here is my combofix log
ComboFix 09-06-23.01 - Tony 06/24/2009 20:51.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.3069.2103 [GMT -5:00]
Running from: c:\users\Tony\Downloads\ComboFix.exe
AV: Norton Internet Security *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
SP: Norton Internet Security *enabled* (Updated) {CBB7EE13-8244-4DAB-8B55-D5C7AA91E59A}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
ADS - Windows: deleted 24 bytes in 1 streams.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-2773397201-2855733099-4214572315-500
c:\$recycle.bin\S-1-5-21-3731822803-1114772756-532019640-500
c:\program files\Mozilla Firefox\Components\9d9646b0-e5c9-9c15-7bd6-74e2f0ae816a.dll
c:\windows\system32\81392971-2ee2-5c59-99a5-ab5077dfddf9.exe
c:\windows\system32\bKdiKc1XL4Csfus.vbs
c:\$recycle.bin\S-1-5-21-2773397201-2855733099-4214572315-500\desktop.ini
c:\$recycle.bin\S-1-5-21-3731822803-1114772756-532019640-500\desktop.ini
c:\users\Tony\AppData\Local\Microsoft\Windows\Temporary Internet Files\1394.tmp
c:\users\Tony\AppData\Local\Microsoft\Windows\Temporary Internet Files\7B96.tmp
c:\users\Tony\AppData\Local\Microsoft\Windows\Temporary Internet Files\88DE.tmp
c:\users\Tony\AppData\Local\Microsoft\Windows\Temporary Internet Files\8939fdff-4947-49a4-e2e4-babbbbc09c68
c:\users\Tony\AppData\Local\Microsoft\Windows\Temporary Internet Files\CE76.tmp
c:\users\Tony\AppData\Local\Microsoft\Windows\Temporary Internet Files\E751.tmp
c:\users\Tony\AppData\Local\Microsoft\Windows\Temporary Internet Files\F1FF.tmp
c:\users\Tony\AppData\Roaming\02000000293580f4620C.manifest
c:\users\Tony\AppData\Roaming\02000000293580f4620O.manifest
c:\users\Tony\AppData\Roaming\02000000293580f4620P.manifest
c:\users\Tony\AppData\Roaming\02000000293580f4620S.manifest
c:\users\Tony\AppData\Roaming\inst.exe
c:\windows\system32\dlcxutil32.dll
c:\windows\system32\iexjqmewqubntjcxl.dll
c:\windows\system32\rrcsqjwlybtexldmm.exe
.
((((((((((((((((((((((((( Files Created from 2009-05-25 to 2009-06-25 )))))))))))))))))))))))))))))))
.
2009-06-24 18:11 . 2009-05-13 08:00 89104 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090624.003\NAVENG.SYS
2009-06-24 18:11 . 2009-05-13 08:00 876144 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090624.003\NAVEX15.SYS
2009-06-24 18:11 . 2009-05-13 08:00 177520 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090624.003\NAVENG32.DLL
2009-06-24 18:11 . 2009-05-13 08:00 1181040 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090624.003\NAVEX32A.DLL
2009-06-24 18:11 . 2009-05-13 08:00 101936 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090624.003\ERASER.SYS
2009-06-24 18:11 . 2009-05-13 08:00 371248 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090624.003\EECTRL.SYS
2009-06-24 18:11 . 2009-05-13 08:00 2414128 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090624.003\CCERASER.DLL
2009-06-24 18:11 . 2008-11-20 09:00 259368 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090624.003\ECMSVR32.DLL
2009-06-22 19:20 . 2009-06-22 19:20 -------- d-----w- c:\program files\Trend Micro
2009-06-22 17:50 . 2009-05-13 08:00 89104 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090622.002\NAVENG.SYS
2009-06-22 17:50 . 2009-05-13 08:00 876144 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090622.002\NAVEX15.SYS
2009-06-22 17:50 . 2009-05-13 08:00 371248 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090622.002\EECTRL.SYS
2009-06-22 17:50 . 2009-05-13 08:00 2414128 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090622.002\CCERASER.DLL
2009-06-22 17:50 . 2009-05-13 08:00 177520 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090622.002\NAVENG32.DLL
2009-06-22 17:50 . 2009-05-13 08:00 1181040 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090622.002\NAVEX32A.DLL
2009-06-22 17:50 . 2009-05-13 08:00 101936 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090622.002\ERASER.SYS
2009-06-22 17:50 . 2008-11-20 09:00 259368 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090622.002\ECMSVR32.DLL
2009-06-22 02:07 . 2009-06-22 02:07 -------- d-----w- c:\programdata\SlySoft
2009-06-22 02:03 . 2009-06-22 02:03 -------- d-----w- c:\program files\SlySoft
2009-06-22 01:17 . 2009-06-22 01:40 -------- d-----w- c:\users\Tony\AppData\Roaming\Any Video Converter
2009-06-21 21:08 . 2009-06-21 21:22 47360 ----a-w- c:\users\Tony\AppData\Roaming\pcouffin.sys
2009-06-21 21:08 . 2009-06-21 21:22 -------- d-----w- c:\users\Tony\AppData\Roaming\Vso
2009-06-21 21:08 . 2009-06-21 21:08 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys
2009-06-20 03:54 . 2009-03-06 17:25 439672 ----a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090618.001\Scxpx86.dll
2009-06-20 03:54 . 2009-02-09 22:59 272432 ----a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090618.001\IDSvix86.sys
2009-06-20 03:54 . 2009-02-09 22:59 251768 ----a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090618.001\SymIDSCo.sys
2009-06-20 03:54 . 2009-02-09 22:59 685432 ----a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090618.001\IDSxpx86.dll
2009-06-20 03:54 . 2009-02-09 22:59 173432 ----a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090618.001\SymIDSI.dll
2009-06-20 03:54 . 2009-02-09 22:59 370224 ----a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090618.001\IDSviA64.sys
2009-06-20 03:54 . 2008-06-04 22:26 157120 ----a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090618.001\IDS9xx86.dll
2009-06-13 04:19 . 2009-06-13 04:19 -------- d-----w- c:\users\Tony\AppData\Roaming\DivX
2009-06-13 04:10 . 2009-04-30 12:37 428544 ----a-w- c:\windows\system32\EncDec.dll
2009-06-13 04:10 . 2009-04-30 12:37 293376 ----a-w- c:\windows\system32\psisdecd.dll
2009-06-13 03:34 . 2009-06-13 03:56 -------- d-----w- C:\divx
2009-06-13 03:32 . 2009-06-13 03:32 -------- d-----w- c:\program files\Common Files\DivX Shared
2009-06-13 03:32 . 2009-06-13 15:41 -------- d-----w- c:\program files\DivX
2009-06-13 01:51 . 2009-06-13 01:51 -------- d-----w- c:\users\Tony\AppData\Roaming\Red Kawa
2009-06-12 23:48 . 2009-06-12 23:48 -------- d-----w- c:\program files\AviSynth 2.5
2009-06-12 23:48 . 2009-06-12 23:48 -------- d-----w- c:\program files\Red Kawa
2009-06-12 23:31 . 2009-03-06 17:25 439672 ----a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090610.001\Scxpx86.dll
2009-06-12 23:31 . 2009-02-09 22:59 272432 ----a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090610.001\IDSvix86.sys
2009-06-12 23:31 . 2009-02-09 22:59 251768 ----a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090610.001\SymIDSCo.sys
2009-06-12 23:31 . 2009-02-09 22:59 685432 ----a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090610.001\IDSxpx86.dll
2009-06-12 23:31 . 2009-02-09 22:59 173432 ----a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090610.001\SymIDSI.dll
2009-06-12 23:31 . 2009-02-09 22:59 370224 ----a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090610.001\IDSviA64.sys
2009-06-12 23:31 . 2008-06-04 22:26 157120 ----a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090610.001\IDS9xx86.dll
2009-06-12 23:13 . 2009-06-12 23:13 -------- d-----w- c:\program files\DVD Decrypter
2009-06-06 15:04 . 2009-05-13 08:00 89104 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\tmp7d4b.tmp\NAVENG.SYS
2009-06-06 15:04 . 2009-05-13 08:00 876144 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\tmp7d4b.tmp\NAVEX15.SYS
2009-06-06 15:04 . 2009-05-13 08:00 371248 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\tmp7d4b.tmp\EECTRL.SYS
2009-06-06 15:04 . 2009-05-13 08:00 2414128 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\tmp7d4b.tmp\CCERASER.DLL
2009-06-06 15:04 . 2009-05-13 08:00 177520 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\tmp7d4b.tmp\NAVENG32.DLL
2009-06-06 15:04 . 2009-05-13 08:00 1181040 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\tmp7d4b.tmp\NAVEX32A.DLL
2009-06-06 15:04 . 2009-05-13 08:00 101936 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\tmp7d4b.tmp\ERASER.SYS
2009-06-06 15:04 . 2008-11-20 09:00 259368 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\tmp7d4b.tmp\ECMSVR32.DLL
2009-06-06 15:03 . 2009-06-05 23:10 1284 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\tmp10af.tmp\cur.scr
2009-05-27 17:12 . 2009-05-27 17:12 -------- d-----w- c:\users\Tony\AppData\Local\Mozilla
2009-05-27 16:34 . 2009-05-27 16:34 -------- d-----w- c:\program files\Microsoft Silverlight
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-22 18:09 . 2008-10-15 22:58 -------- d-----w- c:\program files\Image-Line
2009-06-22 18:09 . 2008-10-15 23:01 -------- d-----w- c:\program files\VstPlugins
2009-06-22 03:22 . 2008-10-16 02:53 -------- d-----w- c:\users\Tony\AppData\Roaming\LimeWire
2009-06-21 23:26 . 2008-07-04 23:11 -------- d-----w- c:\program files\Roxio
2009-06-13 15:02 . 2008-07-04 23:12 -------- d-----w- c:\program files\Common Files\PX Storage Engine
2009-06-13 15:01 . 2009-04-04 02:28 -------- d-----w- c:\program files\Common Files\AVSMedia
2009-06-13 15:00 . 2008-07-14 15:47 58896 ----a-w- c:\users\Tony\AppData\Local\GDIPFONTCACHEV1.DAT
2009-06-13 14:55 . 2009-04-04 02:28 -------- d-----w- c:\users\Tony\AppData\Roaming\AVS4YOU
2009-06-12 23:12 . 2008-07-14 17:20 7620 ----a-w- c:\users\Tony\AppData\Local\d3d9caps.dat
2009-06-11 18:07 . 2008-07-04 23:05 -------- d-----w- c:\programdata\Microsoft Help
2009-05-27 16:56 . 2008-09-16 02:22 -------- d-----w- c:\program files\Safari
2009-05-13 08:00 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-05-13 08:00 . 2009-05-13 08:00 89104 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\NAVENG.SYS
2009-05-13 08:00 . 2009-05-13 08:00 876144 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\NAVEX15.SYS
2009-05-13 08:00 . 2009-05-13 08:00 371248 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\EECTRL.SYS
2009-05-13 08:00 . 2009-05-13 08:00 2414128 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\CCERASER.DLL
2009-05-13 08:00 . 2009-05-13 08:00 177520 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\NAVENG32.DLL
2009-05-13 08:00 . 2009-05-13 08:00 1181040 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\NAVEX32A.DLL
2009-05-13 08:00 . 2009-05-13 08:00 101936 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\ERASER.SYS
2009-05-05 19:34 . 2008-07-04 23:07 -------- d-----w- c:\program files\Google
2009-05-05 02:02 . 2008-07-04 23:13 -------- d-----w- c:\programdata\Symantec
2009-05-01 23:52 . 2009-05-01 23:52 -------- d-----w- c:\program files\EG Toolbar
2009-05-01 23:51 . 2009-05-01 23:51 -------- d-----w- c:\program files\AGI
2009-05-01 23:51 . 2009-05-01 23:51 -------- d-----w- c:\programdata\AGI
2009-05-01 21:02 . 2009-05-01 21:02 90112 ----a-w- c:\windows\system32\dpl100.dll
2009-05-01 21:02 . 2009-05-01 21:02 823296 ----a-w- c:\windows\system32\divx_xx0c.dll
2009-05-01 21:02 . 2009-05-01 21:02 823296 ----a-w- c:\windows\system32\divx_xx07.dll
2009-05-01 21:02 . 2009-05-01 21:02 815104 ----a-w- c:\windows\system32\divx_xx0a.dll
2009-05-01 21:02 . 2009-05-01 21:02 811008 ----a-w- c:\windows\system32\divx_xx16.dll
2009-05-01 21:02 . 2009-05-01 21:02 802816 ----a-w- c:\windows\system32\divx_xx11.dll
2009-05-01 21:02 . 2009-05-01 21:02 685056 ----a-w- c:\windows\system32\DivX.dll
2009-05-01 05:19 . 2009-05-01 05:19 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2009-04-24 16:05 . 2009-06-11 16:24 827904 ----a-w- c:\windows\system32\wininet.dll
2009-04-24 16:02 . 2009-06-11 16:24 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-04-24 13:44 . 2009-06-11 16:24 26624 ----a-w- c:\windows\system32\ieUnatt.exe
2009-04-23 12:43 . 2009-06-11 16:24 784896 ----a-w- c:\windows\system32\rpcrt4.dll
2009-04-23 12:42 . 2009-06-11 16:24 636928 ----a-w- c:\windows\system32\localspl.dll
2009-04-21 11:55 . 2009-06-11 16:24 2033152 ----a-w- c:\windows\system32\win32k.sys
2009-04-16 02:58 . 2009-04-16 02:58 69632 ----a-w- c:\programdata\Apple Computer\Installer Cache\Safari 4.28.17.0\SetupAdmin.exe
2009-04-10 10:05 . 2009-04-10 10:05 710656 ----a-w- c:\windows\system32\nsn5506.dll
2009-04-01 04:07 . 2009-04-01 04:07 75048 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 8.1.0.52\SetupAdmin.exe
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2008-07-04 23:10 . 2008-07-04 23:10 76 --sh--r- c:\windows\CT4CET.bin
2008-07-05 01:42 . 2008-07-05 01:42 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{594bfff8-0c29-4e0d-42c2-89b5e6bcb8fa}]
2009-04-10 10:05 710656 ----a-w- c:\windows\System32\nsn5506.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-07-04 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2008-02-29 17920]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2008-03-11 163840]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2008-03-14 442433]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-10-03 178712]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-07-04 29744]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2008-03-11 16384]
"DpAgent"="c:\program files\DigitalPersona\Bin\dpagent.exe" [2008-03-26 699456]
"Dell Webcam Central"="c:\program files\Dell Webcam\Dell Webcam Central\WebcamDell.exe" [2008-02-19 438403]
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2008-01-14 132392]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-09-04 111936]
"DLCXCATS"="c:\windows\system32\spool\DRIVERS\W32X86\3\DLCXtime.dll" [2006-10-16 106496]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-03-13 342312]
c:\users\Tony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2008-5-13 1058088]
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-7 101440]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-07-04 23:16 10536 ----a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer"=wdmaud.drv
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli DPPWDFLT
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{D052325F-4BB1-4A73-B28F-13DC3A145922}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{C869460F-FEFA-402B-B636-861D67D3B0DA}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{6BCD244E-894A-4374-8513-4A6F155D909D}"= UDP:c:\program files\Dell Video Chat\DellVideoChat.exe

ell Video Chat
"{434DDE75-FED3-4BF4-A382-20C30308872D}"= TCP:c:\program files\Dell Video Chat\DellVideoChat.exe

ell Video Chat
"{353FD763-77F0-452D-80EF-DF59C028CFCB}"= c:\program files\Dell\MediaDirect\MediaDirect.exe

ell MediaDirect
"{9CE949B5-2A1C-48A1-A612-AFB23C813F6D}"= c:\program files\Dell\MediaDirect\PCMService.exe:CyberLink PowerCinema Resident Program
"{268D940B-202D-4B59-BBD6-40FAE51840B8}"= c:\program files\Dell\MediaDirect\Kernel\DMP\CLBrowserEngine.exe:Cyberlink Media Server Browser Engine
"{380B0A3A-A567-47FD-884E-242B7D4CBAD0}"= c:\program files\Dell\MediaDirect\Kernel\DMS\CLMSService.exe:CyberLink Media Server
"{BA620BA4-348C-4CD3-B334-555D2FA2DB55}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{EC7325B7-AA98-4829-9141-011C1BEE929B}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{3F5656FA-32F4-455D-8B20-5001184D1D6A}"= UDP:c:\program files\AIM6\aim6.exe:AIM
"{574D6260-0B7E-472E-9E8C-304D425C8574}"= TCP:c:\program files\AIM6\aim6.exe:AIM
"{7AE652D8-F277-4440-9C70-C33F4E74CCE1}"= UDP:c:\windows\System32\dlcxcoms.exe

ell 926 Server
"{3D20F299-749E-4FFA-A023-F88DEF47DE30}"= TCP:c:\windows\System32\dlcxcoms.exe

ell 926 Server
"{305858BC-E7B8-46B7-AA14-9E4C9EEA1375}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{29728F04-7094-4373-B2CC-DD084D2DE3BC}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{2938310D-9D46-4470-A0FD-62A619009E96}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{25B767AD-E06F-469C-AAE6-EE7714F62CCD}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{6E0734E9-7033-4CC7-BF79-EECB188B09AB}"= UDP:c:\program files\FrostWire\FrostWire.exe:FrostWire
"{3BE9ECDD-BB6F-43DC-AC73-A2740DE6D92E}"= TCP:c:\program files\FrostWire\FrostWire.exe:FrostWire
"{3110B33F-E035-4057-B6D4-1A827CEF353A}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{1DBA3A72-92BD-41B5-94F2-A2BED231E701}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{7883B24F-32D9-44D1-9021-FEA6E9AC6921}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{89FEFDFC-137A-43BB-B836-1F873CB2727E}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{5E4587BF-B4B7-4CB4-A85C-5CE235A44EDA}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{4BB8BAB6-DC86-49EC-BA67-A135C2D301C3}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R1 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\Symantec\DEFINI~1\SymcData\ipsdefs\20090618.001\IDSvix86.sys [6/19/2009 10:54 PM 272432]
R2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_c204e27d\AEstSrv.exe [7/4/2008 8:43 PM 73728]
R2 AGCoreService;AG Core Services;c:\program files\AGI\core\3.0\AGCoreService.exe [5/1/2009 6:51 PM 40960]
R2 ATService;AuthenTec Fingerprint Service;c:\program files\Fingerprint Sensor\AtService.exe [2/29/2008 4:37 AM 1053944]
R2 dlcx_device;dlcx_device;c:\windows\system32\dlcxcoms.exe -service --> c:\windows\system32\dlcxcoms.exe -service [?]
R2 DockLoginService

ock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [4/28/2008 4:56 PM 161048]
R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Common Files\Symantec Shared\CCSVCHST.EXE [12/27/2007 11:49 PM 149352]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [7/14/2008 10:51 AM 24652]
R3 ATSwpWDF;AuthenTec TruePrint USB WDF Driver;c:\windows\System32\drivers\ATSwpWDF.sys [7/4/2008 8:43 PM 548352]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2/25/2009 8:59 PM 101936]
R3 itecir;ITECIR Infrared Receiver;c:\windows\System32\drivers\itecir.sys [7/4/2008 8:43 PM 54784]
R3 k57nd60x;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\System32\drivers\k57nd60x.sys [7/4/2008 8:43 PM 203264]
R3 OA001Ufd;Creative Camera OA001 Upper Filter Driver;c:\windows\System32\drivers\OA001Ufd.sys [7/4/2008 8:43 PM 149208]
R3 OA001Vid;Creative Camera OA001 Function Driver;c:\windows\System32\drivers\OA001Vid.sys [7/4/2008 8:43 PM 277624]
R3 SYMNDISV;SYMNDISV;c:\windows\System32\drivers\symndisv.sys [2/19/2009 11:31 AM 41008]
S3 COH_Mon;COH_Mon;c:\windows\System32\drivers\COH_Mon.sys [12/27/2007 11:41 PM 23888]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\System32\drivers\motccgp.sys [8/22/2008 12:49 AM 18688]
S3 motccgpfl;MotCcgpFlService;c:\windows\System32\drivers\motccgpfl.sys [8/22/2008 12:49 AM 8320]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - COMHOST
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contents of the 'Scheduled Tasks' folder
2009-01-13 c:\windows\Tasks\Norton Internet Security - Run Full System Scan - Tony.job
- c:\program files\Norton Internet Security\Norton AntiVirus\Navw32.exe [2007-12-28 04:41]
.
- - - - ORPHANS REMOVED - - - -
BHO-{FA4AD251-0120-C110-FC9F-F31CC113A74D} - c:\windows\system32\iexjqmewqubntjcxl.dll
HKCU-Run-Aim6 - (no file)
HKLM-Run-qfyklspjim - c:\windows\system32\iexjqmewqubntjcxl.dll
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
DPF: CabBuilder - hxxp://ak.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
FF - ProfilePath - c:\users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\tdm88064.default\
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
---- FIREFOX POLICIES ----
FF - user.js: google.toolbar.linkdoctor.enabled - false
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-06-24 20:59
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCXCATS = rundll32 c:\windows\system32\spool\DRIVERS\W32X86\3\DLCXtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(700)
c:\windows\system32\DPPWDFLT.dll
- - - - - - - > 'Explorer.exe'(1488)
c:\program files\DigitalPersona\Bin\DpoFeedb.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\System32\Ati2evxx.exe
c:\windows\System32\DriverStore\FileRepository\stwrt.inf_c204e27d\stacsv.exe
c:\windows\System32\audiodg.exe
c:\windows\System32\Ati2evxx.exe
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\BCMWLTRY.EXE
c:\windows\System32\wlanext.exe
c:\program files\DigitalPersona\Bin\DpHostW.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\System32\dlcxcoms.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\program files\DellTPad\ApMsgFwd.exe
c:\program files\DellTPad\ApntEx.exe
c:\program files\DellTPad\hidfind.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\System32\wbem\WMIADAP.exe
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Completion time: 2009-06-25 21:04 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-25 02:04
Pre-Run: 136,557,043,712 bytes free
Post-Run: 137,279,275,008 bytes free
319 --- E O F --- 2009-06-13 14:41