Thanks for reply DAVEINCAPS. I am certain jabuck's treatment(s) will catch the bad file that you have pointed out. Thanks again.
jabuck, thank you again for your support. Below is the Combofix log:
ComboFix 08-09-05.02 - Skip 2008-09-06 8:47:20.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.514 [GMT -4:00]
Running from: C:\Documents and Settings\Skip\Desktop\Downloads\Virus & Spyware\ComboFix.exe
* Created a new restore point
[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2008-08-06 to 2008-09-06 )))))))))))))))))))))))))))))))
.
2008-09-05 23:33 . 2008-09-05 23:33 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-09-05 23:33 . 2008-09-05 23:33 <DIR> d-------- C:\Documents and Settings\Skip\Application Data\Malwarebytes
2008-09-05 23:33 . 2008-09-05 23:33 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-05 23:33 . 2008-09-02 00:26 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-05 23:33 . 2008-09-02 00:25 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-09-04 13:06 . 2008-09-04 13:06 <DIR> d-------- C:\WINDOWS\system32\scripting
2008-09-04 13:06 . 2008-09-04 13:06 <DIR> d-------- C:\WINDOWS\system32\en
2008-09-04 13:06 . 2008-09-04 13:06 <DIR> d-------- C:\WINDOWS\system32\bits
2008-09-04 13:06 . 2008-09-04 13:06 <DIR> d-------- C:\WINDOWS\l2schemas
2008-09-04 13:00 . 2008-09-04 13:07 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-09-04 12:54 . 2008-09-04 13:14 2,639 --a------ C:\WINDOWS\imsins.BAK
2008-09-03 22:32 . 2008-04-13 20:12 1,737,856 --------- C:\WINDOWS\system32\mtxparhd.dll
2008-09-03 22:31 . 2008-04-13 20:11 397,312 --------- C:\WINDOWS\system32\mmcex.dll
2008-09-03 22:30 . 2008-04-13 20:11 1,888,992 --------- C:\WINDOWS\system32\ati3duag.dll
2008-08-22 07:19 . 2008-09-05 23:53 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-08-22 07:19 . 2008-08-22 10:29 <DIR> d-------- C:\Documents and Settings\Skip\Application Data\AVGTOOLBAR
2008-08-22 07:19 . 2008-08-22 07:19 97,928 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-08-22 07:19 . 2008-08-22 07:19 76,040 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-08-22 07:19 . 2008-08-22 07:19 12,936 --a------ C:\WINDOWS\system32\drivers\avgrkx86.sys
2008-08-22 07:19 . 2008-08-22 07:19 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-08-22 07:18 . 2008-08-22 07:18 <DIR> d-------- C:\Program Files\AVG
2008-08-22 07:18 . 2008-08-22 07:18 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-08-13 03:26 . 2008-04-11 15:04 691,712 --------- C:\WINDOWS\system32\dllcache\inetcomm.dll
2008-08-13 03:26 . 2008-05-01 10:33 331,776 --------- C:\WINDOWS\system32\dllcache\msadce.dll
2008-08-09 14:42 . 2008-08-09 14:42 29,808 --a------ C:\WINDOWS\system32\drivers\ssfs0bbc.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-06 12:41 --------- d-----w C:\Program Files\Media Resizer PRO
2008-09-06 12:25 --------- d-----w C:\Program Files\Dl_cats
2008-08-21 16:30 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee
2008-08-21 16:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2008-08-09 20:04 1,538,928 ----a-w C:\WINDOWS\WRSetup.dll
2008-08-09 18:42 23,152 ----a-w C:\WINDOWS\system32\drivers\sshrmd.sys
2008-08-09 18:42 166,512 ----a-w C:\WINDOWS\system32\drivers\ssidrv.sys
2008-08-05 20:58 --------- d-----w C:\Documents and Settings\Skip\Application Data\gtk-2.0
2008-08-03 00:35 --------- d-----w C:\Program Files\Avidemux 2.4
2008-08-02 16:16 --------- d-----w C:\Documents and Settings\Skip\Application Data\ArcSoft
2008-07-30 01:16 --------- d-----w C:\Program Files\eMusic Download Manager
2008-07-27 15:43 --------- d-----w C:\Program Files\Blender Foundation
2008-07-27 15:41 --------- d-----w C:\Documents and Settings\Skip\Application Data\avidemux
2008-07-27 15:37 --------- d-----w C:\Program Files\GIMP-2.0
2008-07-27 15:34 --------- d-----w C:\Documents and Settings\Skip\Application Data\jah
2008-07-27 15:31 --------- d-----w C:\Program Files\OpenLibraries
2008-07-27 15:31 --------- d-----w C:\Program Files\Jahshaka
2008-07-27 15:31 --------- d-----w C:\Program Files\Jahplayer
2008-07-27 15:29 86,016 ----a-w C:\WINDOWS\system32\OpenAL32.dll
2008-07-27 15:29 262,144 ----a-w C:\WINDOWS\system32\wrap_oal.dll
2008-07-27 15:28 --------- d-----w C:\Program Files\mlt
2008-07-27 15:28 --------- d-----w C:\Program Files\gtk2
2008-07-27 15:19 --------- d-----w C:\Program Files\Java
2008-07-19 02:10 94,920 ----a-w C:\WINDOWS\system32\dllcache\cdm.dll
2008-07-19 02:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-19 02:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-19 02:10 53,448 ----a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
2008-07-19 02:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-19 02:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-19 02:10 36,552 ----a-w C:\WINDOWS\system32\dllcache\wups.dll
2008-07-19 02:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-19 02:09 563,912 ----a-w C:\WINDOWS\system32\dllcache\wuapi.dll
2008-07-19 02:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-19 02:09 325,832 ----a-w C:\WINDOWS\system32\dllcache\wucltui.dll
2008-07-19 02:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-19 02:09 205,000 ----a-w C:\WINDOWS\system32\dllcache\wuweb.dll
2008-07-19 02:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-19 02:09 1,811,656 ----a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
2008-07-19 02:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
2008-07-19 02:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
2008-07-10 21:24 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-10 21:24 --------- d-----w C:\Program Files\ArcSoft
2008-07-10 21:15 --------- d-----w C:\Program Files\DV TS
2008-07-07 20:26 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-07-07 20:26 253,952 ------w C:\WINDOWS\system32\dllcache\es.dll
2008-06-24 16:43 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-24 16:43 74,240 ------w C:\WINDOWS\system32\dllcache\mscms.dll
2008-06-20 17:46 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 17:46 245,248 ------w C:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 17:46 147,968 ------w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-06-20 11:51 361,600 ------w C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 11:40 138,496 ------w C:\WINDOWS\system32\dllcache\afd.sys
2008-06-20 11:08 225,856 ------w C:\WINDOWS\system32\dllcache\tcpip6.sys
2008-06-13 11:05 272,128 ------w C:\WINDOWS\system32\dllcache\bthport.sys
2006-07-02 00:09 251 ----a-w C:\Program Files\wt3d.ini
2004-08-23 08:31 192,512 ----a-w C:\WINDOWS\inf\rmoem.exe
2002-11-14 14:32 55,808 ----a-w C:\WINDOWS\inf\devcon.exe
2008-05-25 23:14 88 --sh--r C:\WINDOWS\system32\9589B4C7EC.sys
2008-03-15 04:08 104 --sh--r C:\WINDOWS\system32\ECC7B48995.sys
2008-05-25 23:14 7,518 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-08-22 1235736]
"SpySweeper"="C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" [2008-08-09 5418864]
"DLCXCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll" [2006-10-16 106496]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Monitor.lnk - C:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe [2008-07-10 110592]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^802.11g USB adapter.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\802.11g USB adapter.lnk
backup=C:\WINDOWS\pss\802.11g USB adapter.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Photags AutoDetect.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Photags AutoDetect.lnk
backup=C:\WINDOWS\pss\Photags AutoDetect.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Skip^Start Menu^Programs^Startup^Event Reminder.lnk]
path=C:\Documents and Settings\Skip\Start Menu\Programs\Startup\Event Reminder.lnk
backup=C:\WINDOWS\pss\Event Reminder.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 23:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2008-04-13 20:12 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
--a------ 2007-03-15 11:09 460784 C:\Program Files\DellSupport\DSAgnt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DLCXCATS]
--a------ 2006-10-16 01:31 106496 C:\WINDOWS\system32\spool\drivers\w32x86\3\dlcxtime.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dlcxmon.exe]
--a------ 2007-01-12 12:57 292336 C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DMXLauncher]
--a------ 2005-10-05 03:12 94208 C:\Program Files\Dell\Media Experience\DMXLauncher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FaxCenterServer]
--a------ 2006-11-03 18:09 312200 C:\Program Files\Dell PC Fax\fm3032.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM]
--a------ 2006-09-11 04:40 218032 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
--a------ 2006-09-11 04:40 218032 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
--a------ 2006-09-11 04:40 86960 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2006-02-23 15:45 278528 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MemoryCardManager]
--a------ 2006-11-03 18:04 304008 C:\Program Files\Dell Photo AIO Printer 926\memcard.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2006-12-28 20:22 282624 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpySweeper]
--a------ 2008-08-09 16:04 5418864 C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"MioNet"=2 (0x2)
"iPodService"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Documents and Settings\\Skip\\My Documents\\Websites\\Ipswitch\\WS_FTP95.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\WINDOWS\\system32\\dlcxcoms.exe"=
"C:\\Program Files\\SmartFTP Client\\SmartFTP.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1700:TCP"= 1700:TCP:MioNet Remote Drive Access
"1641:TCP"= 1641:TCP:MioNet Remote Drive Verification
R0 AvgRkx86;avgrkx86.sys;C:\WINDOWS\system32\Drivers\avgrkx86.sys [2008-08-22 12936]
R0 ssfs0bbc;ssfs0bbc;C:\WINDOWS\system32\DRIVERS\ssfs0bbc.sys [2008-08-09 29808]
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-08-22 97928]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-08-22 76040]
R2 dlcx_device;dlcx_device;C:\WINDOWS\system32\dlcxcoms.exe [2006-10-11 532480]
R3 camvid40;Philips SPC 900NC PC Camera;C:\WINDOWS\system32\DRIVERS\camdrv41.sys [2005-08-25 1240576]
S2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-08-22 875288]
S2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-08-22 231704]
S3 CoachUsb;Coach Digital Camera on USB;C:\WINDOWS\system32\DRIVERS\CoachUsb.sys [2004-11-24 50976]
S3 usbvm328;HP Camera;C:\WINDOWS\system32\Drivers\usbvm326.sys [ ]
S3 vmfilter323;VC0326 filter service for Serome;C:\WINDOWS\system32\drivers\vmfilter323.sys [2007-04-13 475264]
S4 MioNet;MioNet Service;C:\Program Files\MioNet\MioNetManager.exe [ ]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0ac10097-9f62-11db-afc1-0003c95093f4}]
\Shell\AutoRun\command - F:\podcastready.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
\Shell\AutoRun\command - E:\setup.exe
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -
HKU-Default-Run-DWQueuedReporting - C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe
MSConfigStartUp-!AVG Anti-Spyware - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
MSConfigStartUp-mcagent_exe - C:\Program Files\McAfee.com\Agent\mcagent.exe
MSConfigStartUp-SiteAdvisor - C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.google.com/
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-06 09:13:04
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCXCATS = rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-09-06 9:22:36
ComboFix-quarantined-files.txt 2008-09-06 13:22:10
ComboFix2.txt 2008-03-03 04:25:39
ComboFix3.txt 2008-03-03 03:14:07
ComboFix4.txt 2008-03-02 03:31:45
Pre-Run: 23,276,392,448 bytes free
Post-Run: 23,393,103,872 bytes free
226 --- E O F --- 2008-09-04 23:59:16