Hijack this log file: Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:40:23 PM, on 7/02/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16575)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\WindowsMobile\wmdc.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe
C:\Windows\OEM05Mon.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\Program Files\Dell AIO 810\DLCGmon.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Windows\eHome\ehshell.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
Live Search
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
MSN.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
Live Search
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
Live Search
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
MSN.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\sw g.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [DELL Webcam Manager] "C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe" /s
O4 - HKLM\..\Run: [OEM05Mon.exe] C:\Windows\OEM05Mon.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Updater] C:\Windows\system32\updater\explorer.exe
O4 - HKLM\..\Run: [DLCGCATS] rundll32 C:\Windows\system32\spool\DRIVERS\W32X86\3\DLCGtim e.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [dlcgmon.exe] "C:\Program Files\Dell AIO 810\dlcgmon.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Dell Fax Solutions\fm3032.exe" /s
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O13 - Gopher Prefix:
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O20 - Winlogon Notify: avgwlntf - C:\Windows\SYSTEM32\avgwlntf.dll
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: dlcg_device - - C:\Windows\system32\dlcgcoms.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
--
End of file - 9131 bytes
Combofix:
ComboFix 08-02-22 - Rob 2008-02-22 11:57:30.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.2201 [GMT 11:00]
Running from: C:\Users\Rob\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Windows\system32\x64
.
((((((((((((((((((((((((( Files Created from 2008-01-22 to 2008-02-22 )))))))))))))))))))))))))))))))
.
2008-02-20 15:10 . 2008-02-20 15:10 <DIR> d-------- C:\Program Files\Microsoft.NET
2008-02-20 14:36 . 2008-02-20 14:36 <DIR> d-------- C:\inetpub
2008-02-20 14:17 . 2008-02-20 14:17 194,560 --a------ C:\Windows\System32\WebClnt.dll
2008-02-20 14:17 . 2008-02-20 14:17 110,080 --a------ C:\Windows\System32\drivers\mrxdav.sys
2008-02-20 14:13 . 2008-02-20 14:13 3,504,696 --a------ C:\Windows\System32\ntkrnlpa.exe
2008-02-20 14:13 . 2008-02-20 14:13 3,470,392 --a------ C:\Windows\System32\ntoskrnl.exe
2008-02-20 14:13 . 2008-02-20 14:13 1,060,920 --a------ C:\Windows\System32\drivers\ntfs.sys
2008-02-20 14:13 . 2008-02-20 14:13 211,000 --a------ C:\Windows\System32\drivers\volsnap.sys
2008-02-20 14:13 . 2008-02-20 14:13 154,624 --a------ C:\Windows\System32\drivers\nwifi.sys
2008-02-20 14:13 . 2008-02-20 14:13 110,136 --a------ C:\Windows\System32\drivers\ataport.sys
2008-02-20 14:13 . 2008-02-20 14:13 45,112 --a------ C:\Windows\System32\drivers\pciidex.sys
2008-02-20 14:13 . 2008-02-20 14:13 21,560 --a------ C:\Windows\System32\drivers\atapi.sys
2008-02-20 14:13 . 2008-02-20 14:13 15,928 --a------ C:\Windows\System32\drivers\pciide.sys
2008-02-20 14:12 . 2008-02-20 14:12 4,247,552 --a------ C:\Windows\System32\GameUXLegacyGDFs.dll
2008-02-20 14:12 . 2008-02-20 14:12 1,686,528 --a------ C:\Windows\System32\gameux.dll
2008-02-20 14:12 . 2008-02-20 14:12 803,328 --a------ C:\Windows\System32\drivers\tcpip.sys
2008-02-20 14:12 . 2008-02-20 14:12 216,632 --a------ C:\Windows\System32\drivers\netio.sys
2008-02-20 14:12 . 2008-02-20 14:12 167,424 --a------ C:\Windows\System32\tcpipcfg.dll
2008-02-20 14:12 . 2008-02-20 14:12 24,064 --a------ C:\Windows\System32\netcfg.exe
2008-02-20 14:12 . 2008-02-20 14:12 22,016 --a------ C:\Windows\System32\netiougc.exe
2008-02-20 14:11 . 2008-02-20 14:11 11,776 --a------ C:\Windows\System32\sbunattend.exe
2008-02-20 14:07 . 2008-02-20 14:07 1,244,672 --a------ C:\Windows\System32\mcmde.dll
2008-02-20 13:38 . 2008-02-20 14:21 <DIR> d-------- C:\Windows\System32\catroot2
2008-02-20 13:37 . 2008-02-20 13:37 <DIR> d-------- C:\wutemp
2008-02-20 13:37 . 2008-02-20 13:37 <DIR> d---s---- C:\Windows\Downloaded Program Files
2008-02-20 13:36 . 2008-02-20 13:36 <DIR> d-------- C:\wuold
2008-02-19 19:20 . 2008-02-19 19:20 <DIR> d-------- C:\Users\Rob\AppData\Roaming\Simply Super Software
2008-02-19 19:20 . 2008-02-19 19:20 <DIR> d-------- C:\Users\All Users\Simply Super Software
2008-02-19 19:20 . 2008-02-19 19:20 <DIR> d-------- C:\ProgramData\Simply Super Software
2008-02-19 19:20 . 2008-02-19 19:21 <DIR> d-------- C:\Program Files\Trojan Remover
2008-02-19 19:20 . 2006-05-25 14:52 162,304 --a------ C:\Windows\System32\ztvunrar36.dll
2008-02-19 19:20 . 2003-02-02 19:06 153,088 --a------ C:\Windows\System32\UNRAR3.dll
2008-02-19 19:20 . 2005-08-26 00:50 77,312 --a------ C:\Windows\System32\ztvunace26.dll
2008-02-19 19:20 . 2002-03-06 00:00 75,264 --a------ C:\Windows\System32\unacev2.dll
2008-02-19 19:20 . 2006-06-19 12:01 69,632 --a------ C:\Windows\System32\ztvcabinet.dll
2008-02-19 16:17 . 2008-02-19 16:17 <DIR> d-------- C:\Users\Rob\AppData\Roaming\Grisoft
2008-02-19 16:17 . 2007-05-30 23:10 10,872 --a------ C:\Windows\System32\drivers\AvgAsCln.sys
2008-02-19 15:31 . 2006-10-26 19:56 32,592 --a------ C:\Windows\System32\msonpmon.dll
2008-02-19 15:27 . 2008-02-20 15:29 <DIR> d-------- C:\Users\All Users\Microsoft Help
2008-02-19 15:27 . 2008-02-20 15:29 <DIR> d-------- C:\ProgramData\Microsoft Help
2008-02-18 19:00 . 2008-02-18 19:01 <DIR> d-------- C:\Users\All Users\Lavasoft
2008-02-18 19:00 . 2008-02-18 19:01 <DIR> d-------- C:\ProgramData\Lavasoft
2008-02-18 19:00 . 2008-02-18 19:00 <DIR> d-------- C:\Program Files\Lavasoft
2008-02-18 18:53 . 2008-02-19 19:17 <DIR> d-------- C:\Users\All Users\Spybot - Search & Destroy
2008-02-18 18:53 . 2008-02-19 19:17 <DIR> d-------- C:\ProgramData\Spybot - Search & Destroy
2008-02-18 18:53 . 2008-02-19 19:17 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-02-18 18:47 . 2008-02-22 09:16 <DIR> d-a------ C:\Users\All Users\TEMP
2008-02-18 18:47 . 2008-02-22 09:16 <DIR> d-a------ C:\ProgramData\TEMP
2008-02-18 18:44 . 2005-08-25 18:19 115,920 --a------ C:\Windows\System32\MSINET.OCX
2008-02-18 00:14 . 2008-02-18 00:14 <DIR> d-------- C:\Users\All Users\Real
2008-02-18 00:14 . 2008-02-18 00:14 <DIR> d-------- C:\Program Files\Real Alternative
2008-02-17 16:41 . 2003-06-18 17:31 17,920 --a------ C:\Windows\System32\mdimon.dll
2008-02-17 16:41 . 2008-02-17 16:41 376 --a------ C:\Windows\ODBC.INI
2008-02-17 16:31 . 2008-02-17 16:31 <DIR> dr-h----- C:\MSOCache
2008-02-17 16:23 . 2008-02-17 16:24 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-02-17 16:21 . 2008-02-17 16:21 <DIR> d-------- C:\Program Files\DAEMON Tools Lite
2008-02-17 09:52 . 2008-02-17 09:52 <DIR> d-------- C:\Users\Rob\AppData\Roaming\DAEMON Tools
2008-02-17 09:52 . 2008-02-17 09:52 716,272 --a------ C:\Windows\System32\drivers\sptd.sys
2008-02-09 11:59 . 2008-02-09 11:59 <DIR> d-------- C:\Users\Rob\AppData\Roaming\DivX
2008-02-08 18:59 . 2008-02-08 18:59 <DIR> d-------- C:\Program Files\DivX
2008-02-08 18:59 . 2008-02-08 18:59 <DIR> d-------- C:\Program Files\Common Files\PX Storage Engine
2008-02-08 12:06 . 2008-02-08 12:06 <DIR> d-------- C:\Users\All Users\Hagel Technologies
2008-02-08 12:06 . 2008-02-08 12:06 <DIR> d-------- C:\ProgramData\Hagel Technologies
2008-02-07 18:40 . 2008-02-07 18:40 <DIR> d-------- C:\Program Files\Trend Micro
2008-02-05 20:54 . 2008-02-05 20:54 <DIR> d-------- C:\.jagex_cache_32
2008-01-25 11:03 . 2008-01-25 11:03 <DIR> d-------- C:\Users\Rob\AppData\Roaming\Media Player Classic
2008-01-22 21:30 . 2008-01-22 21:30 <DIR> d-------- C:\Users\Rob\Program Files
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2008-02-21 23:34 --------- d-----w C:\Users\Rob\AppData\Roaming\uTorrent
2008-02-21 21:00 --------- d-----w C:\Users\Rob\AppData\Roaming\AVG7
2008-02-20 09:20 --------- d-----w C:\Program Files\Steam
2008-02-20 04:11 --------- d-----w C:\Program Files\Microsoft Works
2008-02-20 03:18 --------- d-----w C:\Program Files\Windows Sidebar
2008-02-20 03:18 --------- d-----w C:\Program Files\Windows Mail
2008-02-20 03:12 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-02-20 03:12 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-02-20 03:12 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-02-20 03:12 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-02-20 03:09 824,832 ----a-w C:\Windows\System32\wininet.dll
2008-02-20 03:09 56,320 ----a-w C:\Windows\System32\iesetup.dll
2008-02-20 03:09 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2008-02-20 03:09 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2008-02-19 05:17 --------- d-----w C:\ProgramData\Grisoft
2008-02-17 06:59 --------- d-----w C:\Program Files\Common Files\Steam
2008-02-16 12:36 --------- d-----w C:\Program Files\Dl_cats
2008-02-16 07:10 --------- d-----w C:\Users\Rob\AppData\Roaming\LimeWire
2008-02-07 13:47 --------- d-----w C:\ProgramData\Roxio
2008-02-07 13:47 --------- d-----w C:\Program Files\Common Files\Roxio Shared
2008-01-26 00:25 --------- d-----w C:\Program Files\World of Warcraft
2008-01-06 14:25 --------- d-----w C:\Program Files\Combined Community Codec Pack
2008-01-05 13:55 --------- d-----w C:\Users\Rob\AppData\Roaming\vlc
2008-01-04 21:59 524,288 ----a-w C:\Windows\System32\DivXsm.exe
2008-01-04 21:58 3,596,288 ----a-w C:\Windows\System32\qt-dx331.dll
2008-01-04 21:58 200,704 ----a-w C:\Windows\System32\ssldivx.dll
2008-01-04 21:58 1,044,480 ----a-w C:\Windows\System32\libdivx.dll
2008-01-04 21:57 823,296 ----a-w C:\Windows\System32\divx_xx0c.dll
2008-01-04 21:57 823,296 ----a-w C:\Windows\System32\divx_xx07.dll
2008-01-04 21:57 81,920 ----a-w C:\Windows\System32\dpl100.dll
2008-01-04 21:57 802,816 ----a-w C:\Windows\System32\divx_xx11.dll
2008-01-04 21:57 682,496 ----a-w C:\Windows\System32\DivX.dll
2008-01-04 21:57 593,920 ----a-w C:\Windows\System32\dpuGUI11.dll
2008-01-04 21:57 57,344 ----a-w C:\Windows\System32\dpv11.dll
2008-01-04 21:57 53,248 ----a-w C:\Windows\System32\dpuGUI10.dll
2008-01-04 21:57 344,064 ----a-w C:\Windows\System32\dpus11.dll
2008-01-04 21:57 294,912 ----a-w C:\Windows\System32\dpu11.dll
2008-01-04 21:57 294,912 ----a-w C:\Windows\System32\dpu10.dll
2008-01-04 21:57 196,608 ----a-w C:\Windows\System32\dtu100.dll
2008-01-04 21:56 156,992 ----a-w C:\Windows\System32\DivXCodecVersionChecker.exe
2008-01-04 21:56 12,288 ----a-w C:\Windows\System32\DivXWMPExtType.dll
2008-01-01 01:24 --------- d-----w C:\Program Files\Common Files\Blizzard Entertainment
2007-12-28 12:55 --------- d-----w C:\Users\Rob\AppData\Roaming\DellFaxCtr
2007-12-28 06:09 --------- d-----w C:\Program Files\Dell Fax Solutions
2007-12-28 06:09 --------- d-----w C:\Program Files\Dell AIO 810
2007-12-28 06:08 --------- d-----w C:\ProgramData\DellFaxCtr
2007-12-28 06:08 --------- d-----w C:\Program Files\Abbyy FineReader 6.0 Sprint
2007-12-17 01:15 9,216 ----a-w C:\Windows\System32\avgwlntf.dll
2007-12-17 00:57 704,000 ----a-w C:\Windows\System32\PhotoScreensaver.scr
2007-12-17 00:57 67,584 ----a-w C:\Windows\System32\wlanhlp.dll
2007-12-17 00:57 542,720 ----a-w C:\Windows\System32\sysmain.dll
2007-12-17 00:57 502,784 ----a-w C:\Windows\System32\wlansvc.dll
2007-12-17 00:57 47,104 ----a-w C:\Windows\System32\wlanapi.dll
2007-12-17 00:57 299,008 ----a-w C:\Windows\System32\wlansec.dll
2007-12-17 00:57 289,280 ----a-w C:\Windows\System32\wlanmsm.dll
2007-12-17 00:57 24,064 ----a-w C:\Windows\System32\wtsapi32.dll
2007-12-17 00:57 2,923,520 ----a-w C:\Windows\explorer.exe
2007-12-17 00:57 2,027,008 ----a-w C:\Windows\System32\win32k.sys
2007-12-17 00:55 8,147,968 ----a-w C:\Windows\System32\wmploc.DLL
2007-12-17 00:55 7,680 ----a-w C:\Windows\System32\spwmp.dll
2007-12-17 00:55 4,096 ----a-w C:\Windows\System32\dxmasf.dll
2007-12-17 00:55 356,864 ----a-w C:\Windows\System32\MediaMetadataHandler.dll
2007-12-17 00:55 1,327,104 ----a-w C:\Windows\System32\quartz.dll
2007-12-17 00:54 9,728 ----a-w C:\Windows\System32\LAPRXY.DLL
2007-12-17 00:54 84,480 ----a-w C:\Windows\System32\INETRES.dll
2007-12-17 00:54 737,792 ----a-w C:\Windows\System32\inetcomm.dll
2007-12-17 00:54 223,232 ----a-w C:\Windows\System32\WMASF.DLL
2007-12-17 00:50 788,992 ----a-w C:\Windows\System32\rpcrt4.dll
2007-12-17 00:37 80,896 ----a-w C:\Windows\System32\wudriver.dll
2007-12-17 00:37 549,720 ----a-w C:\Windows\System32\wuapi.dll
2007-12-17 00:37 53,080 ----a-w C:\Windows\System32\wuauclt.exe
2007-12-17 00:37 43,352 ----a-w C:\Windows\System32\wups2.dll
2007-12-17 00:37 33,624 ----a-w C:\Windows\System32\wups.dll
2007-12-17 00:37 1,712,984 ----a-w C:\Windows\System32\wuaueng.dll
2007-12-17 00:37 1,524,224 ----a-w C:\Windows\System32\wucltux.dll
2007-12-17 00:36 31,232 ----a-w C:\Windows\System32\wuapp.exe
2007-12-17 00:36 163,000 ----a-w C:\Windows\System32\wuwebv.dll
2007-12-12 01:10 86,016 ----a-w C:\Windows\System32\icfupgd.dll
2007-12-12 01:10 750,080 ----a-w C:\Windows\System32\qmgr.dll
2007-12-12 01:10 61,952 ----a-w C:\Windows\System32\cmifw.dll
2007-12-12 01:10 475,136 ----a-w C:\Windows\System32\evr.dll
2007-12-12 01:10 396,800 ----a-w C:\Windows\System32\MPSSVC.dll
2007-12-12 01:10 392,192 ----a-w C:\Windows\System32\FirewallAPI.dll
2007-12-12 01:10 178,688 ----a-w C:\Windows\System32\iphlpsvc.dll
2007-12-12 01:10 16,896 ----a-w C:\Windows\System32\wfapigp.dll
2007-12-12 01:10 1,335,296 ----a-w C:\Windows\System32\msxml6.dll
2007-12-12 01:08 974,336 ----a-w C:\Windows\System32\crypt32.dll
2007-12-12 01:07 8,704 ----a-w C:\Windows\System32\hccoin.dll
2007-12-12 01:07 135,680 ----a-w C:\Windows\System32\wusa.exe
2007-12-12 01:06 49,664 ----a-w C:\Windows\System32\csrsrv.dll
2007-12-12 01:06 376,320 ----a-w C:\Windows\System32\winsrv.dll
2007-12-12 01:06 104,448 ----a-w C:\Windows\System32\DWWIN.EXE
2007-12-12 01:06 1,191,936 ----a-w C:\Windows\System32\msxml3.dll
2007-12-12 01:04 5,120 ----a-w C:\Windows\System32\wmi.dll
2007-12-12 01:04 36,864 ----a-w C:\Windows\System32\wmdmps.dll
2007-12-12 01:04 311,296 ----a-w C:\Windows\System32\mswmdm.dll
2007-12-12 01:04 31,744 ----a-w C:\Windows\System32\wmdmlog.dll
2007-12-12 01:04 167,424 ----a-w C:\Windows\System32\ActionQueue.dll
2007-12-12 01:04 160,872 ----a-w C:\Windows\System32\halmacpi.dll
2007-12-12 01:04 152,576 ----a-w C:\Windows\System32\imagehlp.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 23:36 201728]
"WindowsWelcomeCenter"="oobefldr.dll" [2006-11-02 23:34 2159104 C:\Windows\System32\oobefldr.dll]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 23:35 125440]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"MSConfig"="C:\Windows\System32\msconfig.exe" [2006-11-02 20:45 222208]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-12-12 12:06 1006264]
"RtHDVCpl"="RtHDVCpl.exe" [2007-05-12 00:26 4452352 C:\Windows\RtHDVCpl.exe]
"Persistence"="C:\Windows\system32\igfxpers.ex e" [2007-09-25 22:10 129560]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-12-21 08:31 579072]
"Updater"="C:\Windows\system32\updater\explorer.ex e" [2007-11-24 14:08 1478612]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-12-17 12:15 219136]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgwlntf]
avgwlntf.dll 2007-12-17 12:15 9216 C:\Windows\System32\avgwlntf.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~2\GOEC62~ 1.DLL
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Wind ows^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=C:\Windows\pss\Digital Line Detect.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^Users^Rob^AppData^Roaming^ Microsoft^Windows^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
path=C:\Users\Rob\AppData\Roaming\Microsoft\Window s\Start Menu\Programs\Startup\LimeWire On Startup.lnk
backup=C:\Windows\pss\LimeWire On Startup.lnk.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!AVG Anti-Spyware]
--a------ 2007-06-11 20:25 6731312 C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 22:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cmds]
C:\Users\Rob\AppData\Local\Temp\awtqn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DELL Webcam Manager]
--------- 2007-07-27 16:43 118784 C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupportCenter]
--a------ 2007-10-09 21:56 202544 C:\Program Files\Dell Support Center\bin\sprtcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DLCGCATS]
--a------ 2006-10-21 11:50 73728 C:\Windows\system32\spool\DRIVERS\W32X86\3\DLCGtim e.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dlcgmon.exe]
--a------ 2007-01-13 07:53 431600 C:\Program Files\Dell AIO 810\dlcgmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dscactivate]
--a------ 2007-10-09 21:57 16384 C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DU Meter]
C:\Windows\system32\DUMeter.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ECenter]
--a------ 2007-05-25 17:03 17920 C:\Dell\E-Center\EULALauncher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FaxCenterServer]
--a------ 2006-11-04 11:14 312200 C:\Program Files\Dell Fax Solutions\fm3032.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
--a------ 2007-12-12 04:42 1838592 C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
--a------ 2007-09-25 22:10 154136 C:\Windows\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
--a------ 2007-09-25 22:10 141848 C:\Windows\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
--a------ 2006-10-03 14:37 81920 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSServer]
C:\Users\Rob\AppData\Local\Temp\awvvw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OEM05Mon.exe]
--a------ 2007-08-22 16:39 36864 C:\Windows\OEM05Mon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
--a------ 2006-11-10 15:35 90112 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-09-25 01:11 132496 C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrojanScanner]
--a------ 2008-02-14 18:00 862288 C:\Program Files\Trojan Remover\Trjscan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Mobile Device Center]
%windir%\WindowsMobile\wmdc.exe
R2 RapiMgr;Windows Mobile-based device connectivity;C:\Windows\system32\svchost.exe [2006-11-02 20:45]
R2 sprtsvc_dellsupportcenter;SupportSoft Sprocket Service (dellsupportcenter);C:\Program Files\Dell Support Center\bin\sprtsvc.exe /service []
R2 WcesComm;Windows Mobile-2003-based device connectivity;C:\Windows\system32\svchost.exe [2006-11-02 20:45]
R2 XAudio;XAudio;C:\Windows\system32\DRIVERS\xaudio.s ys [2006-08-05 11:39]
R3 atikmdag;atikmdag;C:\Windows\system32\DRIVERS\atik mdag.sys [2007-11-02 16:56]
R3 AvgWFP;AVG7 Firewall Driver x86;C:\Windows\system32\Drivers\avgwfp.sys [2007-12-21 08:31]
R3 RLDesignVirtualAudioCableWdm;Live! Cam Virtual;C:\Windows\system32\DRIVERS\livecamv.sys [2007-01-15 20:57]
S3 igfx;igfx;C:\Windows\system32\DRIVERS\igdkmd32.sys [2007-09-25 22:10]
S3 OEM05Afx;Provides a software interface to control audio effects of OEM005 camera.;C:\Windows\system32\Drivers\OEM05Afx.sys [2007-08-22 16:39]
S3 OEM05Vfx;Creative Camera OEM005 Video VFX Driver;C:\Windows\system32\DRIVERS\OEM05Vfx.sys [2007-08-22 16:39]
S3 OEM05Vid;Creative Camera OEM005 Driver;C:\Windows\system32\DRIVERS\OEM05Vid.sys [2007-08-22 16:39]
S3 R300;R300;C:\Windows\system32\DRIVERS\atikmdag.sys [2007-11-02 16:56]
S3 Steam Client Service;Steam Client Service;C:\Program Files\Common Files\Steam\SteamService.exe [2008-02-16 22:26]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\{9d8ee0c7-dd17-11dc-8881-001d0976d2fe}]
\shell\AutoRun\command - G:\SETUP.EXE
\shell\configure\command - G:\SETUP.EXE
\shell\install\command - G:\SETUP.EXE
.
************************************************** ************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-02-22 12:00:20
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
.
Completion time: 2008-02-22 12:00:55
.
2008-02-21 23:33:16 --- E O F ---