Hi,
Downloaded and ran combofix.. Internet is back working! is the Log below what you are after?
Thanks again,
Dwayne
ComboFix 10-01-04.01 - Dwayne 08/01/2010 18:55:10.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1022.561 [GMT 11:00]
Running from: c:\program files\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Spyware Doctor with AntiVirus *On-access scanning disabled* (Updated) {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Dwayne\Application Data\inst.exe
c:\documents and settings\Dwayne\Application Data\Microsoft\Internet Explorer\Quick Launch\Advanced Virus Remover.lnk
c:\documents and settings\Dwayne\Application Data\Microsoft\Internet Explorer\Quick Launch\Internet Security 2010.lnk
c:\documents and settings\Dwayne\Local Settings\Application Data\emhudv
c:\documents and settings\Dwayne\Local Settings\Application Data\emhudv\cmdxsysguard.exe
C:\s
c:\windows\system32\10334.exe
c:\windows\system32\11478.exe
c:\windows\system32\12371.exe
c:\windows\system32\12548.exe
c:\windows\system32\13701.exe
c:\windows\system32\1413198755.dat
c:\windows\system32\14582.exe
c:\windows\system32\14932.exe
c:\windows\system32\15724.exe
c:\windows\system32\16011.exe
c:\windows\system32\18467.exe
c:\windows\system32\18577.exe
c:\windows\system32\19007.exe
c:\windows\system32\19169.exe
c:\windows\system32\19624.exe
c:\windows\system32\22118.exe
c:\windows\system32\22305.exe
c:\windows\system32\2275.exe
c:\windows\system32\22862.exe
c:\windows\system32\24172.exe
c:\windows\system32\25338.exe
c:\windows\system32\25973.exe
c:\windows\system32\26163.exe
c:\windows\system32\26500.exe
c:\windows\system32\26995.exe
c:\windows\system32\2730.exe
c:\windows\system32\27462.exe
c:\windows\system32\27501.exe
c:\windows\system32\28656.exe
c:\windows\system32\30152.exe
c:\windows\system32\31615.exe
c:\windows\system32\31808.exe
c:\windows\system32\31909.exe
c:\windows\system32\32121.exe
c:\windows\system32\3595.exe
c:\windows\system32\41.exe
c:\windows\system32\4234.exe
c:\windows\system32\4273.exe
c:\windows\system32\5416.exe
c:\windows\system32\6334.exe
c:\windows\system32\7112.exe
c:\windows\system32\833.exe
c:\windows\system32\AVR10.exe
c:\windows\system32\critical_warning.html
c:\windows\system32\flags.ini
c:\windows\system32\kbdsock.dll
c:\windows\system32\mshlps.dll
c:\windows\system32\Thumbs.db
c:\windows\system32\uses32.dat
c:\windows\system32\winhelper86.dll
c:\windows\TEMP\logishrd\LVPrcInj01.dll
.
((((((((((((((((((((((((( Files Created from 2009-12-08 to 2010-01-08 )))))))))))))))))))))))))))))))
.
2010-01-08 07:45 . 2010-01-08 07:41 3819182 ----a-r- c:\program files\ComboFix.exe
2010-01-07 08:34 . 2010-01-07 08:28 16883056 ----a-w- c:\program files\IE8-WindowsXP-x86-ENU.exe
2010-01-07 02:12 . 2010-01-07 02:12 -------- d-----w- c:\documents and settings\Owner
2010-01-07 00:54 . 2010-01-07 00:54 -------- d-----w- c:\program files\Common Files\Skype
2010-01-06 23:23 . 2004-08-04 10:00 31232 -c--a-w- c:\windows\system32\dllcache\weitekp9.sys
2010-01-06 23:23 . 2004-08-04 10:00 41600 -c--a-w- c:\windows\system32\dllcache\weitekp9.dll
2010-01-06 23:23 . 2004-08-04 10:00 48256 -c--a-w- c:\windows\system32\dllcache\w32.dll
2010-01-06 23:23 . 2004-08-04 10:00 14336 -c--a-w- c:\windows\system32\dllcache\tsprof.exe
2010-01-06 23:23 . 2004-08-04 10:00 10240 -c--a-w- c:\windows\system32\dllcache\tmigrate.dll
2010-01-06 23:23 . 2004-08-04 10:00 455168 -c--a-w- c:\windows\system32\dllcache\tintsetp.exe
2010-01-06 23:23 . 2004-08-04 10:00 44032 -c--a-w- c:\windows\system32\dllcache\tintlphr.exe
2010-01-06 23:23 . 2004-08-04 10:00 185344 -c--a-w- c:\windows\system32\dllcache\thawbrkr.dll
2010-01-06 23:23 . 2004-08-04 10:00 21896 -c--a-w- c:\windows\system32\dllcache\tdipx.sys
2010-01-06 23:23 . 2004-08-04 10:00 19464 -c--a-w- c:\windows\system32\dllcache\tdspx.sys
2010-01-06 23:23 . 2004-08-04 10:00 13192 -c--a-w- c:\windows\system32\dllcache\tdasync.sys
2010-01-06 23:21 . 2004-08-04 10:00 33792 -c--a-w- c:\windows\system32\dllcache\lmmib2.dll
2010-01-06 23:20 . 2004-08-04 10:00 331264 -c--a-w- c:\windows\system32\dllcache\aqueue.dll
2010-01-06 22:49 . 2004-08-04 10:00 24661 -c--a-w- c:\windows\system32\dllcache\spxcoins.dll
2010-01-06 22:49 . 2004-08-04 10:00 24661 ----a-w- c:\windows\system32\spxcoins.dll
2010-01-06 22:49 . 2004-08-04 10:00 13312 -c--a-w- c:\windows\system32\dllcache\irclass.dll
2010-01-06 22:49 . 2004-08-04 10:00 13312 ----a-w- c:\windows\system32\irclass.dll
2010-01-06 20:58 . 2010-01-08 08:04 6144 ----a-w- c:\documents and settings\Dwayne\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10001.dll
2010-01-06 20:58 . 2010-01-08 08:04 22528 ----a-w- c:\documents and settings\Dwayne\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10000.dll
2010-01-06 20:56 . 2010-01-06 20:56 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-01-06 19:51 . 2010-01-06 19:51 -------- d-----w- c:\windows\dell
2010-01-06 10:04 . 2004-08-04 10:00 16384 -c--a-w- c:\windows\system32\dllcache\isignup.exe
2009-12-21 11:49 . 2009-12-21 13:27 -------- d-----w- c:\documents and settings\All Users\Application Data\80322621
2009-12-15 11:25 . 2009-12-15 11:25 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple
2009-12-11 21:35 . 2010-01-02 09:38 2066200 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcorex.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-08 08:03 . 2009-11-27 10:36 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-01-08 08:03 . 2008-09-07 06:01 0 ----a-w- c:\windows\system32\drivers\lvuvc.hs
2010-01-08 08:03 . 2008-09-07 05:59 0 ----a-w- c:\windows\system32\drivers\logiflt.iad
2010-01-07 02:13 . 2006-06-22 15:10 -------- d-----w- c:\program files\Microsoft Works
2010-01-07 00:55 . 2008-06-21 10:38 -------- d-----w- c:\documents and settings\Dwayne\Application Data\Skype
2010-01-07 00:54 . 2008-06-21 10:33 -------- d-----r- c:\program files\Skype
2010-01-07 00:54 . 2008-06-21 10:33 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2010-01-07 00:52 . 2008-06-21 10:41 -------- d-----w- c:\documents and settings\Dwayne\Application Data\skypePM
2010-01-06 23:17 . 2004-08-10 05:02 23428 ----a-w- c:\windows\system32\emptyregdb.dat
2010-01-06 23:17 . 2010-01-06 23:17 1663 ----a-w- c:\windows\inf\COM158.tmp
2010-01-06 22:26 . 2009-04-19 00:36 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2010-01-06 22:03 . 2006-06-29 08:33 43760 ----a-w- c:\documents and settings\Dwayne\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-06 20:57 . 2007-06-11 03:06 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-01-06 20:57 . 2007-06-11 03:06 -------- d-----w- c:\documents and settings\Dwayne\Application Data\SUPERAntiSpyware.com
2010-01-06 10:27 . 2006-07-04 06:22 -------- d-----w- c:\program files\Dl_cats
2009-11-27 20:19 . 2009-11-27 10:16 -------- d-----w- c:\program files\Spyware Doctor
2009-11-27 10:37 . 2009-11-27 10:16 -------- d-----w- c:\program files\Common Files\PC Tools
2009-11-27 10:16 . 2009-11-27 10:16 -------- d-----w- c:\documents and settings\Dwayne\Application Data\PC Tools
2009-11-27 10:16 . 2009-11-27 10:16 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
2009-11-27 09:57 . 2009-11-27 09:57 34132720 ----a-w- C:\sdasetup_aff.exe
2009-11-09 23:28 . 2009-11-27 10:36 149456 ----a-w- c:\windows\SGDetectionTool.dll
2009-11-09 23:28 . 2009-11-27 10:36 165840 ----a-w- c:\windows\PCTBDRes.dll
2009-11-09 23:28 . 2009-11-27 10:36 1640400 ----a-w- c:\windows\PCTBDCore.dll
2009-11-09 23:26 . 2009-11-27 10:36 767952 ----a-w- c:\windows\BDTSupport.dll
2009-11-09 00:20 . 2009-11-27 10:16 207792 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2009-10-30 00:11 . 2009-11-27 10:17 233136 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2009-10-27 14:36 . 2009-11-27 10:36 1152444 ----a-w- c:\windows\UDB.zip
2007-05-20 01:58 . 2007-05-20 01:58 21612432 ----a-w- c:\program files\DivXInstaller.exe
2006-09-07 08:03 . 2006-09-07 08:03 3064200 ----a-w- c:\program files\LimeWireWin-full.exe
2006-09-07 08:00 . 2006-09-07 07:59 359112 ----a-w- c:\program files\LimeWireWin.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-09-22 39408]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-08-19 1576176]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DLCDCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLCDtime.dll" [2005-09-13 73728]
"MCUpdateExe"="c:\progra~1\mcafee.com\agent\mcupdate.exe" [2006-01-11 212992]
"MSKDetectorExe"="c:\program files\McAfee\SpamKiller\MSKDetct.exe" [2006-11-07 1121280]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-02-13 2196240]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-05 344064]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-12-11 2043160]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-07-03 180269]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-04 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-21 305440]
"SigmatelSysTrayApp"="stsystra.exe" [2005-03-22 339968]
c:\documents and settings\Dwayne\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - c:\movies\LimeWire\LimeWire.exe [2009-8-1 139776]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-6-23 24576]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2008-9-7 66864]
McAfee Security Scan.lnk - c:\program files\McAfee Security Scan\1.0.150\SSScheduler.exe [2009-7-28 199184]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-12 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-07-23 05:28 352256 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-17 23:06 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2004-08-04 10:00 15360 ------w- c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
2005-05-14 18:04 332800 ----a-w- c:\program files\Dell Support\DSAgnt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dlcdmon.exe]
2005-10-06 12:01 430080 ----a-w- c:\program files\Dell Photo AIO Printer 944\dlcdmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DMXLauncher]
2005-10-31 19:12 94208 ----a-w- c:\program files\Dell\Media Experience\DMXLauncher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InternodeUsage]
2008-10-14 07:46 1339904 ----a-w- c:\progra~1\INTERN~2\mum.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
2004-07-27 08:50 221184 ----a-w- c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
2004-07-27 08:50 81920 ----a-w- c:\program files\Common Files\InstallShield\UpdateService\issch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechCommunicationsManager]
2008-02-13 03:02 564496 ----a-w- c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCAgentExe]
2005-09-22 08:59 303104 ----a-w- c:\progra~1\McAfee.com\Agent\mcagent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCUpdateExe]
2006-01-11 02:35 212992 ----a-w- c:\progra~1\McAfee.com\Agent\mcupdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MemoryCardManager]
2005-09-06 09:37 290816 ----a-w- c:\program files\Dell Photo AIO Printer 944\memcard.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSKDetectorExe]
2006-11-07 04:19 1121280 ----a-w- c:\progra~1\McAfee\SPAMKI~1\MSKDetct.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-09-04 14:54 417792 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
2005-03-22 08:20 339968 ----a-w- c:\windows\stsystra.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
2008-08-19 12:34 1576176 ----a-w- c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2006-07-03 10:32 180269 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
2006-03-30 06:15 313472 ----a-r- c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Movies\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"2275:UDP"= 2275:UDP:Windows Media Format SDK (iexplore.exe)
"2274:UDP"= 2274:UDP:Windows Media Format SDK (iexplore.exe)
"2448:UDP"= 2448:UDP:Windows Media Format SDK (iexplore.exe)
"2449:UDP"= 2449:UDP:Windows Media Format SDK (iexplore.exe)
"2899:UDP"= 2899:UDP:Windows Media Format SDK (iexplore.exe)
"2898:UDP"= 2898:UDP:Windows Media Format SDK (iexplore.exe)
"3080:UDP"= 3080:UDP:Windows Media Format SDK (iexplore.exe)
"3081:UDP"= 3081:UDP:Windows Media Format SDK (iexplore.exe)
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [27/11/2009 9:16 PM 207792]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [19/04/2009 11:36 AM 335240]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [19/08/2008 11:34 PM 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [19/08/2008 11:34 PM 55024]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [19/04/2009 11:36 AM 297752]
R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\Spyware Doctor\BDT\BDTUpdateService.exe [27/11/2009 9:36 PM 112592]
R3 dlcd_device;dlcd_device;c:\windows\system32\dlcdcoms.exe -service --> c:\windows\system32\dlcdcoms.exe -service [?]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [19/08/2008 11:34 PM 7408]
.
Contents of the 'Scheduled Tasks' folder
2009-12-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 01:34]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.google.com/uSearch Page =
hxxp://www.google.comuSearchMigratedDefaultURL =
hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8uSearch Bar =
hxxp://www.google.com/iemDefault_Search_URL =
hxxp://www.google.com/ieuInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride =
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
Name-Space Handler: ftp\* - {419A0123-4312-1122-A0C0-434FDA6DA542} - c:\program files\CoreFTP\pftpns.dll
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Internet Security 2010 - c:\program files\InternetSecurity2010\IS2010.exe
HKCU-Run-rtaxkmxp - c:\documents and settings\Dwayne\Local Settings\Application Data\emhudv\cmdxsysguard.exe
HKLM-Run-rtaxkmxp - c:\documents and settings\Dwayne\Local Settings\Application Data\emhudv\cmdxsysguard.exe
SharedTaskScheduler-IPC Configuration Utility - (no file)
MSConfigStartUp-alg - c:\windows\alg.exe
MSConfigStartUp-Deluxe Tree - c:\documents and settings\Dwayne\Desktop\Christmas.exe
MSConfigStartUp-MPFExe - c:\progra~1\McAfee.com\PERSON~1\MpfTray.exe
MSConfigStartUp-MSKAGENTEXE - c:\progra~1\McAfee\SPAMKI~1\MskAgent.exe
MSConfigStartUp-netc - c:\windows\svc.exe
MSConfigStartUp-netsv32 - c:\windows\sv.exe
MSConfigStartUp-netw - c:\windows\svw.exe
MSConfigStartUp-Network Associates Error Reporting Service - c:\program files\Common Files\Network Associates\TalkBack\TBMon.exe
MSConfigStartUp-netx - c:\windows\svx.exe
MSConfigStartUp-odb - c:\windows\odb.exe
MSConfigStartUp-odby - c:\windows\odb.exe
MSConfigStartUp-runsql - c:\windows\runsql.exe
MSConfigStartUp-sms - c:\windows\sms.exe
MSConfigStartUp-spool - c:\windows\spool.exe
MSConfigStartUp-SunServer - c:\program files\Sunbelt Software\CounterSpy\Consumer\sunserver.exe
MSConfigStartUp-taskmg - c:\windows\taskmg.exe
MSConfigStartUp-UpdateWin - c:\windows\system32\1037v.exe
MSConfigStartUp-vlc - c:\windows\vlc.exe
MSConfigStartUp-wdmon - c:\windows\wdmon.exe
AddRemove-WebCyberCoach_wtrb - c:\program files\WebCyberCoach\b_Dell\WCC_Wipe.exe WebCyberCoach ext\wtrb
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-08 19:04
Windows 5.1.2600 Service Pack 2 NTFS
scanning hȋdden processes ...
scanning hȋdden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCDCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLCDtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hȋdden files ...
scan completed successfully
hȋdden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(644)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
- - - - - - - > 'explorer.exe'(2972)
c:\windows\TEMP\logishrd\LVPrcInj01.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\progra~1\AVG\AVG8\avgrsx.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\progra~1\mcafee.com\agent\mctskshd.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\windows\system32\dlcdcoms.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Common Files\Logishrd\LQCVFX\COCIManager.exe
.
**************************************************************************
.
Completion time: 2010-01-08 19:11:50 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-08 08:11
ComboFix2.txt 2007-06-11 04:49
Pre-Run: 79,320,023,040 bytes free
Post-Run: 82,412,445,696 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - 478094BDE7F1F1A1E61A3A5E33A549A9