alright.... tried to remove 3 or 4 things from startup then ran combofix.... heres the log......
ComboFix 08-06-12.2 - Jay Welch 2008-06-15 12:12:54.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.546 [GMT -4:00]
Running from: C:\Documents and Settings\Jay Welch\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Starware316
C:\Documents and Settings\All Users\Start Menu\Online Security Guide.url
C:\Documents and Settings\All Users\Start Menu\Security Troubleshooting.url
C:\Documents and Settings\Gaming\Application Data\Starware316
C:\Documents and Settings\Gaming\Favorites\Online Security Test.url
C:\Documents and Settings\Jay Welch\Application Data\Starware316
C:\Program Files\Common Files\Yazzle1552OinAdmin.exe
C:\Program Files\Common Files\Yazzle1552OinUninstaller.exe
C:\Program Files\Starware316
C:\Program Files\Starware316\bin\Starware316.dll
C:\Program Files\Starware316\icons\star_16.ico
C:\Program Files\Starware316\Starware316Uninstall.exe
C:\WINDOWS\Fonts\CALIBRIB.TTF
C:\WINDOWS\retadpu72.exe
C:\WINDOWS\system32\mdm.exe
C:\WINDOWS\system32\media
C:\WINDOWS\system32\media\AvidRender.wav
C:\WINDOWS\system32\pskill.exe
.
((((((((((((((((((((((((( Files Created from 2008-05-15 to 2008-06-15 )))))))))))))))))))))))))))))))
.
2008-06-14 14:24 . 2008-06-14 14:24 <DIR> d-------- C:\Program Files\Opera
2008-06-14 13:49 . 2008-06-14 13:49 <DIR> d-------- C:\Program Files\Trend Micro
2008-06-14 07:20 . 2008-06-14 07:20 <DIR> d-------- C:\Program Files\DellSupport
2008-06-09 15:26 . 2008-06-09 15:26 <DIR> d-------- C:\Documents and Settings\Gaming\Application Data\Viewpoint
2008-06-08 14:44 . 2008-06-08 14:50 <DIR> d-------- C:\Program Files\Windows Live
2008-06-08 14:44 . 2008-06-08 14:49 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2008-06-08 14:44 . 2008-06-08 14:45 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-06-05 19:48 . 2008-06-05 19:48 <DIR> d-------- C:\GSP_Demo_406
2008-06-05 19:48 . 2008-06-07 22:16 1,510 --a------ C:\WINDOWS\Sketchpad Preferences.dat
2008-06-03 16:05 . 2008-06-03 19:41 <DIR> d-------- C:\Documents and Settings\Jay Welch\Application Data\U3
2008-05-25 12:01 . 2008-06-14 07:33 <DIR> d-------- C:\PowerPanel
2008-05-21 19:42 . 2008-05-21 19:42 <DIR> d-------- C:\Program Files\Synergy
2008-05-15 17:04 . 2008-05-15 17:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Bluetooth
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-15 16:00 --------- d-----w C:\Program Files\Mozilla Firefox 3 Beta 2
2008-06-15 12:32 --------- d-----w C:\Documents and Settings\Jay Welch\Application Data\nView_Wallpaper
2008-06-15 11:59 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-14 18:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\WholeSecurity
2008-06-14 17:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Corporation
2008-06-14 17:41 --------- d-----w C:\Program Files\Xilisoft
2008-06-14 17:39 30,601 ----a-w C:\Documents and Settings\Jay Welch\x.exe
2008-06-14 17:39 --------- d-----w C:\Program Files\VisualRoute
2008-06-14 17:39 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-06-14 17:33 --------- d-----w C:\Program Files\Dell
2008-06-14 17:30 --------- d-----w C:\Program Files\Google
2008-06-14 17:29 --------- d-----w C:\Program Files\GameSpy Arcade
2008-06-14 11:49 --------- d-----w C:\Documents and Settings\Jay Welch\Application Data\Lionhead Studios
2008-06-14 11:43 --------- d-----w C:\Program Files\Visual IP Trace 2007
2008-06-14 11:33 --------- d-----w C:\Program Files\NVIDIA Corporation
2008-06-14 11:31 --------- d-----w C:\Program Files\MySpeed PC
2008-06-14 11:30 --------- d-----w C:\Program Files\Mp3TorrentDownload
2008-06-14 11:30 --------- d-----w C:\Program Files\Mozilla Thunderbird
2008-06-14 11:28 --------- d-----r C:\Program Files\Microsoft Games
2008-06-14 11:27 --------- d-----w C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor
2008-06-14 11:26 --------- d-----w C:\Program Files\KaraFun
2008-06-14 11:25 --------- d-----w C:\Program Files\IrfanView
2008-06-14 11:24 --------- d-----w C:\Program Files\Harry Potter Print Studio 5
2008-06-14 11:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\GalleryPlayer
2008-06-14 11:18 --------- d-----w C:\Program Files\Common Files\Sonic Shared
2008-06-14 11:16 --------- d-----w C:\Program Files\SlySoft
2008-06-14 11:10 --------- d-----w C:\Program Files\TimeTo
2008-06-14 11:09 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-06-13 11:09 --------- d-----w C:\Documents and Settings\Jay Welch\Application Data\OpenOffice.org2
2008-06-12 22:51 --------- d-----w C:\Program Files\Dl_cats
2008-06-08 22:29 --------- d-----w C:\Documents and Settings\Gaming\Application Data\Vidalia
2008-06-08 22:29 --------- d-----w C:\Documents and Settings\Gaming\Application Data\tor
2008-05-24 00:32 --------- d-----w C:\Documents and Settings\All Users\Application Data\nView_Profiles
2008-05-15 21:04 --------- d-----w C:\Program Files\AlphaZIP
2008-05-07 19:15 58,904 ----a-w C:\WINDOWS\system32\azipcontmn.dll
2008-05-05 22:34 --------- d-----w C:\Program Files\IVT Corporation
2008-04-12 21:02 1,781 ----a-w C:\WINDOWS\system32\IEPM4JTX.DRV
2008-04-06 23:10 58,904 ----a-w C:\WINDOWS\system32\sysfolderazipcnt.dll
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-19 09:47 1,845,248 ------w C:\WINDOWS\system32\dllcache\win32k.sys
2007-04-16 23:18 61 --sh--w C:\WINDOWS\cnerolf.bin
2008-01-21 19:11 56 --sh--r C:\WINDOWS\system32\3C99E4FCAE.sys
2008-01-21 19:11 1,890 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BE2ED590-CA49-46B5-8CCE-244FB2E0D1AA}]
2006-07-20 17:41 111616 --a------ C:\WINDOWS\IECodecPl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{1962C5BC-E475-465B-823B-133E711BCEB9}"= "C:\Program Files\Starware316\bin\Starware316.dll" [ ]
[HKEY_CLASSES_ROOT\clsid\{1962c5bc-e475-465b-823b-133e711bceb9}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2008-01-03 12:15 50528]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 06:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EPSON Stylus C86 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2R1.exe" [ ]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 17:50 221184]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 20:42 1404928]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-09-16 16:06 185632]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-09-08 06:20 122940]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-04-05 20:19 77824]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2005-07-23 00:25 28160 C:\WINDOWS\KHALMNPR.Exe]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2005-04-05 20:23 114688]
"nwiz"="nwiz.exe" [2006-10-22 12:22 1622016 C:\WINDOWS\system32\nwiz.exe]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-22 12:22 7700480]
"DLCCCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll" [2005-09-14 01:50 73728]
"NvMediaCenter"="NvMCTray.dll" [2006-10-22 12:22 86016 C:\WINDOWS\system32\nvmctray.dll]
"dlccmon.exe"="C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe" [2005-10-21 03:40 430080]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-03-20 18:21 29744]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 00:56 110592 C:\WINDOWS\system32\bthprops.cpl]
"Start WingMan Profiler"="C:\Program Files\Logitech\Gaming Software\LWEMon.exe" [2007-09-25 16:03 93208]
"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2005-09-26 20:34 169984]
C:\Documents and Settings\Jay Welch\Start Menu\Programs\Startup\
Stardock ObjectDock.lnk - C:\Program Files\Stardock\ObjectDock\ObjectDock.exe [2007-02-18 10:28:47 2746104]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-07-28 07:30:25 24576]
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2007-02-02 20:37:23 528384]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.iv41"= ir41_32.dll
"VIDC.YV12"= yv12vfw.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BlueSoleil.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\BlueSoleil.lnk
backup=C:\WINDOWS\pss\BlueSoleil.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Google Updater.lnk
backup=C:\WINDOWS\pss\Google Updater.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=C:\WINDOWS\pss\Logitech Desktop Messenger.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Works Calendar Reminders.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Works Calendar Reminders.lnk
backup=C:\WINDOWS\pss\Microsoft Works Calendar Reminders.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Privoxy.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Privoxy.lnk
backup=C:\WINDOWS\pss\Privoxy.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Run Google Web Accelerator.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Run Google Web Accelerator.lnk
backup=C:\WINDOWS\pss\Run Google Web Accelerator.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ymetray.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ymetray.lnk
backup=C:\WINDOWS\pss\ymetray.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Gaming^Start Menu^Programs^Startup^Metacafe.lnk]
path=C:\Documents and Settings\Gaming\Start Menu\Programs\Startup\Metacafe.lnk
backup=C:\WINDOWS\pss\Metacafe.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Gaming^Start Menu^Programs^Startup^OpenOffice.org 2.2.lnk]
path=C:\Documents and Settings\Gaming\Start Menu\Programs\Startup\OpenOffice.org 2.2.lnk
backup=C:\WINDOWS\pss\OpenOffice.org 2.2.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Jay Welch^Start Menu^Programs^Startup^Flash Securer.lnk]
path=C:\Documents and Settings\Jay Welch\Start Menu\Programs\Startup\Flash Securer.lnk
backup=C:\WINDOWS\pss\Flash Securer.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Jay Welch^Start Menu^Programs^Startup^hc_tray.lnk]
path=C:\Documents and Settings\Jay Welch\Start Menu\Programs\Startup\hc_tray.lnk
backup=C:\WINDOWS\pss\hc_tray.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Jay Welch^Start Menu^Programs^Startup^Joystick To Mouse.lnk]
path=C:\Documents and Settings\Jay Welch\Start Menu\Programs\Startup\Joystick To Mouse.lnk
backup=C:\WINDOWS\pss\Joystick To Mouse.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Jay Welch^Start Menu^Programs^Startup^OpenOffice.org 2.3.lnk]
path=C:\Documents and Settings\Jay Welch\Start Menu\Programs\Startup\OpenOffice.org 2.3.lnk
backup=C:\WINDOWS\pss\OpenOffice.org 2.3.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Jay Welch^Start Menu^Programs^Startup^UsbAutoStart.lnk]
path=C:\Documents and Settings\Jay Welch\Start Menu\Programs\Startup\UsbAutoStart.lnk
backup=C:\WINDOWS\pss\UsbAutoStart.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 22:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeUpdater]
-ra------ 2007-03-01 10:37 2321600 C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BootSkin Startup Jobs]
--a------ 2004-04-26 17:21 270336 C:\Program Files\Stardock\WinCustomize\BootSkin\BootSkin.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDTray]
C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Creative Detector]
--------- 2004-12-02 19:23 102400 C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
--a------ 2007-03-15 11:09 460784 C:\Program Files\DellSupport\DSAgnt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dlccmon.exe]
--a------ 2005-10-21 03:40 430080 C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DMXLauncher]
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eBayToolbar]
--a------ 2008-03-22 07:46 652528 C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GPClientMonitor]
C:\Program Files\GalleryPlayer\Player\GPClientMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GPDownloadManager]
C:\Program Files\GalleryPlayer\Player\GPDownloadManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
--a------ 2005-04-05 20:22 94208 C:\WINDOWS\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
--a------ 2004-07-27 17:50 81920 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM]
--a------ 2007-02-16 18:22 67128 C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Portfolio]
--a------ 2000-08-08 16:00 311350 C:\Program Files\Microsoft Works\WksSb.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Update Detection]
--a------ 2000-08-08 16:00 28739 C:\Program Files\Microsoft Works\WkDetect.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSKDetectorExe]
--a------ 2005-07-12 20:05 1117184 C:\Program Files\McAfee\SpamKiller\MSKDetct.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MtdAcq]
--------- 2004-07-02 12:26 122956 C:\Program Files\Creative\Shared Files\Media Sniffer\MtdAcq.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Picasa Media Detector]
--a------ 2008-02-25 21:23 443968 C:\Program Files\Picasa2\PicasaMediaDetector.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-02-16 10:54 282624 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiteAdvisor]
--a------ 2007-01-16 13:38 36904 C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
-ra------ 2007-08-23 00:19 23120680 C:\Program Files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WindowBlinds]
C:\Program Files\Stardock\Object Desktop\WindowBlinds\WBInstall32.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WorksFUD]
--a------ 2000-08-08 16:00 24576 C:\Program Files\Microsoft Works\wkfud.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wuauserv"=2 (0x2)
"wscsvc"=2 (0x2)
"WLSetupSvc"=3 (0x3)
"WinDefend"=2 (0x2)
"UPS"=3 (0x3)
"TapiSrv"=2 (0x2)
"ssoftservice"=2 (0x2)
"Messenger"=2 (0x2)
"iPod Service"=2 (0x2)
"IMGJTM"=3 (0x3)
"helpsvc"=2 (0x2)
"gusvc"=3 (0x3)
"GoogleDesktopManager-022208-143751"=3 (0x3)
"Fax"=2 (0x2)
"Creative Service for CDROM Access"=2 (0x2)
"aawservice"=2 (0x2)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"VistaStartMenu"="C:\Program Files\Vista Start Menu\VistaStartMenu.exe"
"LDM"=C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" /startup
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"WinDVR SchSvr"="C:\Program Files\Common Files\InterVideo\SchSvr\SchSvr.exe"
"SVRemote"=c:\Program Files\SVRemote\TVCardRemote.exe
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\system32\\dlcccoms.exe"=
"C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\dlccPSWX.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"C:\\WINDOWS\\system32\\java.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\AIM6\\aim6.exe"=
"C:\\Program Files\\Kontiki\\KService.exe"=
"C:\\Program Files\\BitTorrent\\bittorrent.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"135:TCP"= 135:TCP:TCP Port 135
"5000:TCP"= 5000:TCP:TCP Port 5000
"5001:TCP"= 5001:TCP:TCP Port 5001
"5002:TCP"= 5002:TCP:TCP Port 5002
"5003:TCP"= 5003:TCP:TCP Port 5003
"5004:TCP"= 5004:TCP:TCP Port 5004
"5005:TCP"= 5005:TCP:TCP Port 5005
"5006:TCP"= 5006:TCP:TCP Port 5006
"5007:TCP"= 5007:TCP:TCP Port 5007
"5008:TCP"= 5008:TCP:TCP Port 5008
"5009:TCP"= 5009:TCP:TCP Port 5009
"5010:TCP"= 5010:TCP:TCP Port 5010
"5011:TCP"= 5011:TCP:TCP Port 5011
"5012:TCP"= 5012:TCP:TCP Port 5012
"5013:TCP"= 5013:TCP:TCP Port 5013
"5014:TCP"= 5014:TCP:TCP Port 5014
"5015:TCP"= 5015:TCP:TCP Port 5015
"5016:TCP"= 5016:TCP:TCP Port 5016
"5017:TCP"= 5017:TCP:TCP Port 5017
"5018:TCP"= 5018:TCP:TCP Port 5018
"5019:TCP"= 5019:TCP:TCP Port 5019
"5020:TCP"= 5020:TCP:TCP Port 5020
R1 LADriver;LADriver;C:\WINDOWS\system32\drivers\LADriver.sys [2005-09-22 04:12]
R1 LDDriver;LDDriver;C:\WINDOWS\system32\drivers\LDDriver.sys [2005-09-22 03:17]
R1 LHDriver;LHDriver;C:\WINDOWS\system32\drivers\LHDriver.sys [2005-09-22 04:21]
R2 ssoftnt4;ssoftnt4;C:\WINDOWS\system32\Drivers\ssoftnt4.sys [2007-01-24 12:16]
R3 cdiskdun;cdiskdun;C:\DOCUME~1\JAYWEL~1\LOCALS~1\Temp\cdiskdun.sys [2004-03-27 13:10]
S3 Cap7134;SinoVideo PCI 2309 Cap7134 Capture;C:\WINDOWS\system32\DRIVERS\Cap7134.sys [2003-10-16 16:33]
S3 PhTVTune;7130 TV tuner card WDM TVTuner;C:\WINDOWS\system32\DRIVERS\PhTVTune.sys [2006-08-25 23:08]
S4 GoogleDesktopManager-022208-143751;Google Desktop Manager 5.7.802.22438;"C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-03-20 18:21]
S4 IMGJTM;IMG Joystick-To-Mouse Service;C:\WINDOWS\JOY2MSE\IMGJTM.EXE [2002-09-26 22:00]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{51ac566c-b23b-11db-9ad3-806d6172696f}]
\Shell\AutoRun\command - G:\_MyPendrive\MyPendrive.exe
\Shell\MyPendrive\command - G:\_MyPendrive\MyPendrive.exe
\Shell\progr0\command - \MyPendriveUI.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{aacf1a58-b244-11db-9ad4-001676a20453}]
\Shell\AutoRun\command - G:\_MyPendrive\MyPendrive.exe
\Shell\MyPendrive\command - G:\_MyPendrive\MyPendrive.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cb66bb43-2a8a-11dd-91fb-0018391c6357}]
\Shell\AutoRun\command - I:\LaunchU3.exe -a
*Newly Created Service* - CATCHME
*Newly Created Service* - CDISKDUN
*Newly Created Service* - DSBROKERSERVICE
.
Contents of the 'Scheduled Tasks' folder
"2008-05-16 22:24:54 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-06-15 12:25:52
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCCCATS = rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hidden files ...
**************************************************************************
.
Completion time: 2008-06-15 12:29:18
ComboFix-quarantined-files.txt 2008-06-15 16:28:15
Pre-Run: 50,609,963,008 bytes free
Post-Run: 51,035,889,664 bytes free
335 --- E O F --- 2008-04-10 10:04:38