The Log for Combofix:
ComboFix 07-08-14.4 - "Ands" 2007-08-21 12:00:36.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.452 [GMT 1:00]
* Created a new restore point
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\jkkjg.dll
((((((((((((((((((((((((( Files Created from 2007-07-21 to 2007-08-21 )))))))))))))))))))))))))))))))
2007-08-21 11:59 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-08-19 19:12 <DIR> d-------- C:\potrename
2007-08-19 19:07 <DIR> d-------- C:\Harry Potter and the Prisoner of Azkaban
2007-08-19 19:00 1,417,160 --a------ C:\ComboFix.exe
2007-08-19 16:19 <DIR> d-------- C:\Program Files\SopCast
2007-08-18 20:39 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-08-18 20:39 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab
2007-08-18 19:42 <DIR> d-------- C:\Program Files\Wise Registry Cleaner
2007-08-18 15:35 <DIR> d-------- C:\Program Files\Trend Micro
2007-08-17 16:47 <DIR> d-------- C:\Program Files\iTunes
2007-08-17 16:47 <DIR> d-------- C:\Program Files\iPod
2007-08-15 22:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-08-15 21:06 1,152 --a------ C:\WINDOWS\system32\windrv.sys
2007-08-15 21:06 <DIR> d-------- C:\Program Files\Common Files\Download Manager
2007-08-15 17:43 1,156 --a------ C:\WINDOWS\mozver.dat
2007-08-15 17:40 <DIR> d-------- C:\DOCUME~1\Ands\.housecall6.6
2007-08-14 19:22 <DIR> d-------- C:\Program Files\MSXML 6.0
2007-08-14 15:53 <DIR> d-------- C:\Program Files\WinAVI Video Converter
2007-08-10 15:19 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab Setup Files
2007-08-08 23:24 1,470 --a------ C:\WINDOWS\system32\tmp.reg
2007-08-08 17:30 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2007-08-04 08:47 9,488 --a------ C:\WINDOWS\system32\sporder.dll
2007-08-04 08:41 <DIR> d-------- C:\Program Files\Common Files\Panda Software
2007-08-03 13:53 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2007-08-03 11:36 <DIR> d-a------ C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
2007-07-30 14:06 63 --a------ C:\WINDOWS\system\SYSRegC.dll
2007-07-30 14:06 143,360 --a------ C:\WINDOWS\system32\GetHardDiskNo.dll
2007-07-30 14:06 1,126,400 --a------ C:\WINDOWS\system32\VchReg.dll
2007-07-30 14:06 <DIR> d-------- C:\Program Files\Max Registry Cleaner
2007-07-24 10:48 <DIR> d-------- C:\Program Files\QuickTime
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-08-21 12:04 --------- d-------- C:\DOCUME~1\Ands\APPLIC~1\Azureus
2007-08-19 17:05 --------- d-------- C:\Program Files\Common Files\AOL
2007-08-19 17:02 --------- d-------- C:\Program Files\MSN Messenger
2007-08-19 08:23 --------- d-------- C:\Program Files\Azureus
2007-08-17 16:27 --------- d-------- C:\DOCUME~1\Ands\APPLIC~1\Real
2007-08-17 15:49 --------- d-------- C:\Program Files\Apple Software Update
2007-08-16 17:24 --------- d-------- C:\Program Files\CyberLink
2007-08-16 17:22 --------- d--h----- C:\Program Files\InstallShield Installation Information
2007-08-11 11:26 --------- d-------- C:\DOCUME~1\Ands\APPLIC~1\dvdcss
2007-08-07 22:09 --------- d-------- C:\Program Files\DirectVobSub
2007-08-07 22:09 --------- d-------- C:\Program Files\AOL 9.0
2007-08-05 16:49 203776 --a------ C:\WINDOWS\system32\clrviddc.dll
2007-08-04 21:06 --------- d-------- C:\DOCUME~1\Ands\APPLIC~1\LimeWire
2007-08-04 14:16 --------- d-------- C:\Program Files\Real
2007-08-03 18:54 8552 --a------ C:\WINDOWS\system32\drivers\asctrm.sys
2007-08-03 17:21 --------- d-------- C:\Program Files\RealMedia
2007-08-02 17:28 848 --ahs---- C:\WINDOWS\system32\KGyGaAvL.sys
2007-07-24 11:00 --------- d-------- C:\Program Files\DivX
2007-07-09 20:07 524288 --a------ C:\WINDOWS\system32\DivXsm.exe
2007-07-09 20:07 3596288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2007-07-09 20:07 200704 --a------ C:\WINDOWS\system32\ssldivx.dll
2007-07-09 20:07 1044480 --a------ C:\WINDOWS\system32\libdivx.dll
2007-07-09 20:05 823296 --a------ C:\WINDOWS\system32\divx_xx0c.dll
2007-07-09 20:05 823296 --a------ C:\WINDOWS\system32\divx_xx07.dll
2007-07-09 20:05 802816 --a------ C:\WINDOWS\system32\divx_xx11.dll
2007-07-09 20:05 740442 --a------ C:\WINDOWS\system32\DivX.dll
2007-07-09 20:05 73728 --a------ C:\WINDOWS\system32\dpl100.dll
2007-07-09 20:05 593920 --a------ C:\WINDOWS\system32\dpuGUI11.dll
2007-07-09 20:05 57344 --a------ C:\WINDOWS\system32\dpv11.dll
2007-07-09 20:05 53248 --a------ C:\WINDOWS\system32\dpuGUI10.dll
2007-07-09 20:05 344064 --a------ C:\WINDOWS\system32\dpus11.dll
2007-07-09 20:05 294912 --a------ C:\WINDOWS\system32\dpu11.dll
2007-07-09 20:05 294912 --a------ C:\WINDOWS\system32\dpu10.dll
2007-07-09 20:05 196608 --a------ C:\WINDOWS\system32\dtu100.dll
2007-07-09 20:05 124472 --a------ C:\WINDOWS\system32\DivXCodecUpdateChecker.exe
2007-07-09 20:05 12288 --a------ C:\WINDOWS\system32\DivXWMPExtType.dll
2007-07-06 14:33 --------- d-------- C:\DOCUME~1\Ands\APPLIC~1\Lavasoft
2007-07-04 17:59 --------- d-------- C:\Program Files\Common Files\Apple
2007-06-27 15:34 6058496 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2007-06-27 15:34 52224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-06-27 15:34 459264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-06-27 15:34 383488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-06-27 15:34 267776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2007-06-27 09:27 13824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-06-26 16:13 851968 --a--c--- C:\WINDOWS\system32\dllcache\vgx.dll
2007-06-26 15:09 658944 --a--c--- C:\WINDOWS\system32\dllcache\wininet.dll
2007-06-26 07:08 1104896 --a--c--- C:\WINDOWS\system32\dllcache\msxml3.dll
2007-06-26 07:08 1104896 --a------ C:\WINDOWS\system32\msxml3.dll
2007-06-19 14:31 282112 --a--c--- C:\WINDOWS\system32\dllcache\gdi32.dll
2007-06-19 14:31 282112 --a------ C:\WINDOWS\system32\gdi32.dll
2007-06-14 19:09 96256 --a--c--- C:\WINDOWS\system32\dllcache\inseng.dll
2007-06-14 19:09 615424 --a--c--- C:\WINDOWS\system32\dllcache\urlmon.dll
2007-06-14 19:09 55808 --a--c--- C:\WINDOWS\system32\dllcache\extmgr.dll
2007-06-14 19:09 532480 --a--c--- C:\WINDOWS\system32\dllcache\mstime.dll
2007-06-14 19:09 474112 --a--c--- C:\WINDOWS\system32\dllcache\shlwapi.dll
2007-06-14 19:09 449024 --a--c--- C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-06-14 19:09 39424 --a--c--- C:\WINDOWS\system32\dllcache\pngfilt.dll
2007-06-14 19:09 357888 --a--c--- C:\WINDOWS\system32\dllcache\dxtmsft.dll
2007-06-14 19:09 3058688 --a--c--- C:\WINDOWS\system32\dllcache\mshtml.dll
2007-06-14 19:09 251392 --a--c--- C:\WINDOWS\system32\dllcache\iepeers.dll
2007-06-14 19:09 205312 --a--c--- C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-06-14 19:09 16384 --a--c--- C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-06-14 19:09 151040 --a--c--- C:\WINDOWS\system32\dllcache\cdfview.dll
2007-06-14 19:09 1494528 --a--c--- C:\WINDOWS\system32\dllcache\shdocvw.dll
2007-06-14 19:09 146432 --a--c--- C:\WINDOWS\system32\dllcache\msrating.dll
2007-06-14 19:09 1054208 --a--c--- C:\WINDOWS\system32\dllcache\danim.dll
2007-06-14 19:09 1023488 --a--c--- C:\WINDOWS\system32\dllcache\browseui.dll
2007-06-14 15:07 18432 --a--c--- C:\WINDOWS\system32\dllcache\iedw.exe
2007-06-13 12:26 1033216 --a--c--- C:\WINDOWS\system32\dllcache\explorer.exe
2007-06-13 12:26 1033216 --a------ C:\WINDOWS\explorer.exe
2007-06-11 23:51 10834944 --a--c--- C:\WINDOWS\system32\dllcache\wmp.dll
2007-03-10 18:29 87608 --a------ C:\DOCUME~1\Ands\APPLIC~1\ezpinst.exe
2007-03-10 18:29 47360 --a------ C:\DOCUME~1\Ands\APPLIC~1\pcouffin.sys
2006-12-05 20:51 915968 --a------ C:\Program Files\WinRAR.exe
2006-12-05 20:51 483 --a------ C:\Program Files\rarreg.key
2006-12-05 20:36 22 --a------ C:\Program Files\zipnew.dat
2006-12-05 20:36 20 --a------ C:\Program Files\rarnew.dat
2006-12-03 15:53 98304 --a------ C:\Program Files\Uninstall.exe
2006-12-03 15:53 66560 --a------ C:\Program Files\Zip.SFX
2006-12-03 15:53 651 --a------ C:\Program Files\Uninstall.lst
2006-12-03 15:53 405874 --a------ C:\Program Files\WinRAR.hlp
2006-12-03 15:53 126464 --a------ C:\Program Files\RarExt.dll
2006-12-03 15:53 100864 --a------ C:\Program Files\Default.SFX
2006-12-03 15:52 313856 --a------ C:\Program Files\Rar.exe
2006-12-03 15:52 200704 --a------ C:\Program Files\UnRAR.exe
2006-12-02 15:34 9232 --a------ C:\Program Files\TechNote.txt
2006-12-02 15:34 71189 --a------ C:\Program Files\Rar.txt
2006-12-02 15:34 502 --a------ C:\Program Files\File_Id.diz
2006-12-02 15:32 16536 --a------ C:\Program Files\WhatsNew.txt
2006-09-14 01:19 79360 --a------ C:\Program Files\WinCon.SFX
2006-06-29 19:35 9695 --a------ C:\Program Files\WinRAR.cnt
2006-04-11 13:01 1088 --a------ C:\Program Files\RarFiles.lst
2005-10-18 19:20 3128 --a------ C:\Program Files\Order.htm
2005-10-18 19:10 4494 --a------ C:\Program Files\License.txt
2005-06-07 13:26 43008 --a------ C:\Program Files\RarExt64.dll
2005-06-07 13:25 44032 --a------ C:\Program Files\RarExtLoader.exe
2005-06-02 17:05 1111 --a------ C:\Program Files\Descript.ion
2005-05-12 19:02 90 --a------ C:\Program Files\UnrarSrc.txt
2005-05-12 19:01 1687 --a------ C:\Program Files\ReadMe.txt
2007-05-20 13:11:02 5 --sha-w C:\WINDOWS\system32\fccdfeaf7_d.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-22 13:22]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-08-04 14:16]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-07-31 18:44]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 06:24]
"HostManager"="C:\Program Files\Common Files\AOL\1173538569\ee\AOLSoftware.exe" [2006-11-17 14:21]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:07]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 21:05]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"RunNarrator"=Narrator.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AOL 9.0 Tray Icon.lnk]
backup=C:\WINDOWS\pss\AOL 9.0 Tray Icon.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^hp psc 1000 series.lnk]
backup=C:\WINDOWS\pss\hp psc 1000 series.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^hpoddt01.exe.lnk]
backup=C:\WINDOWS\pss\hpoddt01.exe.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
backup=C:\WINDOWS\pss\Logitech Desktop Messenger.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Ands^Start Menu^Programs^Startup^IMVU.lnk]
backup=C:\WINDOWS\pss\IMVU.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!AVG Anti-Spyware]
"C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\%FP%Friendly fts.exe]
"C:\Program Files\VoyagerTest\fts.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
"C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast!]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG7_CC]
"C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" /STARTUP
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVP]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DSLAGENTEXE]
dslagent.exe USB
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
"C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GSICONEXE]
gsicon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
C:\Program Files\Common Files\AOL\1173538569\ee\AOLSoftware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelliPoint]
"c:\Program Files\Microsoft IntelliPoint\ipoint.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\itype]
"c:\Program Files\Microsoft IntelliType Pro\itype.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
"RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RCAutoLiveUpdate]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RCSystemTray]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirusProtectPro 3.5]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
C:\Program Files\Windows Media Player\WMPNSCFG.exe
R2 AutoExNT;AutoExNT;C:\WINDOWS\system32\AutoExNT.Exe
R3 Point32;Microsoft IntelliPoint Filter Driver;C:\WINDOWS\system32\DRIVERS\point32.sys
R3 PPPoEWin;PPPoEWin Miniport;C:\WINDOWS\system32\DRIVERS\PPPoEWin.SYS
S3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver;C:\WINDOWS\system32\DRIVERS\fetnd5.sys
S3 glausb;GlobeSpan USB ADSL LAN Modem;C:\WINDOWS\system32\DRIVERS\glausb.sys
S3 PavSRK.sys;PavSRK.sys;\??\C:\WINDOWS\system32\PavSRK.sys
S3 PavTPK.sys;PavTPK.sys;\??\C:\WINDOWS\system32\PavTPK.sys
S3 pgfilter;pgfilter;\??\C:\Program Files\PeerGuardian2\pgfilter.sys
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\K]
AutoRun\command- K:\Autorun.exe
Contents of the 'Scheduled Tasks' folder
2007-08-17 14:49:17 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
2007-06-14 14:32:17 C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1173792879.job - C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-08-21 12:05:39
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-08-21 12:08:45 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-08-21 12:08
--- E O F ---