here is the new combofix report you asked for…………..
ComboFix 08-12-31.01 - Danni-Doug 2009-01-01 18:45:08.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.667 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1296 [VPS 090101-0] *On-access scanning disabled* (Updated)
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2008-12-01 to 2009-01-01 )))))))))))))))))))))))))))))))
.
2008-12-29 07:12 . 2008-12-29 07:12 d——– c:\program files\Alwil Software
2008-12-28 18:43 . 2008-12-28 18:45 d——– c:\documents and settings\Danni-Doug\.SunDownloadManager
2008-12-28 18:30 . 2008-12-28 18:30 d——– C:\61c22c20cbe8fe9ff137
2008-12-28 07:44 . 2008-12-28 07:44 d——– c:\documents and settings\Danni-Doug\Application Data\Malwarebytes
2008-12-28 07:41 . 2008-12-28 07:44 d——– c:\program files\detriot pistons
2008-12-28 07:41 . 2008-12-28 07:41 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-28 07:41 . 2008-12-03 19:52 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-28 07:41 . 2008-12-03 19:52 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2008-12-27 02:35 . 2008-12-27 02:37 d——– c:\program files\Windows Live Safety Center
2008-12-25 23:34 . 2008-12-25 23:34 d——– c:\documents and settings\Guest\Application Data\Skinux
2008-12-25 23:34 . 2008-12-25 23:35 d——– c:\documents and settings\Guest\Application Data\ArcSoft
2008-12-25 23:26 . 2008-12-25 23:26 d——– c:\documents and settings\Doug\Application Data\Skinux
2008-12-25 23:26 . 2008-12-25 23:27 d——– c:\documents and settings\Doug\Application Data\ArcSoft
2008-12-25 23:26 . 2008-12-25 23:26 d——– c:\documents and settings\Doug
2008-12-25 20:04 . 2008-12-25 20:04 d——– c:\program files\Trend Micro
2008-12-18 06:27 . 2008-12-23 06:02 d——– c:\windows\ie8updates
2008-12-17 17:40 . 2008-12-17 17:40 410,984 –a—— c:\windows\system32\deploytk.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-29 11:27 ——— d—–w c:\program files\Java
2008-12-26 04:07 ——— d—–w c:\program files\Teamspeak2_RC2
2008-12-24 07:58 ——— d—–w c:\program files\Microsoft LifeCam
2008-12-24 07:44 ——— d—–w c:\program files\iTunes
2008-12-24 07:44 ——— d—–w c:\program files\iPod
2008-12-24 07:41 ——— d–h–w c:\program files\InstallShield Installation Information
2008-12-24 07:41 ——— d—–w c:\documents and settings\All Users\Application Data\BVRP Software
2008-12-24 07:39 ——— d—–w c:\program files\Bonjour
2008-12-24 07:37 ——— d—–w c:\program files\Blubster
2008-12-10 18:00 ——— d—–w c:\program files\Lx_cats
2008-11-29 04:11 ——— d—–w c:\program files\FlightGear
2008-11-29 04:09 ——— d—–w c:\program files\Common Files\eSellerate
2008-11-29 02:14 ——— d—–w c:\program files\YSFLIGHT.COM
2008-11-29 01:55 ——— d—–w c:\documents and settings\Danni-Doug\Application Data\flightgear.org
2008-11-28 07:21 ——— d—–w c:\program files\Windows Media Connect 2
2008-11-24 07:22 0 —ha-w c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-11-24 07:22 0 —ha-w c:\windows\system32\drivers\Msft_Kernel_motmodem_01005.Wdf
2008-11-24 07:21 ——— d—–w c:\program files\Common Files\Motorola Shared
2008-11-09 17:34 ——— d—–w c:\documents and settings\Danni-Doug\Application Data\KodakCredentialStore
2008-11-09 03:14 ——— d—–w c:\program files\Common Files\ArcSoft
2008-11-09 03:14 ——— d—–w c:\documents and settings\Danni-Doug\Application Data\ArcSoft
2008-11-09 03:14 ——— d—–w c:\documents and settings\All Users\Application Data\ArcSoft
2008-11-09 03:13 ——— d—–w c:\program files\ArcSoft
2008-11-09 03:10 ——— d—–w c:\program files\Common Files\Kodak
2008-11-09 03:00 ——— d—–w c:\program files\Kodak
2008-11-09 03:00 ——— d—–w c:\documents and settings\Danni-Doug\Application Data\Skinux
2008-11-09 03:00 ——— d—–w c:\documents and settings\All Users\Application Data\Kodak
2008-11-04 03:28 ——— d—–w c:\program files\QuickTime
2008-11-04 03:28 ——— d—–w c:\documents and settings\All Users\Application Data\Apple Computer
2008-10-23 12:36 286,720 —-a-w c:\windows\system32\gdi32.dll
2008-10-16 20:38 826,368 —-a-w c:\windows\system32\wininet.dll
2008-10-16 19:13 202,776 —-a-w c:\windows\system32\wuweb.dll
2008-10-16 19:13 1,809,944 —-a-w c:\windows\system32\wuaueng.dll
2008-10-16 19:12 561,688 —-a-w c:\windows\system32\wuapi.dll
2008-10-16 19:12 323,608 —-a-w c:\windows\system32\wucltui.dll
2008-10-16 19:09 92,696 —-a-w c:\windows\system32\cdm.dll
2008-10-16 19:09 51,224 —-a-w c:\windows\system32\wuauclt.exe
2008-10-16 19:09 43,544 —-a-w c:\windows\system32\wups2.dll
2008-10-16 19:08 34,328 —-a-w c:\windows\system32\wups.dll
2008-10-16 19:06 268,648 —-a-w c:\windows\system32\mucltui.dll
2008-10-16 19:06 208,744 —-a-w c:\windows\system32\muweb.dll
2008-10-03 10:02 247,326 —-a-w c:\windows\system32\strmdll.dll
2008-10-02 14:07 453,152 —-a-w c:\windows\system32\NVUNINST.EXE
2008-09-28 19:29 24 -c–a-w c:\documents and settings\Danni-Doug\jagex_runescape_preferences.dat
2008-05-21 00:56 32,768 -csha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008052020080521\index.dat
.
((((((((((((((((((((((((((((( snapshot_2008-12-30_ 4.26.12.40 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-12-28 12:33:35 32,768 -c–a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2008-12-31 19:33:03 32,768 -c–a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2008-12-28 12:33:35 32,768 -c–a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-12-31 19:33:03 32,768 -c–a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-12-28 12:33:35 49,152 -c–a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-12-31 19:33:03 49,152 -c–a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-01-01 23:22:17 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_498.dat
+ 2009-01-01 23:22:30 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_660.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTSysVol"="c:\program files\Creative\SB Live! 24-bit\Surround Mixer\CTSysVol.exe" [2003-09-17 57344]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"LogitechVideoRepair"="c:\program files\Logitech\Video\ISStart.exe" [2004-06-01 458752]
"LXCGCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll" [2005-07-20 73728]
"ddoctorv2"="c:\program files\Comcast\Desktop Doctor\bin\sprtcmd.exe" [2008-04-24 202560]
"VX6000"="c:\windows\vVX6000.exe" [2006-10-13 994096]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-10-07 86016]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2008-11-20 178688]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-17 136600]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
"nwiz"="nwiz.exe" [2008-10-07 c:\windows\system32\nwiz.exe]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.enc"= ITIG726.acm
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoTray]
——— 2004-06-01 11:03 217088 c:\program files\Logitech\Video\LogiTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-09-06 15:09 413696 c:\program files\QuickTime\QTTask.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\PlayOnline\\SquareEnix\\PlayOnlineViewer\\pol.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\AeriaGames\\LastChaosUSA\\LC.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-12-29 111184]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-12-29 20560]
S3 VX6000;Microsoft LifeCam VX-6000;c:\windows\system32\DRIVERS\VX6000Xp.sys [2006-06-29 2383152]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.msn.com
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr7/*http://www.yahoo.com
c:\windows\Downloaded Program Files\gtplugin.ocx - O16 -: {E93E9DF0-3E59-4331-A269-F1E077C66F00}
hxxp://cnn-5.vo.llnwd.net/c1/static/client/browserplayer/gtplugin.cab
c:\windows\Downloaded Program Files\gtplugin.inf
FF - ProfilePath - c:\documents and settings\Danni-Doug\Application Data\Mozilla\Firefox\Profiles\4fn9pvih.default\
FF - prefs.js: browser.startup.homepage - hxxp://en-US.start2.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official
FF - plugin: c:\program files\Yahoo!\Shared\npYState.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-01-01 18:47:39
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXCGCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-01-01 18:49:13
ComboFix-quarantined-files.txt 2009-01-01 23:48:39
ComboFix2.txt 2008-12-31 20:23:47
ComboFix3.txt 2008-12-30 21:54:23
ComboFix4.txt 2008-12-29 02:24:50
Pre-Run: 93,361,491,968 bytes free
Post-Run: 93,377,179,648 bytes free
159 — E O F — 2008-12-23 20:22:16