ok here it is: ComboFix 09-04-15.08 - CorrinaDeschambeault 15/04/2009 19:59.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.510.221 [GMT -6:00]
Running from: c:\documents and settings\CorrinaDeschambeault\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
.
((((((((((((((((((((((((( Files Created from 2009-03-16 to 2009-04-16 )))))))))))))))))))))))))))))))
.
2009-04-16 01:24 . 2009-04-16 01:24 -------- d-----w c:\windows\LastGood
2009-04-14 03:12 . 2009-04-14 03:19 -------- d-----w c:\documents and settings\Dennis ****\Application Data\AVGTOOLBAR
2009-04-13 16:47 . 2009-04-13 19:16 -------- d-----w c:\documents and settings\Autumn\Application Data\AVGTOOLBAR
2009-04-11 04:50 . 2009-04-15 04:12 -------- dc-h--w C:\$AVG8.VAULT$
2009-04-11 04:25 . 2009-04-11 04:25 108552 ----a-w c:\windows\system32\drivers\avgtdix.sys
2009-04-11 04:25 . 2009-04-11 04:25 10520 ----a-w c:\windows\system32\avgrsstx.dll
2009-04-11 04:25 . 2009-04-11 04:25 325640 ----a-w c:\windows\system32\drivers\avgldx86.sys
2009-04-11 04:25 . 2009-04-16 01:25 -------- d-----w c:\windows\system32\drivers\Avg
2009-04-11 04:25 . 2009-04-11 04:43 -------- d-----w c:\documents and settings\CorrinaDeschambeault\Application Data\AVGTOOLBAR
2009-04-11 04:25 . 2009-04-16 01:45 -------- dc----w c:\documents and settings\All Users\Application Data\avg8
2009-04-06 04:11 . 2009-04-06 04:11 -------- d-----w c:\documents and settings\NetworkService\Local Settings\Application Data\F-Secure
2009-04-06 04:08 . 2009-04-06 04:08 -------- dc----w c:\documents and settings\All Users\Application Data\fssg
2009-04-06 04:07 . 2009-04-11 02:34 -------- dc----w c:\documents and settings\All Users\Application Data\f-secure
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-14 03:19 . 2007-05-16 00:04 268 -c-ha-w C:\sqmdata19.sqm
2009-04-14 03:19 . 2007-05-16 00:04 244 -c-ha-w C:\sqmnoopt19.sqm
2009-04-14 03:11 . 2007-05-15 13:30 268 -c-ha-w C:\sqmdata18.sqm
2009-04-14 03:11 . 2007-05-15 13:30 244 -c-ha-w C:\sqmnoopt18.sqm
2009-04-12 14:41 . 2009-03-11 00:57 -------- d-----w c:\documents and settings\CorrinaDeschambeault\Application Data\Azureus
2009-04-11 04:25 . 2007-03-07 22:44 -------- d-----w c:\documents and settings\All Users\Application Data\Grisoft
2009-04-11 04:25 . 2009-04-11 04:25 -------- d-----w c:\program files\AVG
2009-04-11 02:34 . 2009-04-06 04:08 -------- d-----w c:\program files\Shaw Secure
2009-04-08 03:30 . 2008-12-02 01:24 -------- d-----w c:\documents and settings\CorrinaDeschambeault\Application Data\LimeWire
2009-03-28 16:28 . 2008-12-02 01:24 -------- d-----w c:\program files\LimeWire
2009-03-15 04:27 . 2009-03-12 20:34 -------- d-----w c:\program files\VSO
2009-03-15 04:27 . 2006-12-21 07:50 -------- d-----w c:\documents and settings\CorrinaDeschambeault\Application Data\Vso
2009-03-15 04:27 . 2006-12-21 07:50 47360 -c--a-w c:\documents and settings\CorrinaDeschambeault\Application Data\pcouffin.sys
2009-03-15 04:21 . 2006-12-21 07:50 47360 ----a-w c:\windows\system32\drivers\pcouffin.sys
2009-03-12 22:56 . 2009-03-12 22:56 -------- dc----w c:\documents and settings\All Users\Application Data\SlySoft
2009-03-12 21:53 . 2009-03-12 21:53 -------- dc----w c:\documents and settings\All Users\Application Data\vsosdk
2009-03-12 16:23 . 2009-03-12 16:18 -------- d-----w c:\program files\Elaborate Bytes
2009-03-11 19:52 . 2008-12-21 04:39 -------- d-----w c:\program files\DivX
2009-03-11 19:39 . 2006-08-18 17:12 -------- d-----w c:\program files\Google
2009-03-11 19:09 . 2009-03-11 19:09 -------- d-----w c:\program files\Common Files\supportsoft
2009-03-11 19:08 . 2008-12-22 00:55 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-03-11 18:40 . 2006-08-25 17:27 -------- d-----w c:\program files\Common Files\Command Software
2009-03-11 18:06 . 2008-05-26 19:30 -------- d-----w c:\documents and settings\All Users\Application Data\SupportSoft
2009-03-11 18:06 . 2008-05-26 19:29 -------- d-----w c:\program files\Dell Support Center
2009-03-11 00:57 . 2009-03-11 00:57 -------- d-----w c:\documents and settings\All Users\Application Data\Azureus
2009-03-01 18:04 . 2006-08-18 17:07 -------- d--h--w c:\program files\InstallShield Installation Information
2009-03-01 17:58 . 2009-03-01 17:57 -------- d-----w c:\program files\Philips
2009-03-01 17:56 . 2009-03-01 17:56 -------- d-----w c:\documents and settings\CorrinaDeschambeault\Application Data\InstallShield
2009-03-01 01:57 . 2007-05-14 17:10 268 -c-ha-w C:\sqmdata17.sqm
2009-03-01 01:57 . 2007-05-14 17:10 244 -c-ha-w C:\sqmnoopt17.sqm
2009-02-23 20:57 . 2009-02-23 20:57 304160 -c--a-w C:\PA207.DAT
2009-02-16 07:32 . 2006-09-08 14:53 56 -csh--r c:\windows\system32\54F4A0600C.sys
2009-02-16 07:32 . 2006-08-25 15:45 5018 -csha-w c:\windows\system32\KGyGaAvL.sys
2009-02-16 07:32 . 2006-08-25 15:45 5018 -csha-w c:\windows\system32\KGyGaAvL.sys
2009-02-16 07:26 . 2006-08-25 16:40 -------- d-----w c:\program files\TELUS eCare
2009-02-11 01:13 . 2006-08-28 21:20 113032 -c--a-w c:\documents and settings\Dennis ****\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-02-09 15:33 . 2007-05-14 14:00 268 -c-ha-w C:\sqmdata16.sqm
2009-02-09 15:33 . 2007-05-14 14:00 244 -c-ha-w C:\sqmnoopt16.sqm
2009-02-09 11:13 . 2008-11-27 20:07 1846784 ------w c:\windows\system32\dllcache\win32k.sys
2009-02-09 11:13 . 2004-08-10 17:51 1846784 ----a-w c:\windows\system32\win32k.sys
2009-01-27 15:33 . 2007-05-14 13:56 268 -c-ha-w C:\sqmdata15.sqm
2009-01-27 15:33 . 2007-05-14 13:56 244 -c-ha-w C:\sqmnoopt15.sqm
2009-01-26 14:39 . 2007-05-13 02:21 268 -c-ha-w C:\sqmdata14.sqm
2009-01-26 14:39 . 2007-05-13 02:21 244 -c-ha-w C:\sqmnoopt14.sqm
2009-01-17 04:35 . 2007-10-30 23:42 3594752 ------w c:\windows\system32\dllcache\mshtml.dll
2008-10-13 18:51 . 2006-08-25 15:05 113032 -c--a-w c:\documents and settings\CorrinaDeschambeault\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2008-07-31 00:21 . 2008-03-13 01:39 98096 -c--a-w c:\documents and settings\Autumn\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2008-03-13 01:39 . 2008-03-13 01:39 129 -c--a-w c:\documents and settings\Autumn\Local Settings\Application Data\fusioncache.dat
2007-03-05 03:18 . 2007-03-05 03:18 247 -c--a-w c:\program files\setuplog.txt
2007-02-05 04:42 . 2007-02-05 04:42 0 -c-h--w c:\program files\AppUpdate.log
2007-02-05 04:35 . 2006-12-21 07:50 81920 -c--a-w c:\documents and settings\CorrinaDeschambeault\Application Data\ezpinst.exe
2006-09-03 16:36 . 2006-09-03 16:36 135 -c--a-w c:\documents and settings\Dennis ****\Local Settings\Application Data\fusioncache.dat
2006-08-25 15:05 . 2006-08-25 15:05 143 -c--a-w c:\documents and settings\CorrinaDeschambeault\Local Settings\Application Data\fusioncache.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-09-25 68856]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-14 206064]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-19 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-15 1404928]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-04-06 94208]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-04-06 77824]
"Persistence"="c:\windows\system32\igfxpers.exe" [2005-04-06 114688]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2006-05-03 98304]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"Monitor"="c:\windows\PixArt\PAC207\Monitor.exe" [2006-11-03 319488]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-03-29 413696]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-14 206064]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-04-11 1932568]
c:\documents and settings\CorrinaDeschambeault\Start Menu\Programs\Startup\
TextBridge Instant Access OCR.lnk - c:\program files\TextBridge Classic\Bin\TBMenu.exe [2007-5-22 23040]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-04-11 04:25 10520 ----a-w c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=muyhje.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.JDCT"= jl_jdct.drv
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^TELUS eCare.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\TELUS eCare.lnk
backup=c:\windows\pss\TELUS eCare.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
2006-03-30 22:45 313472 -c--a-r c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
R2 A4SII300;A4SII300;c:\windows\System32\drivers\A4SII300.SYS [1998-02-26 25632]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2009-04-11 325640]
S1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2009-04-11 108552]
S2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-04-11 908056]
S2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-04-11 298264]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{49e1a128-b7d1-11dc-88f7-001676884c3b}]
\Shell\AutoRun\command - F:\DigitalPhotoKeychain.EXE
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bd92f57b-aa8e-11dc-88f2-001676884c3b}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL iexplore
http://www.mgae.com/keylauncher/?code=3654405786816657
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e9a64e7e-c47d-11dc-88fe-001676884c3b}]
\Shell\AutoRun\command - F:\DigitalPhotoKeychain.EXE
.
Contents of the 'Scheduled Tasks' folder
.
.
------- Supplementary Scan -------
.
uStart Page = sympatico.msn.ca/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = 127.0.0.1
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-04-15 20:01
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-3618293995-1840668372-3379709252-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*$%ñ*D*]
@Class="Shell"
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_USERS\S-1-5-21-3618293995-1840668372-3379709252-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*$%ñ*D*\OpenWithList]
@Class="Shell"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(3492)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-04-16 20:03
ComboFix-quarantined-files.txt 2009-04-16 02:03
ComboFix2.txt 2009-04-16 01:54
Pre-Run: 10,411,495,424 bytes free
Post-Run: 10,405,011,456 bytes free
184 --- E O F --- 2009-04-14 15:10