvyxx.ini2 not found.
< C:\WINDOWS\system32\ooppo.ini2 >
File/Folder C:\WINDOWS\system32\ooppo.ini2 not found.
< C:\WINDOWS\system32\rrbesjrx.dll >
File/Folder C:\WINDOWS\system32\rrbesjrx.dll not found.
< C:\WINDOWS\system32\xgoqhvjs.dll >
File/Folder C:\WINDOWS\system32\xgoqhvjs.dll not found.
< C:\WINDOWS\system32\gjlnn.ini2 >
File/Folder C:\WINDOWS\system32\gjlnn.ini2 not found.
< C:\WINDOWS\system32\xvvjbvrt.dll >
File/Folder C:\WINDOWS\system32\xvvjbvrt.dll not found.
< C:\WINDOWS\system32\rmywatww.dll >
File/Folder C:\WINDOWS\system32\rmywatww.dll not found.
< C:\WINDOWS\system32\bdccf.ini2 >
File/Folder C:\WINDOWS\system32\bdccf.ini2 not found.
< C:\WINDOWS\system32\xwyay.ini2 >
File/Folder C:\WINDOWS\system32\xwyay.ini2 not found.
< C:\WINDOWS\system32\opnlklk.dll >
File/Folder C:\WINDOWS\system32\opnlklk.dll not found.
< C:\WINDOWS\system32\kmpoq.ini2 >
File/Folder C:\WINDOWS\system32\kmpoq.ini2 not found.
< C:\WINDOWS\system32\opnonli.dll >
File/Folder C:\WINDOWS\system32\opnonli.dll not found.
< C:\WINDOWS\system32\iifddef.dll >
DllUnregisterServer procedure not found in C:\WINDOWS\system32\iifddef.dll
C:\WINDOWS\system32\iifddef.dll NOT unregistered.
File move failed. C:\WINDOWS\system32\iifddef.dll scheduled to be moved on reboot.
OTMoveIt2 by OldTimer - Version 1.0.21 log created on 03162008_151734
Here is the combofix log
ComboFix 08-03-14.4 - Christina 2008-03-16 15:32:03.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.388 [GMT -6:00]
Running from: C:\Documents and Settings\Christina\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\bdccf.ini
C:\WINDOWS\system32\ddcyy.dll
C:\WINDOWS\system32\gjlnn.ini
C:\WINDOWS\system32\iifddef.dll
C:\WINDOWS\system32\kjlnn.ini
C:\WINDOWS\system32\kjlnn.ini2
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\qomjj.dll
C:\WINDOWS\system32\tvyxx.ini
C:\WINDOWS\system32\wacdd.ini
C:\WINDOWS\system32\yycdd.ini
C:\WINDOWS\system32\yycdd.ini2
.
((((((((((((((((((((((((( Files Created from 2008-02-16 to 2008-03-16 )))))))))))))))))))))))))))))))
.
2008-03-16 15:19 . 2008-03-16 15:19 6,697 --a------ C:\WINDOWS\system32\ncpnmepu.dll
2008-03-16 15:18 . 2008-03-16 15:18 6,683 --a------ C:\WINDOWS\system32\ojhshgrh.dll
2008-03-16 15:17 . 2008-03-16 15:17 <DIR> d-------- C:\_OTMoveIt
2008-03-16 15:17 . 2008-03-16 15:17 6,687 --a------ C:\WINDOWS\system32\horfjsti.dll
2008-03-16 14:21 . 2008-03-16 14:21 6,697 --a------ C:\WINDOWS\system32\ekgyaqcv.dll
2008-03-16 14:21 . 2008-03-16 14:21 6,683 --a------ C:\WINDOWS\system32\fjwcmuug.dll
2008-03-15 18:58 . 2008-03-15 18:58 <DIR> d-------- C:\Deckard
2008-03-13 22:18 . 2008-03-13 22:18 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Grisoft
2008-03-13 22:01 . 2008-03-13 22:01 <DIR> d-------- C:\Documents and Settings\Christina\Application Data\Grisoft
2008-03-13 21:59 . 2007-05-30 06:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-03-13 21:58 . 2008-03-13 21:58 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-03-13 21:30 . 2008-03-13 21:30 <DIR> d---s---- C:\Documents and Settings\Christina\UserData
2008-03-13 21:16 . 2008-03-13 21:23 <DIR> d-------- C:\fixwareout
2008-03-13 17:44 . 2008-03-13 22:16 15,639 --ahs---- C:\WINDOWS\system32\ooppo.ini
2008-03-13 14:27 . 2008-03-16 15:07 <DIR> d-------- C:\VundoFix Backups
2008-03-12 11:09 . 2008-03-12 11:09 15,811 --a------ C:\WINDOWS\output.tre
2008-03-12 10:42 . 2004-06-11 14:16 36,864 --a------ C:\WINDOWS\system32\UnAudioNT.dll
2008-03-12 10:37 . 2004-05-24 14:11 141,696 --a------ C:\WINDOWS\system32\drivers\viaudios.sys
2008-03-12 10:05 . 2008-03-12 10:05 0 --a------ C:\WINDOWS\Irremote.ini
2008-03-12 09:35 . 2008-03-13 16:04 7,839 --ahs---- C:\WINDOWS\system32\xwyay.ini
2008-03-12 01:04 . 2008-03-16 14:41 10,752 --a------ C:\WINDOWS\DCEBoot.exe
2008-03-11 23:36 . 2008-03-11 23:36 <DIR> d-------- C:\WINDOWS\kdefense
2008-03-11 23:36 . 2008-03-11 23:36 846,336 --a------ C:\WINDOWS\system32\kdfinj.dll
2008-03-11 23:36 . 2008-03-16 15:23 722,472 --a------ C:\WINDOWS\system32\kdfmgr.exe
2008-03-11 23:36 . 2008-03-16 15:23 192,512 --a------ C:\WINDOWS\system32\kdfvmgr.exe
2008-03-11 23:36 . 2008-03-16 15:23 77,824 --a------ C:\WINDOWS\system32\kdfapi.dll
2008-03-11 23:36 . 2008-03-16 15:23 53,248 --a------ C:\WINDOWS\system32\Kdfhok.dll
2008-03-11 22:06 . 2008-03-12 09:27 24,287 --ahs---- C:\WINDOWS\system32\kmpoq.ini
2008-03-11 21:52 . 2008-03-11 21:52 <DIR> d-------- C:\Documents and Settings\Christina\Application Data\Nero
2008-03-11 21:43 . 2008-03-11 21:43 <DIR> d-------- C:\Program Files\Nero
2008-03-11 21:43 . 2008-03-12 10:24 <DIR> d-------- C:\Program Files\Common Files\Nero
2008-03-11 21:43 . 2008-03-12 10:23 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Nero
2008-03-11 21:20 . 2008-03-11 21:20 <DIR> d-------- C:\WINDOWS\LocalSSL
2008-03-11 21:19 . 2007-12-24 17:37 138,384 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2008-03-11 21:19 . 2007-12-24 17:37 52,496 --a------ C:\WINDOWS\system32\drivers\tmactmon.sys
2008-03-11 21:19 . 2007-12-24 17:37 52,240 --a------ C:\WINDOWS\system32\drivers\tmevtmgr.sys
2008-03-11 21:18 . 2008-03-13 21:35 <DIR> d-------- C:\Program Files\Trend Micro
2008-03-11 12:58 . 2008-03-11 21:18 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Trend Micro
2008-03-08 13:32 . 2008-03-08 13:32 <DIR> d-------- C:\Documents and Settings\Christina\Application Data\AVS4YOU
2008-03-08 13:32 . 2008-03-08 13:32 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\AVS4YOU
2008-03-08 13:31 . 2008-03-08 13:32 <DIR> d-------- C:\Program Files\Common Files\AVSMedia
2008-03-08 13:31 . 2008-03-08 13:32 <DIR> d-------- C:\Program Files\AVS4YOU
2008-03-07 23:48 . 2008-03-08 13:32 <DIR> d-------- C:\Documents and Settings\Christina\Application Data\DivX
2008-03-07 21:09 . 2008-03-07 21:09 3,532 --a------ C:\drmHeader.bin
2008-03-07 18:55 . 2008-03-07 18:56 <DIR> d-------- C:\Program Files\DivX
2008-03-07 18:55 . 2008-02-20 20:05 120,056 --------- C:\WINDOWS\system32\pxcpyi64.exe
2008-03-07 18:55 . 2008-02-20 20:05 118,520 --------- C:\WINDOWS\system32\pxinsi64.exe
2008-03-03 15:23 . 2008-03-03 15:23 376 --a------ C:\WINDOWS\ODBC.INI
2008-03-03 15:22 . 2008-03-03 15:22 <DIR> d-------- C:\WINDOWS\ShellNew
2008-03-03 15:21 . 2008-03-03 15:21 <DIR> d-------- C:\Documents and Settings\Christina\Application Data\Microsoft Web Folders
2008-03-02 04:02 . 2008-03-02 04:02 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-03-01 04:00 . 2008-03-02 04:12 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2008-02-29 23:59 . 2008-02-29 23:59 <DIR> d-------- C:\Program Files\Winamp Remote
2008-02-29 23:59 . 2008-02-29 23:59 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\OrbNetworks
2008-02-29 23:52 . 2008-02-20 20:05 129,784 --------- C:\WINDOWS\system32\pxafs.dll
2008-02-29 23:52 . 2007-03-07 17:51 9,464 --------- C:\WINDOWS\system32\drivers\cdralw2k.sys
2008-02-29 23:52 . 2007-03-07 17:51 9,336 --------- C:\WINDOWS\system32\drivers\cdr4_xp.sys
2008-02-29 23:36 . 2008-02-29 23:47 <DIR> d-------- C:\Downloads
2008-02-29 23:35 . 2008-03-02 22:40 <DIR> d-------- C:\Program Files\BitComet
2008-02-29 12:22 . 2008-02-29 12:22 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2008-02-29 11:58 . 2008-02-29 11:58 <DIR> d-------- C:\Program Files\ArcSoft
2008-02-29 11:58 . 2004-08-17 13:00 413,696 --a------ C:\WINDOWS\system32\msvc2223.rra
2008-02-29 10:29 . 2008-02-29 12:00 <DIR> d-------- C:\Documents and Settings\Christina\Application Data\ArcSoft
2008-02-29 10:28 . 2008-02-29 10:28 <DIR> d-------- C:\Program Files\Common Files\ArcSoft
2008-02-29 10:28 . 2004-05-04 12:53 1,645,320 --a------ C:\WINDOWS\system32\gdiplus.dll
2008-02-29 10:28 . 2005-06-21 11:29 245,408 --a------ C:\WINDOWS\system32\unicows.dll
2008-02-29 10:25 . 2008-03-16 15:36 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-02-29 10:25 . 2008-02-29 10:25 1,409 --a------ C:\WINDOWS\QTFont.for
2008-02-29 10:23 . 2008-02-29 10:23 <DIR> d-------- C:\Program Files\iTunes
2008-02-29 10:23 . 2008-02-29 10:23 <DIR> d-------- C:\Program Files\iPod
2008-02-29 10:23 . 2008-02-29 10:23 <DIR> d-------- C:\Program Files\Bonjour
2008-02-29 10:23 . 2008-02-29 12:22 <DIR> d-------- C:\Documents and Settings\Christina\Application Data\Apple Computer
2008-02-29 10:22 . 2008-02-29 10:22 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-02-29 10:22 . 2008-02-29 10:23 <DIR> d-------- C:\Program Files\QuickTime
2008-02-29 10:22 . 2008-02-29 10:22 <DIR> d-------- C:\Program Files\Apple Software Update
2008-02-29 10:22 . 2008-02-29 10:23 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-02-29 10:21 . 2008-02-29 10:21 <DIR> d-------- C:\Program Files\Common Files\Apple
2008-02-29 10:21 . 2008-02-29 10:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-02-29 08:54 . 2008-02-29 14:21 <DIR> d-------- C:\Documents and Settings\Christina\Application Data\SuperNZB
2008-02-28 22:36 . 2008-03-16 15:36 <DIR> dr------- C:\Program Files\Net Nanny
2008-02-28 22:36 . 1999-09-09 12:28 446,464 --a------ C:\WINDOWS\system32\HHActiveX.dll
2008-02-28 22:36 . 2002-09-24 10:21 81,920 --a------ C:\WINDOWS\system32\NNComm.dll
2008-02-28 22:36 . 2002-09-24 10:21 24,576 --a------ C:\WINDOWS\system32\HookRes.dll
2008-02-28 22:36 . 2008-02-28 22:59 119 --a------ C:\WINDOWS\NNS.INI
2008-02-28 18:08 . 2008-02-28 18:08 <DIR> d-------- C:\Program Files\River Past
2008-02-28 18:08 . 2008-02-28 18:08 <DIR> d-------- C:\Program Files\Common Files\River Past
2008-02-28 18:08 . 2008-02-28 18:08 <DIR> d-------- C:\Documents and Settings\Christina\Application Data\River Past G5
2008-02-28 18:08 . 2008-02-28 18:57 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\River Past G5
2008-02-28 18:08 . 2008-02-28 18:08 164,329 --a------ C:\WINDOWS\Crazi Video for Sansa Uninstaller.exe
2008-02-28 18:02 . 2008-02-28 18:02 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2008-02-28 18:02 . 2008-02-28 18:03 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2008-02-28 18:02 . 2006-09-25 18:58 23,856 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-02-28 16:40 . 2008-02-28 16:40 <DIR> d-------- C:\Program Files\MSECache
2008-02-28 16:24 . 2008-03-09 21:11 116 --a------ C:\WINDOWS\NeroDigital.ini
2008-02-28 15:58 . 2008-03-01 14:35 <DIR> d-------- C:\Program Files\uTorrent
2008-02-28 15:58 . 2008-03-11 21:32 <DIR> d-------- C:\Documents and Settings\Christina\Application Data\uTorrent
2008-02-20 20:05 . 2008-02-20 20:05 3,596,288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2008-02-20 20:05 . 2008-02-20 20:05 1,044,480 --a------ C:\WINDOWS\system32\libdivx.dll
2008-02-20 20:05 . 2008-02-20 20:05 524,288 --a------ C:\WINDOWS\system32\DivXsm.exe
2008-02-20 20:05 . 2008-02-20 20:05 200,704 --a------ C:\WINDOWS\system32\ssldivx.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-14 03:31 --------- d-----w C:\Program Files\McAfee
2008-03-12 16:42 --------- d-----w C:\Program Files\VIAudioi
2008-03-12 03:32 --------- d-----w C:\Program Files\Ahead
2008-03-03 04:43 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-01 05:59 --------- d-----w C:\Program Files\Winamp
2008-02-29 04:57 --------- d-----w C:\Program Files\Common Files\Adobe
2008-02-21 02:04 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2008-02-21 02:04 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2008-02-21 02:04 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2008-02-21 02:04 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2008-02-21 02:04 682,496 ----a-w C:\WINDOWS\system32\DivX.dll
2008-02-21 02:04 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2008-02-21 02:04 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2008-02-21 02:04 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2008-02-21 02:04 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2008-02-21 02:04 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2008-02-21 02:04 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2008-02-21 02:04 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2008-02-12 20:15 --------- d-----w C:\Program Files\Coupons
2008-02-02 02:22 --------- d-----w C:\Program Files\directx
2008-02-02 02:04 --------- d-----w C:\Program Files\Activision
2008-02-01 03:12 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-02-01 02:56 --------- d-----w C:\Program Files\Sony
2008-01-25 02:50 --------- d-----w C:\Program Files\HP
2008-01-25 02:48 --------- d-----w C:\Program Files\Hewlett-Packard
2008-01-25 02:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
2008-01-25 02:47 --------- d-----w C:\Program Files\Common Files\Hewlett-Packard
2008-01-23 05:43 --------- d-----w C:\Program Files\DriverGuide DriverScan
2008-01-23 05:27 --------- d-----w C:\Program Files\Java
2008-01-23 05:25 --------- d-----w C:\Program Files\Common Files\Java
2008-01-23 05:07 --------- d-----w C:\Program Files\Google
2008-01-22 03:40 --------- d-----w C:\Program Files\Linksys
2008-01-21 20:23 --------- d-----w C:\Program Files\DVD Shrink
2008-01-21 20:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\DVD Shrink
2008-01-21 20:06 --------- d-----w C:\Program Files\microsoft frontpage
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{11E4ADF6-7ECB-495F-BCF0-5AA6ABA9A10E}]
C:\WINDOWS\system32\xxyvt.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2C54E13C-A722-4E77-A4C1-A032A4F8D9A3}]
C:\WINDOWS\system32\fccdb.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4107B3FF-F0F4-4BA3-B969-7C6671B01BF0}]
C:\WINDOWS\system32\nnljk.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{65CFDAFB-EA22-4EE3-9B2A-23D0F0E553EA}]
C:\WINDOWS\system32\qopmk.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{96EFCE13-8B8D-414A-8592-27A6F5F481B9}]
C:\WINDOWS\system32\yaywx.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ADADB652-FFEE-4851-97D0-F48E4C4B521A}]
C:\WINDOWS\system32\nnljg.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BB19741F-7F3F-44EB-BBFD-6751872926C6}]
C:\WINDOWS\system32\oppoo.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C941BD38-336A-4EF2-AF71-5AEBC35917BA}]
C:\WINDOWS\system32\ddcaw.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{E7620C98-FCCC-40E5-92EC-C7685D2E1E40}"= "C:\Program Files\Trend Micro\TrendSecure\TransactionProtector\TSToolbar.dll" [2007-09-18 14:06 103760]
[HKEY_CLASSES_ROOT\clsid\{e7620c98-fccc-40e5-92ec-c7685d2e1e40}]
[HKEY_CLASSES_ROOT\TSToolbar.TSProtectorBar.1]
[HKEY_CLASSES_ROOT\TypeLib\{EC525605-2266-4775-8F78-A68A6446465C}]
[HKEY_CLASSES_ROOT\TSToolbar.TSProtectorBar]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 10:24 1694208]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-01-22 23:07 171448]
"BitComet"="C:\Program Files\BitComet\BitComet.exe" [ ]
"Orb"="C:\Program Files\Winamp Remote\bin\OrbTray.exe" [2008-01-07 14:02 495616]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe" [2004-06-21 11:40 172032]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 02:11 132496]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2004-02-12 14:38 49152]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 16:18 241664]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"NNTray"="C:\Program Files\Net Nanny\nnstart.exe" [2002-09-24 10:21 61440]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-02-01 00:13 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-19 14:10 267048]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2008-01-15 16:54 37376]
"UfSeAgnt.exe"="C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe" [2007-10-27 01:47 1393928]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [ ]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 03:25 6731312]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-01-21 14:19:14 113664]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2004-05-28 23:31:38 241664]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [2000-01-21 02:15:54 65588]
Wireless-B PCI Adapter Utility.lnk - C:\Program Files\Linksys\WMP11 Config Utility\WMP11Cfg.exe [2008-01-21 21:40:48 4638720]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\iifddef]
iifddef.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Sony\\Station\\Launchpad\\LaunchPad.exe"=
"C:\\Program Files\\Sony\\Station\\Launchpad\\_aunchPad.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\Orb.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"10465:TCP"= 10465:TCP:BitComet 10465 TCP
"10465:UDP"= 10465:UDP:BitComet 10465 UDP
R3 IPN2120;Instant Wireless-B PCI Adapter Driver;C:\WINDOWS\system32\DRIVERS\LSIPNDS.sys [2003-07-10 11:09]
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-03-16 15:36:49
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Net Nanny\nnsvc.exe
C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
C:\Program Files\Trend Micro\BM\TMBMSRV.exe
C:\Program Files\Net Nanny\nntray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
C:\Program Files\Trend Micro\TrendSecure\TSCFCommander.exe
C:\Program Files\Trend Micro\TrendSecure\TSCFPlatformCOMSvr.exe
.
**************************************************************************
.
Completion time: 2008-03-16 15:41:03 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-16 21:40:54
.
2008-03-02 10:12:34 --- E O F ---