Hi and Sorry. I thought it would help to 'bump' this thread.
ComboFix 10-01-17.02 - Erin 01/18/2010 8:20.1.2 - x86
Microsoft
Windows Vista
Home Premium 6.0.6002.2.1252.1.1033.18.2036.898 [GMT -5:00]
Running from: c:\users\Erin\Downloads\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-1400113804-1914402855-3429530994-500
c:\$recycle.bin\S-1-5-21-2152478756-3922319563-605102323-500
c:\$recycle.bin\S-1-5-21-3168843342-2594981274-797375477-500
.
((((((((((((((((((((((((( Files Created from 2009-12-18 to 2010-01-18 )))))))))))))))))))))))))))))))
.
2010-01-18 13:18 . 2010-01-18 13:19 -------- d-----w- C:\32788R22FWJFW
2010-01-17 16:06 . 2010-01-17 16:30 -------- d-----w- c:\program files\Spyware Doctor
2010-01-17 16:06 . 2010-01-17 16:30 -------- d-----w- c:\program files\Common Files\PC Tools
2010-01-17 16:01 . 2009-10-19 13:38 156672 ----a-w- c:\windows\system32\t2embed.dll
2010-01-17 16:01 . 2009-10-19 13:35 72704 ----a-w- c:\windows\system32\fontsub.dll
2010-01-17 15:43 . 2010-01-17 15:45 680 ----a-w- c:\users\Erin\AppData\Local\d3d9caps.dat
2009-12-24 21:20 . 2009-12-24 21:20 690952 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-18 08:02 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-01-13 18:00 . 2008-03-27 03:06 10036 ----a-w- c:\users\Erin\AppData\Roaming\wklnhst.dat
2010-01-07 13:01 . 2008-08-11 15:36 -------- d-----w- c:\users\Erin\AppData\Roaming\skypePM
2010-01-05 00:00 . 2008-08-11 15:34 -------- d-----w- c:\users\Erin\AppData\Roaming\Skype
2009-12-06 22:51 . 2009-12-04 15:40 -------- d-----w- c:\users\Erin\AppData\Roaming\Samsung
2009-12-06 22:51 . 2009-12-04 15:39 -------- d-----w- c:\program files\Samsung
2009-12-06 22:51 . 2008-03-18 23:29 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-06 22:51 . 2009-12-04 15:39 -------- d-----w- c:\program files\PC Connectivity Solution
2009-12-04 15:43 . 2009-12-04 15:43 -------- d-----w- c:\programdata\PC Suite
2009-12-04 15:43 . 2009-12-04 15:43 -------- d-----w- c:\users\Erin\AppData\Roaming\PC Suite
2009-12-04 15:40 . 2009-12-04 15:40 -------- d-----w- c:\program files\DIFX
2009-12-02 22:48 . 2009-12-02 22:48 -------- d-----w- c:\users\Erin\AppData\Roaming\PeerNetworking
2009-12-02 22:45 . 2008-03-18 23:33 -------- d-----w- c:\program files\Roxio
2009-12-01 08:19 . 2009-12-01 08:19 -------- d-----w- c:\program files\Windows Portable Devices
2009-12-01 08:19 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-12-01 08:18 . 2009-12-01 08:18 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-11-30 15:00 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar
2009-11-30 15:00 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Photo Gallery
2009-11-30 15:00 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Journal
2009-11-30 15:00 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Collaboration
2009-11-30 15:00 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Calendar
2009-11-30 15:00 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender
2009-11-09 12:31 . 2009-12-09 08:02 24064 ----a-w- c:\windows\system32\nshhttp.dll
2009-11-09 12:30 . 2009-12-09 08:02 30720 ----a-w- c:\windows\system32\httpapi.dll
2009-11-09 10:36 . 2009-12-09 08:02 411648 ----a-w- c:\windows\system32\drivers\http.sys
2009-11-03 01:42 . 2009-10-03 02:47 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-10-29 09:17 . 2009-11-25 08:01 2048 ----a-w- c:\windows\system32\tzres.dll
2009-10-27 14:11 . 2009-12-09 01:14 834048 ----a-w- c:\windows\system32\wininet.dll
2009-10-27 13:16 . 2009-12-09 01:14 78336 ----a-w- c:\windows\system32\ieencode.dll
2008-03-19 07:08 . 2008-03-19 06:54 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2007-05-25 17920]
"RtHDVCpl"="RtHDVCpl.exe" [2007-05-11 4452352]
"PMX Daemon"="ICO.EXE" [2006-11-08 49152]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 81920]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 221184]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-02-01 385024]
"FaxCenterServer"="c:\program files\Dell PC Fax\fm3032.exe" [2006-11-03 312200]
"dlcxmon.exe"="c:\program files\Dell Photo AIO Printer 926\dlcxmon.exe" [2007-01-12 292336]
"MemoryCardManager"="c:\program files\Dell Photo AIO Printer 926\memcard.exe" [2006-11-03 304008]
"DLCXCATS"="c:\windows\system32\spool\DRIVERS\W32X86\3\DLCXtime.dll" [2006-10-16 106496]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-12 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-12 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-12 133656]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
c:\users\Erin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Picture Motion Browser Media Check Tool.lnk - c:\program files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe [2008-4-27 385024]
wkcalrem.LNK - c:\program files\Microsoft Works\WkCalRem.exe [2007-11-28 46432]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2008-3-18 50688]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):1c,76,ee,8c,ce,71,ca,01
R2 dlcx_device;dlcx_device;c:\windows\system32\dlcxcoms.exe -service --> c:\windows\system32\dlcxcoms.exe -service [?]
R3 pmxmouse;PMXMOUSE;c:\windows\System32\drivers\pmxmouse.sys [3/18/2008 6:29 PM 18432]
R3 pmxusblf;PMXUSBLF;c:\windows\System32\drivers\pmxusblf.sys [3/18/2008 6:29 PM 19008]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [6/17/2008 11:54 AM 21504]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\System32\FsUsbExDisk.Sys [12/4/2009 10:40 AM 36608]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - PCTSDINJDRIVER32
*Deregistered* - PCTSDInjDriver32
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
2010-01-17 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-06-26 00:01]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.yahoo.com/LSP: c:\windows\system32\wpclsp.dll
FF - ProfilePath - c:\users\Erin\AppData\Roaming\Mozilla\Firefox\Profiles\unlahzbb.default\
FF - prefs.js: browser.startup.homepage -
hxxp://www.yahoo.com/FF - plugin: c:\program files\Google\Google Updater\2.4.1601.7122\npCIDetect13.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava11.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava12.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava13.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava14.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava32.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjpi160.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npoji610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmidas.dll
FF - hȋdden: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-01-18 08:28
Windows 6.0.6002 Service Pack 2 NTFS
scanning hȋdden processes ...
scanning hȋdden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCXCATS = rundll32 c:\windows\system32\spool\DRIVERS\W32X86\3\DLCXtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hȋdden files ...
scan completed successfully
hȋdden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2010-01-18 08:31:50
ComboFix-quarantined-files.txt 2010-01-18 13:31
Pre-Run: 220,505,247,744 bytes free
Post-Run: 220,538,757,120 bytes free
- - End Of File - - F042F8202B60826BC0D94B245F74DA56