Oops. I updated combo-fix and reran. I think there's some adventitious stuff at the end:
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.485 [GMT -5:00]
Running from: c:\documents and settings\Gene Barnes\Desktop\Combo-Fix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((( Files Created from 2009-12-21 to 2010-01-21 )))))))))))))))))))))))))))))))
.
2010-01-20 20:39 . 2010-01-20 20:39 -------- d-----w- c:\documents and settings\Gene Barnes\Application Data\Malwarebytes
2010-01-20 20:38 . 2010-01-07 21:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-20 20:38 . 2010-01-20 20:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-01-20 20:38 . 2010-01-20 20:39 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-20 20:38 . 2010-01-07 21:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-20 13:30 . 2010-01-20 13:30 -------- d-----w- c:\program files\Sun
2010-01-20 13:30 . 2010-01-20 13:30 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-01-19 09:42 . 2009-10-30 16:11 233136 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2010-01-19 09:42 . 2009-11-09 16:20 207792 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2010-01-19 09:42 . 2009-10-06 21:31 87784 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2010-01-19 09:42 . 2009-09-03 14:45 70408 ----a-w- c:\windows\system32\drivers\pctplsg.sys
2010-01-19 09:42 . 2010-01-19 10:11 -------- d-----w- c:\program files\Spyware Doctor
2010-01-19 09:42 . 2010-01-19 09:42 -------- d-----w- c:\program files\Common Files\PC Tools
2010-01-19 09:42 . 2010-01-19 09:42 -------- d-----w- c:\documents and settings\Gene Barnes\Application Data\PC Tools
2010-01-19 09:42 . 2010-01-19 09:42 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
2010-01-19 03:13 . 2010-01-19 03:13 -------- d-----w- c:\program files\ESET
2010-01-17 14:47 . 2010-01-20 03:00 -------- d-----w- c:\documents and settings\Gene Barnes\Local Settings\Application Data\lggocl
2010-01-13 13:17 . 2009-11-21 15:51 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-01-09 15:33 . 2010-01-12 15:00 1924744 ----a-w- c:\documents and settings\Gene Barnes\Application Data\Macromedia\Flash Player\
www.macromedia.com\bin\fpupdatepl\fpupdatepl.exe.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-21 05:51 . 2008-09-17 22:59 -------- d-----w- c:\documents and settings\Gene Barnes\Application Data\OpenOffice.org2
2010-01-21 05:50 . 2008-09-19 02:16 -------- d-----w- c:\program files\Dl_cats
2010-01-20 16:23 . 2008-09-30 00:43 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-01-20 16:19 . 2008-09-30 01:01 -------- d-----w- c:\program files\Microsoft Silverlight
2010-01-20 13:31 . 2008-09-11 15:57 -------- d-----w- c:\program files\Common Files\Java
2010-01-20 13:30 . 2008-09-11 15:57 -------- d-----w- c:\program files\Java
2010-01-14 16:12 . 2009-12-08 02:02 181120 ------w- c:\windows\system32\MpSigStub.exe
2010-01-12 13:53 . 2008-11-10 23:16 1 ----a-w- c:\documents and settings\Gene Barnes\Application Data\OpenOffice.org2\user\uno_packages\cache\stamp.sys
2010-01-06 20:00 . 2008-09-11 15:34 -------- d-----w- c:\program files\Common Files\Adobe
2009-12-22 14:43 . 2009-12-12 14:37 2066200 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcorex.dll
2009-12-16 18:27 . 2009-12-16 18:27 -------- d-----w- c:\documents and settings\Elaine\Application Data\OpenOffice.org2
2009-12-11 04:17 . 2008-12-21 18:29 20 ---h--w- c:\documents and settings\All Users\Application Data\PKP_DLec.DAT
2009-12-08 13:53 . 2008-11-10 01:19 -------- d-----w- c:\documents and settings\Gene Barnes\Application Data\Apple Computer
2009-12-08 02:00 . 2009-12-08 02:00 26232 ---ha-w- c:\windows\system32\mlfcache.dat
2009-12-07 15:37 . 2009-12-07 15:36 -------- d-----w- c:\program files\iTunes
2009-12-07 15:37 . 2009-12-07 15:36 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-12-07 15:36 . 2009-12-07 15:36 -------- d-----w- c:\program files\iPod
2009-12-07 15:36 . 2008-11-10 01:11 -------- d-----w- c:\program files\Common Files\Apple
2009-12-07 15:35 . 2009-12-07 15:34 -------- d-----w- c:\program files\QuickTime
2009-12-07 15:31 . 2009-12-07 15:31 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2009-12-07 15:29 . 2009-12-07 15:29 -------- d-----w- c:\program files\Safari
2009-12-07 15:28 . 2009-12-07 15:28 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\Safari 5.31.21.10\SetupAdmin.exe
2009-12-07 15:28 . 2009-12-07 15:28 -------- d-----w- c:\program files\Bonjour
2009-12-07 14:21 . 2008-09-11 17:58 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-12-07 14:21 . 2008-09-11 17:58 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-12-07 14:21 . 2008-09-11 17:58 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-11-23 23:06 . 2008-12-26 02:20 -------- d-----w- c:\documents and settings\Gene Barnes\Application Data\uTorrent
2009-11-21 15:51 . 2006-03-15 12:00 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-10-29 07:46 . 2006-03-15 12:00 832512 ------w- c:\windows\system32\wininet.dll
2009-10-29 07:46 . 2006-03-15 12:00 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-10-29 07:46 . 2006-03-15 12:00 17408 ----a-w- c:\windows\system32\corpol.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\Gene Barnes\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-12-25 135664]
"PowerDVD"="c:\program files\CyberLink\PowerDVD\PowerDVD.exe" [2007-01-10 955952]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-03 866584]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-12-12 2043160]
"SigmatelSysTrayApp"="stsystra.exe" [2005-03-22 339968]
"dlcdmon.exe"="c:\program files\Dell Photo AIO Printer 944\dlcdmon.exe" [2005-10-07 430080]
"MemoryCardManager"="c:\program files\Dell Photo AIO Printer 944\memcard.exe" [2005-09-07 290816]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"DLCDCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLCDtime.dll" [2005-09-14 73728]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]
c:\documents and settings\Gene Barnes\Start Menu\Programs\Startup\
OpenOffice.org 2.4.lnk - c:\program files\OpenOffice.org 2.4\program\quickstart.exe [2008-1-21 393216]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
NkbMonitor.exe.lnk - c:\program files\Nikon\PictureProject\NkbMonitor.exe [2008-12-21 118784]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-12-07 14:21 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-10-03 09:08 35696 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
2005-08-05 17:56 64512 ----a-w- c:\windows\ehome\ehtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
2005-10-15 02:46 77824 ----a-w- c:\windows\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
2005-10-15 02:50 114688 ----a-w- c:\windows\system32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]
2005-10-15 02:49 94208 ----a-w- c:\windows\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
2006-12-06 02:55 54832 ----a-w- c:\program files\CyberLink\PowerDVD\Language\Language.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2006-01-12 19:40 155648 ----a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
2006-11-23 19:10 56928 ------w- c:\program files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2008-08-18 22:41 1832272 --sha-r- c:\program files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2008-06-10 08:27 144784 ----a-w- c:\program files\Java\jre1.6.0_07\bin\jusched.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Common Files\\Ahead\\Nero Web\\SetupX.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Documents and Settings\\Gene Barnes\\Application Data\\Macromedia\\Flash Player\\
www.macromedia.com\\bin\\octoshape\\octoshape.exe"="c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [1/19/2010 4:42 AM 207792]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [9/11/2008 12:58 PM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [9/11/2008 12:58 PM 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [9/11/2008 12:58 PM 908056]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [9/11/2008 12:58 PM 297752]
R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [1/19/2010 4:42 AM 359624]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 6:19 PM 13592]
R3 dlcd_device;dlcd_device;c:\windows\system32\dlcdcoms.exe -service --> c:\windows\system32\dlcdcoms.exe -service [?]
.
Contents of the 'Scheduled Tasks' folder
2010-01-20 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
2010-01-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1220945662-746137067-725345543-1003Core.job
- c:\documents and settings\Gene Barnes\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-12-25 14:07]
2010-01-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1220945662-746137067-725345543-1003UA.job
- c:\documents and settings\Gene Barnes\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-12-25 14:07]
2010-01-21 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 23:20]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.yahoo.com/FF - ProfilePath - c:\documents and settings\Gene Barnes\Application Data\Mozilla\Firefox\Profiles\czizpajo.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - plugin: c:\documents and settings\Gene Barnes\Local Settings\Application Data\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
.
**************************************************************************
scanning hȋdden processes ...
scanning hȋdden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCDCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLCDtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hȋdden files ...
scan completed successfully
hȋdden files:
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(708)
c:\windows\system32\igfxdev.dll
- - - - - - - > 'explorer.exe'(252)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-01-21 12:57:33
ComboFix-quarantined-files.txt 2010-01-21 17:57
ComboFix2.txt 2010-01-21 05:56
Pre-Run: 135,286,095,872 bytes free
Post-Run: 135,241,986,048 bytes free
- - End Of File - - 097196A9EF792C2D13D87FFF0288F697
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.485 [GMT -5:00]
Running from: c:\documents and settings\Gene Barnes\Desktop\Combo-Fix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((( Files Created from 2009-12-21 to 2010-01-21 )))))))))))))))))))))))))))))))
.
2010-01-20 20:39 . 2010-01-20 20:39 -------- d-----w- c:\documents and settings\Gene Barnes\Application Data\Malwarebytes
2010-01-20 20:38 . 2010-01-07 21:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-20 20:38 . 2010-01-20 20:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-01-20 20:38 . 2010-01-20 20:39 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-20 20:38 . 2010-01-07 21:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-20 13:30 . 2010-01-20 13:30 -------- d-----w- c:\program files\Sun
2010-01-20 13:30 . 2010-01-20 13:30 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-01-19 09:42 . 2009-10-30 16:11 233136 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2010-01-19 09:42 . 2009-11-09 16:20 207792 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2010-01-19 09:42 . 2009-10-06 21:31 87784 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2010-01-19 09:42 . 2009-09-03 14:45 70408 ----a-w- c:\windows\system32\drivers\pctplsg.sys
2010-01-19 09:42 . 2010-01-19 10:11 -------- d-----w- c:\program files\Spyware Doctor
2010-01-19 09:42 . 2010-01-19 09:42 -------- d-----w- c:\program files\Common Files\PC Tools
2010-01-19 09:42 . 2010-01-19 09:42 -------- d-----w- c:\documents and settings\Gene Barnes\Application Data\PC Tools
2010-01-19 09:42 . 2010-01-19 09:42 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
2010-01-19 03:13 . 2010-01-19 03:13 -------- d-----w- c:\program files\ESET
2010-01-17 14:47 . 2010-01-20 03:00 -------- d-----w- c:\documents and settings\Gene Barnes\Local Settings\Application Data\lggocl
2010-01-13 13:17 . 2009-11-21 15:51 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-01-09 15:33 . 2010-01-12 15:00 1924744 ----a-w- c:\documents and settings\Gene Barnes\Application Data\Macromedia\Flash Player\
www.macromedia.com\bin\fpupdatepl\fpupdatepl.exe.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-21 05:51 . 2008-09-17 22:59 -------- d-----w- c:\documents and settings\Gene Barnes\Application Data\OpenOffice.org2
2010-01-21 05:50 . 2008-09-19 02:16 -------- d-----w- c:\program files\Dl_cats
2010-01-20 16:23 . 2008-09-30 00:43 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-01-20 16:19 . 2008-09-30 01:01 -------- d-----w- c:\program files\Microsoft Silverlight
2010-01-20 13:31 . 2008-09-11 15:57 -------- d-----w- c:\program files\Common Files\Java
2010-01-20 13:30 . 2008-09-11 15:57 -------- d-----w- c:\program files\Java
2010-01-14 16:12 . 2009-12-08 02:02 181120 ------w- c:\windows\system32\MpSigStub.exe
2010-01-12 13:53 . 2008-11-10 23:16 1 ----a-w- c:\documents and settings\Gene Barnes\Application Data\OpenOffice.org2\user\uno_packages\cache\stamp.sys
2010-01-06 20:00 . 2008-09-11 15:34 -------- d-----w- c:\program files\Common Files\Adobe
2009-12-22 14:43 . 2009-12-12 14:37 2066200 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcorex.dll
2009-12-16 18:27 . 2009-12-16 18:27 -------- d-----w- c:\documents and settings\Elaine\Application Data\OpenOffice.org2
2009-12-11 04:17 . 2008-12-21 18:29 20 ---h--w- c:\documents and settings\All Users\Application Data\PKP_DLec.DAT
2009-12-08 13:53 . 2008-11-10 01:19 -------- d-----w- c:\documents and settings\Gene Barnes\Application Data\Apple Computer
2009-12-08 02:00 . 2009-12-08 02:00 26232 ---ha-w- c:\windows\system32\mlfcache.dat
2009-12-07 15:37 . 2009-12-07 15:36 -------- d-----w- c:\program files\iTunes
2009-12-07 15:37 . 2009-12-07 15:36 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-12-07 15:36 . 2009-12-07 15:36 -------- d-----w- c:\program files\iPod
2009-12-07 15:36 . 2008-11-10 01:11 -------- d-----w- c:\program files\Common Files\Apple
2009-12-07 15:35 . 2009-12-07 15:34 -------- d-----w- c:\program files\QuickTime
2009-12-07 15:31 . 2009-12-07 15:31 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2009-12-07 15:29 . 2009-12-07 15:29 -------- d-----w- c:\program files\Safari
2009-12-07 15:28 . 2009-12-07 15:28 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\Safari 5.31.21.10\SetupAdmin.exe
2009-12-07 15:28 . 2009-12-07 15:28 -------- d-----w- c:\program files\Bonjour
2009-12-07 14:21 . 2008-09-11 17:58 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-12-07 14:21 . 2008-09-11 17:58 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-12-07 14:21 . 2008-09-11 17:58 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-11-23 23:06 . 2008-12-26 02:20 -------- d-----w- c:\documents and settings\Gene Barnes\Application Data\uTorrent
2009-11-21 15:51 . 2006-03-15 12:00 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-10-29 07:46 . 2006-03-15 12:00 832512 ------w- c:\windows\system32\wininet.dll
2009-10-29 07:46 . 2006-03-15 12:00 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-10-29 07:46 . 2006-03-15 12:00 17408 ----a-w- c:\windows\system32\corpol.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\Gene Barnes\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-12-25 135664]
"PowerDVD"="c:\program files\CyberLink\PowerDVD\PowerDVD.exe" [2007-01-10 955952]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-03 866584]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-12-12 2043160]
"SigmatelSysTrayApp"="stsystra.exe" [2005-03-22 339968]
"dlcdmon.exe"="c:\program files\Dell Photo AIO Printer 944\dlcdmon.exe" [2005-10-07 430080]
"MemoryCardManager"="c:\program files\Dell Photo AIO Printer 944\memcard.exe" [2005-09-07 290816]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"DLCDCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLCDtime.dll" [2005-09-14 73728]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]
c:\documents and settings\Gene Barnes\Start Menu\Programs\Startup\
OpenOffice.org 2.4.lnk - c:\program files\OpenOffice.org 2.4\program\quickstart.exe [2008-1-21 393216]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
NkbMonitor.exe.lnk - c:\program files\Nikon\PictureProject\NkbMonitor.exe [2008-12-21 118784]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-12-07 14:21 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-10-03 09:08 35696 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
2005-08-05 17:56 64512 ----a-w- c:\windows\ehome\ehtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
2005-10-15 02:46 77824 ----a-w- c:\windows\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
2005-10-15 02:50 114688 ----a-w- c:\windows\system32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]
2005-10-15 02:49 94208 ----a-w- c:\windows\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
2006-12-06 02:55 54832 ----a-w- c:\program files\CyberLink\PowerDVD\Language\Language.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2006-01-12 19:40 155648 ----a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
2006-11-23 19:10 56928 ------w- c:\program files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2008-08-18 22:41 1832272 --sha-r- c:\program files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2008-06-10 08:27 144784 ----a-w- c:\program files\Java\jre1.6.0_07\bin\jusched.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Common Files\\Ahead\\Nero Web\\SetupX.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Documents and Settings\\Gene Barnes\\Application Data\\Macromedia\\Flash Player\\
www.macromedia.com\\bin\\octoshape\\octoshape.exe"="c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [1/19/2010 4:42 AM 207792]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [9/11/2008 12:58 PM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [9/11/2008 12:58 PM 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [9/11/2008 12:58 PM 908056]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [9/11/2008 12:58 PM 297752]
R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [1/19/2010 4:42 AM 359624]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 6:19 PM 13592]
R3 dlcd_device;dlcd_device;c:\windows\system32\dlcdcoms.exe -service --> c:\windows\system32\dlcdcoms.exe -service [?]
.
Contents of the 'Scheduled Tasks' folder
2010-01-20 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
2010-01-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1220945662-746137067-725345543-1003Core.job
- c:\documents and settings\Gene Barnes\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-12-25 14:07]
2010-01-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1220945662-746137067-725345543-1003UA.job
- c:\documents and settings\Gene Barnes\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-12-25 14:07]
2010-01-21 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 23:20]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.yahoo.com/FF - ProfilePath - c:\documents and settings\Gene Barnes\Application Data\Mozilla\Firefox\Profiles\czizpajo.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - plugin: c:\documents and settings\Gene Barnes\Local Settings\Application Data\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
.
**************************************************************************
scanning hȋdden processes ...
scanning hȋdden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCDCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLCDtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hȋdden files ...
scan completed successfully
hȋdden files:
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(708)
c:\windows\system32\igfxdev.dll
- - - - - - - > 'explorer.exe'(252)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-01-21 12:57:33
ComboFix-quarantined-files.txt 2010-01-21 17:57
ComboFix2.txt 2010-01-21 05:56
Pre-Run: 135,286,095,872 bytes free
Post-Run: 135,241,986,048 bytes free
- - End Of File - - 097196A9EF792C2D13D87FFF0288F697
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.485 [GMT -5:00]
Running from: c:\documents and settings\Gene Barnes\Desktop\Combo-Fix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((( Files Created from 2009-12-21 to 2010-01-21 )))))))))))))))))))))))))))))))
.
2010-01-20 20:39 . 2010-01-20 20:39 -------- d-----w- c:\documents and settings\Gene Barnes\Application Data\Malwarebytes
2010-01-20 20:38 . 2010-01-07 21:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-20 20:38 . 2010-01-20 20:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-01-20 20:38 . 2010-01-20 20:39 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-20 20:38 . 2010-01-07 21:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-20 13:30 . 2010-01-20 13:30 -------- d-----w- c:\program files\Sun
2010-01-20 13:30 . 2010-01-20 13:30 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-01-19 09:42 . 2009-10-30 16:11 233136 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2010-01-19 09:42 . 2009-11-09 16:20 207792 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2010-01-19 09:42 . 2009-10-06 21:31 87784 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2010-01-19 09:42 . 2009-09-03 14:45 70408 ----a-w- c:\windows\system32\drivers\pctplsg.sys
2010-01-19 09:42 . 2010-01-19 10:11 -------- d-----w- c:\program files\Spyware Doctor
2010-01-19 09:42 . 2010-01-19 09:42 -------- d-----w- c:\program files\Common Files\PC Tools
2010-01-19 09:42 . 2010-01-19 09:42 -------- d-----w- c:\documents and settings\Gene Barnes\Application Data\PC Tools
2010-01-19 09:42 . 2010-01-19 09:42 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
2010-01-19 03:13 . 2010-01-19 03:13 -------- d-----w- c:\program files\ESET
2010-01-17 14:47 . 2010-01-20 03:00 -------- d-----w- c:\documents and settings\Gene Barnes\Local Settings\Application Data\lggocl
2010-01-13 13:17 . 2009-11-21 15:51 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-01-09 15:33 . 2010-01-12 15:00 1924744 ----a-w- c:\documents and settings\Gene Barnes\Application Data\Macromedia\Flash Player\
www.macromedia.com\bin\fpupdatepl\fpupdatepl.exe.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-21 05:51 . 2008-09-17 22:59 -------- d-----w- c:\documents and settings\Gene Barnes\Application Data\OpenOffice.org2
2010-01-21 05:50 . 2008-09-19 02:16 -------- d-----w- c:\program files\Dl_cats
2010-01-20 16:23 . 2008-09-30 00:43 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-01-20 16:19 . 2008-09-30 01:01 -------- d-----w- c:\program files\Microsoft Silverlight
2010-01-20 13:31 . 2008-09-11 15:57 -------- d-----w- c:\program files\Common Files\Java
2010-01-20 13:30 . 2008-09-11 15:57 -------- d-----w- c:\program files\Java
2010-01-14 16:12 . 2009-12-08 02:02 181120 ------w- c:\windows\system32\MpSigStub.exe
2010-01-12 13:53 . 2008-11-10 23:16 1 ----a-w- c:\documents and settings\Gene Barnes\Application Data\OpenOffice.org2\user\uno_packages\cache\stamp.sys
2010-01-06 20:00 . 2008-09-11 15:34 -------- d-----w- c:\program files\Common Files\Adobe
2009-12-22 14:43 . 2009-12-12 14:37 2066200 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcorex.dll
2009-12-16 18:27 . 2009-12-16 18:27 -------- d-----w- c:\documents and settings\Elaine\Application Data\OpenOffice.org2
2009-12-11 04:17 . 2008-12-21 18:29 20 ---h--w- c:\documents and settings\All Users\Application Data\PKP_DLec.DAT
2009-12-08 13:53 . 2008-11-10 01:19 -------- d-----w- c:\documents and settings\Gene Barnes\Application Data\Apple Computer
2009-12-08 02:00 . 2009-12-08 02:00 26232 ---ha-w- c:\windows\system32\mlfcache.dat
2009-12-07 15:37 . 2009-12-07 15:36 -------- d-----w- c:\program files\iTunes
2009-12-07 15:37 . 2009-12-07 15:36 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-12-07 15:36 . 2009-12-07 15:36 -------- d-----w- c:\program files\iPod
2009-12-07 15:36 . 2008-11-10 01:11 -------- d-----w- c:\program files\Common Files\Apple
2009-12-07 15:35 . 2009-12-07 15:34 -------- d-----w- c:\program files\QuickTime
2009-12-07 15:31 . 2009-12-07 15:31 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2009-12-07 15:29 . 2009-12-07 15:29 -------- d-----w- c:\program files\Safari
2009-12-07 15:28 . 2009-12-07 15:28 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\Safari 5.31.21.10\SetupAdmin.exe
2009-12-07 15:28 . 2009-12-07 15:28 -------- d-----w- c:\program files\Bonjour
2009-12-07 14:21 . 2008-09-11 17:58 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-12-07 14:21 . 2008-09-11 17:58 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-12-07 14:21 . 2008-09-11 17:58 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-11-23 23:06 . 2008-12-26 02:20 -------- d-----w- c:\documents and settings\Gene Barnes\Application Data\uTorrent
2009-11-21 15:51 . 2006-03-15 12:00 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-10-29 07:46 . 2006-03-15 12:00 832512 ------w- c:\windows\system32\wininet.dll
2009-10-29 07:46 . 2006-03-15 12:00 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-10-29 07:46 . 2006-03-15 12:00 17408 ----a-w- c:\windows\system32\corpol.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\Gene Barnes\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-12-25 135664]
"PowerDVD"="c:\program files\CyberLink\PowerDVD\PowerDVD.exe" [2007-01-10 955952]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-03 866584]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-12-12 2043160]
"SigmatelSysTrayApp"="stsystra.exe" [2005-03-22 339968]
"dlcdmon.exe"="c:\program files\Dell Photo AIO Printer 944\dlcdmon.exe" [2005-10-07 430080]
"MemoryCardManager"="c:\program files\Dell Photo AIO Printer 944\memcard.exe" [2005-09-07 290816]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"DLCDCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLCDtime.dll" [2005-09-14 73728]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]
c:\documents and settings\Gene Barnes\Start Menu\Programs\Startup\
OpenOffice.org 2.4.lnk - c:\program files\OpenOffice.org 2.4\program\quickstart.exe [2008-1-21 393216]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
NkbMonitor.exe.lnk - c:\program files\Nikon\PictureProject\NkbMonitor.exe [2008-12-21 118784]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-12-07 14:21 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-10-03 09:08 35696 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
2005-08-05 17:56 64512 ----a-w- c:\windows\ehome\ehtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
2005-10-15 02:46 77824 ----a-w- c:\windows\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
2005-10-15 02:50 114688 ----a-w- c:\windows\system32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]
2005-10-15 02:49 94208 ----a-w- c:\windows\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
2006-12-06 02:55 54832 ----a-w- c:\program files\CyberLink\PowerDVD\Language\Language.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2006-01-12 19:40 155648 ----a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
2006-11-23 19:10 56928 ------w- c:\program files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2008-08-18 22:41 1832272 --sha-r- c:\program files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2008-06-10 08:27 144784 ----a-w- c:\program files\Java\jre1.6.0_07\bin\jusched.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Common Files\\Ahead\\Nero Web\\SetupX.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Documents and Settings\\Gene Barnes\\Application Data\\Macromedia\\Flash Player\\
www.macromedia.com\\bin\\octoshape\\octoshape.exe"="c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [1/19/2010 4:42 AM 207792]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [9/11/2008 12:58 PM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [9/11/2008 12:58 PM 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [9/11/2008 12:58 PM 908056]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [9/11/2008 12:58 PM 297752]
R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [1/19/2010 4:42 AM 359624]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 6:19 PM 13592]
R3 dlcd_device;dlcd_device;c:\windows\system32\dlcdcoms.exe -service --> c:\windows\system32\dlcdcoms.exe -service [?]
.
Contents of the 'Scheduled Tasks' folder
2010-01-20 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
2010-01-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1220945662-746137067-725345543-1003Core.job
- c:\documents and settings\Gene Barnes\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-12-25 14:07]
2010-01-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1220945662-746137067-725345543-1003UA.job
- c:\documents and settings\Gene Barnes\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-12-25 14:07]
2010-01-21 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 23:20]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.yahoo.com/FF - ProfilePath - c:\documents and settings\Gene Barnes\Application Data\Mozilla\Firefox\Profiles\czizpajo.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - plugin: c:\documents and settings\Gene Barnes\Local Settings\Application Data\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
.
**************************************************************************
scanning hȋdden processes ...
scanning hȋdden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCDCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLCDtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hȋdden files ...
scan completed successfully
hȋdden files:
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(708)
c:\windows\system32\igfxdev.dll
- - - - - - - > 'explorer.exe'(252)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-01-21 12:57:33
ComboFix-quarantined-files.txt 2010-01-21 17:57
ComboFix2.txt 2010-01-21 05:56
Pre-Run: 135,286,095,872 bytes free
Post-Run: 135,241,986,048 bytes free
- - End Of File - - 097196A9EF792C2D13D87FFF0288F697
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.485 [GMT -5:00]
Running from: c:\documents and settings\Gene Barnes\Desktop\Combo-Fix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((( Files Created from 2009-12-21 to 2010-01-21 )))))))))))))))))))))))))))))))
.
2010-01-20 20:39 . 2010-01-20 20:39 -------- d-----w- c:\documents and settings\Gene Barnes\Application Data\Malwarebytes
2010-01-20 20:38 . 2010-01-07 21:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-20 20:38 . 2010-01-20 20:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-01-20 20:38 . 2010-01-20 20:39 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-20 20:38 . 2010-01-07 21:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-20 13:30 . 2010-01-20 13:30 -------- d-----w- c:\program files\Sun
2010-01-20 13:30 . 2010-01-20 13:30 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-01-19 09:42 . 2009-10-30 16:11 233136 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2010-01-19 09:42 . 2009-11-09 16:20 207792 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2010-01-19 09:42 . 2009-10-06 21:31 87784 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2010-01-19 09:42 . 2009-09-03 14:45 70408 ----a-w- c:\windows\system32\drivers\pctplsg.sys
2010-01-19 09:42 . 2010-01-19 10:11 -------- d-----w- c:\program files\Spyware Doctor
2010-01-19 09:42 . 2010-01-19 09:42 -------- d-----w- c:\program files\Common Files\PC Tools
2010-01-19 09:42 . 2010-01-19 09:42 -------- d-----w- c:\documents and settings\Gene Barnes\Application Data\PC Tools
2010-01-19 09:42 . 2010-01-19 09:42 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
2010-01-19 03:13 . 2010-01-19 03:13 -------- d-----w- c:\program files\ESET
2010-01-17 14:47 . 2010-01-20 03:00 -------- d-----w- c:\documents and settings\Gene Barnes\Local Settings\Application Data\lggocl
2010-01-13 13:17 . 2009-11-21 15:51 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-01-09 15:33 . 2010-01-12 15:00 1924744 ----a-w- c:\documents and settings\Gene Barnes\Application Data\Macromedia\Flash Player\
www.macromedia.com\bin\fpupdatepl\fpupdatepl.exe.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-21 05:51 . 2008-09-17 22:59 -------- d-----w- c:\documents and settings\Gene Barnes\Application Data\OpenOffice.org2
2010-01-21 05:50 . 2008-09-19 02:16 -------- d-----w- c:\program files\Dl_cats
2010-01-20 16:23 . 2008-09-30 00:43 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-01-20 16:19 . 2008-09-30 01:01 -------- d-----w- c:\program files\Microsoft Silverlight
2010-01-20 13:31 . 2008-09-11 15:57 -------- d-----w- c:\program files\Common Files\Java
2010-01-20 13:30 . 2008-09-11 15:57 -------- d-----w- c:\program files\Java
2010-01-14 16:12 . 2009-12-08 02:02 181120 ------w- c:\windows\system32\MpSigStub.exe
2010-01-12 13:53 . 2008-11-10 23:16 1 ----a-w- c:\documents and settings\Gene Barnes\Application Data\OpenOffice.org2\user\uno_packages\cache\stamp.sys
2010-01-06 20:00 . 2008-09-11 15:34 -------- d-----w- c:\program files\Common Files\Adobe
2009-12-22 14:43 . 2009-12-12 14:37 2066200 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcorex.dll
2009-12-16 18:27 . 2009-12-16 18:27 -------- d-----w- c:\documents and settings\Elaine\Application Data\OpenOffice.org2
2009-12-11 04:17 . 2008-12-21 18:29 20 ---h--w- c:\documents and settings\All Users\Application Data\PKP_DLec.DAT
2009-12-08 13:53 . 2008-11-10 01:19 -------- d-----w- c:\documents and settings\Gene Barnes\Application Data\Apple Computer
2009-12-08 02:00 . 2009-12-08 02:00 26232 ---ha-w- c:\windows\system32\mlfcache.dat
2009-12-07 15:37 . 2009-12-07 15:36 -------- d-----w- c:\program files\iTunes
2009-12-07 15:37 . 2009-12-07 15:36 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-12-07 15:36 . 2009-12-07 15:36 -------- d-----w- c:\program files\iPod
2009-12-07 15:36 . 2008-11-10 01:11 -------- d-----w- c:\program files\Common Files\Apple
2009-12-07 15:35 . 2009-12-07 15:34 -------- d-----w- c:\program files\QuickTime
2009-12-07 15:31 . 2009-12-07 15:31 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2009-12-07 15:29 . 2009-12-07 15:29 -------- d-----w- c:\program files\Safari
2009-12-07 15:28 . 2009-12-07 15:28 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\Safari 5.31.21.10\SetupAdmin.exe
2009-12-07 15:28 . 2009-12-07 15:28 -------- d-----w- c:\program files\Bonjour
2009-12-07 14:21 . 2008-09-11 17:58 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-12-07 14:21 . 2008-09-11 17:58 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-12-07 14:21 . 2008-09-11 17:58 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-11-23 23:06 . 2008-12-26 02:20 -------- d-----w- c:\documents and settings\Gene Barnes\Application Data\uTorrent
2009-11-21 15:51 . 2006-03-15 12:00 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-10-29 07:46 . 2006-03-15 12:00 832512 ------w- c:\windows\system32\wininet.dll
2009-10-29 07:46 . 2006-03-15 12:00 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-10-29 07:46 . 2006-03-15 12:00 17408 ----a-w- c:\windows\system32\corpol.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\Gene Barnes\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-12-25 135664]
"PowerDVD"="c:\program files\CyberLink\PowerDVD\PowerDVD.exe" [2007-01-10 955952]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-03 866584]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-12-12 2043160]
"SigmatelSysTrayApp"="stsystra.exe" [2005-03-22 339968]
"dlcdmon.exe"="c:\program files\Dell Photo AIO Printer 944\dlcdmon.exe" [2005-10-07 430080]
"MemoryCardManager"="c:\program files\Dell Photo AIO Printer 944\memcard.exe" [2005-09-07 290816]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"DLCDCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLCDtime.dll" [2005-09-14 73728]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]
c:\documents and settings\Gene Barnes\Start Menu\Programs\Startup\
OpenOffice.org 2.4.lnk - c:\program files\OpenOffice.org 2.4\program\quickstart.exe [2008-1-21 393216]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
NkbMonitor.exe.lnk - c:\program files\Nikon\PictureProject\NkbMonitor.exe [2008-12-21 118784]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-12-07 14:21 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-10-03 09:08 35696 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
2005-08-05 17:56 64512 ----a-w- c:\windows\ehome\ehtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
2005-10-15 02:46 77824 ----a-w- c:\windows\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
2005-10-15 02:50 114688 ----a-w- c:\windows\system32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]
2005-10-15 02:49 94208 ----a-w- c:\windows\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
2006-12-06 02:55 54832 ----a-w- c:\program files\CyberLink\PowerDVD\Language\Language.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2006-01-12 19:40 155648 ----a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
2006-11-23 19:10 56928 ------w- c:\program files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2008-08-18 22:41 1832272 --sha-r- c:\program files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2008-06-10 08:27 144784 ----a-w- c:\program files\Java\jre1.6.0_07\bin\jusched.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Common Files\\Ahead\\Nero Web\\SetupX.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Documents and Settings\\Gene Barnes\\Application Data\\Macromedia\\Flash Player\\
www.macromedia.com\\bin\\octoshape\\octoshape.exe"="c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [1/19/2010 4:42 AM 207792]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [9/11/2008 12:58 PM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [9/11/2008 12:58 PM 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [9/11/2008 12:58 PM 908056]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [9/11/2008 12:58 PM 297752]
R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [1/19/2010 4:42 AM 359624]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 6:19 PM 13592]
R3 dlcd_device;dlcd_device;c:\windows\system32\dlcdcoms.exe -service --> c:\windows\system32\dlcdcoms.exe -service [?]
.
Contents of the 'Scheduled Tasks' folder
2010-01-20 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
2010-01-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1220945662-746137067-725345543-1003Core.job
- c:\documents and settings\Gene Barnes\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-12-25 14:07]
2010-01-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1220945662-746137067-725345543-1003UA.job
- c:\documents and settings\Gene Barnes\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-12-25 14:07]
2010-01-21 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 23:20]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.yahoo.com/FF - ProfilePath - c:\documents and settings\Gene Barnes\Application Data\Mozilla\Firefox\Profiles\czizpajo.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - plugin: c:\documents and settings\Gene Barnes\Local Settings\Application Data\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
.
**************************************************************************
scanning hȋdden processes ...
scanning hȋdden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCDCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLCDtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hȋdden files ...
scan completed successfully
hȋdden files:
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(708)
c:\windows\system32\igfxdev.dll
- - - - - - - > 'explorer.exe'(252)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-01-21 12:57:33
ComboFix-quarantined-files.txt 2010-01-21 17:57
ComboFix2.txt 2010-01-21 05:56
Pre-Run: 135,286,095,872 bytes free
Post-Run: 135,241,986,048 bytes free
- - End Of File - - 097196A9EF792C2D13D87FFF0288F697