and the combofix log:
ComboFix 07-12-28.1 - Ellen Allen 2007-12-29 16:41:55.1 - NTFSx86
Running from: C:\Documents and Settings\Ellen Allen\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Starware347
C:\Documents and Settings\All Users\Application Data\Starware347\buttons\FindIt.bmp
C:\Documents and Settings\All Users\Application Data\Starware347\buttons\FindItHot.bmp
C:\Documents and Settings\All Users\Application Data\Starware347\buttons\findithotxp.png
C:\Documents and Settings\All Users\Application Data\Starware347\buttons\finditxp.png
C:\Documents and Settings\All Users\Application Data\Starware347\buttons\Highlight.bmp
C:\Documents and Settings\All Users\Application Data\Starware347\buttons\HighlightHot.bmp
C:\Documents and Settings\All Users\Application Data\Starware347\buttons\highlighthotxp.png
C:\Documents and Settings\All Users\Application Data\Starware347\buttons\highlightxp.png
C:\Documents and Settings\All Users\Application Data\Starware347\buttons\jokesearch.bmp
C:\Documents and Settings\All Users\Application Data\Starware347\buttons\pranks.bmp
C:\Documents and Settings\All Users\Application Data\Starware347\buttons\starware_toolbar_icon.bmp
C:\Documents and Settings\All Users\Application Data\Starware347\contexts\error.xml
C:\Documents and Settings\All Users\Application Data\Starware347\contexts\related.xml
C:\Documents and Settings\All Users\Application Data\Starware347\contexts\travel.xml
C:\Temp\bkR11
C:\WINDOWS\b122.exe
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\bbadd.ini
C:\WINDOWS\system32\bbadd.ini2
C:\WINDOWS\system32\ddabb.dll
C:\WINDOWS\system32\fbheksyo.dll
C:\WINDOWS\system32\ixjrfgue.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\tqcxkfqt.dll
C:\WINDOWS\system32\tqfkxcqt.ini
C:\WINDOWS\system32\vbtgnrfx.dll
C:\WINDOWS\system32\yjtivrvk(2).dll
C:\WINDOWS\Fonts\-
.
((((((((((((((((((((((((( Files Created from 2007-11-28 to 2007-12-29 )))))))))))))))))))))))))))))))
.
2007-12-29 14:22 . 2007-12-29 14:22 552 --a------ C:\WINDOWS\system32\d3d8caps.dat
2007-12-29 13:39 . 2006-12-20 18:24 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\You've Got Pictures Screensaver
2007-12-29 13:39 . 2006-12-20 18:32 <DIR> d--h----- C:\Documents and Settings\Administrator\Application Data\Gtek
2007-12-29 13:39 . 2006-12-28 16:02 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\AOL
2007-12-27 22:03 . 2007-12-27 23:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-27 19:04 . 2007-12-27 19:04 <DIR> d-------- C:\Program Files\Lavasoft
2007-12-27 19:04 . 2007-12-27 19:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-12-27 19:01 . 2007-12-27 19:01 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-12-27 18:15 . 2007-12-29 13:48 1,031,799 --ahs---- C:\WINDOWS\system32\komrsmog.ini
2007-12-26 22:06 . 2005-10-14 20:45 135,168 --a------ C:\WINDOWS\system32\igfxres.dll
2007-12-26 22:05 . 2007-12-26 22:05 13,726 --a------ C:\WINDOWS\system32\wpa.bak
2007-12-26 21:43 . 2004-08-04 10:00 1,875,968 --a--c--- C:\WINDOWS\system32\dllcache\msir3jp.lex
2007-12-26 21:42 . 2004-08-04 10:00 13,463,552 --a--c--- C:\WINDOWS\system32\dllcache\hwxjpn.dll
2007-12-26 21:41 . 2004-08-04 10:00 1,677,824 --a--c--- C:\WINDOWS\system32\dllcache\chsbrkr.dll
2007-12-26 21:40 . 2004-05-13 00:39 876,653 --a--c--- C:\WINDOWS\system32\dllcache\fp4awel.dll
2007-12-26 21:37 . 2007-12-26 21:37 749 -rah----- C:\WINDOWS\WindowsShell.Manifest
2007-12-26 21:37 . 2007-12-26 21:37 749 -rah----- C:\WINDOWS\system32\wuaucpl.cpl.manifest
2007-12-26 21:37 . 2007-12-26 21:37 749 -rah----- C:\WINDOWS\system32\sapi.cpl.manifest
2007-12-26 21:37 . 2007-12-26 21:37 749 -rah----- C:\WINDOWS\system32\ncpa.cpl.manifest
2007-12-26 21:37 . 2007-12-26 21:37 488 -rah----- C:\WINDOWS\system32\logonui.exe.manifest
2007-12-26 21:36 . 2004-08-04 10:00 32,768 --a--c--- C:\WINDOWS\system32\dllcache\icwdl.dll
2007-12-26 21:35 . 2004-08-04 10:00 214,528 --a--c--- C:\WINDOWS\system32\dllcache\icwconn1.exe
2007-12-26 21:35 . 2004-08-04 10:00 86,016 --a--c--- C:\WINDOWS\system32\dllcache\icwconn2.exe
2007-12-26 21:35 . 2004-08-04 10:00 20,480 --a--c--- C:\WINDOWS\system32\dllcache\inetwiz.exe
2007-12-26 21:10 . 2004-08-04 10:00 24,661 --a------ C:\WINDOWS\system32\spxcoins.dll
2007-12-26 21:10 . 2004-08-04 10:00 24,661 --a--c--- C:\WINDOWS\system32\dllcache\spxcoins.dll
2007-12-26 21:10 . 2004-08-04 10:00 13,312 --a------ C:\WINDOWS\system32\irclass.dll
2007-12-26 21:10 . 2004-08-04 10:00 13,312 --a--c--- C:\WINDOWS\system32\dllcache\irclass.dll
2007-12-26 20:57 . 2007-12-26 20:57 <DIR> d-------- C:\WINDOWS\dell
2007-12-26 17:37 . 2007-12-27 18:13 1,028,080 --ahs---- C:\WINDOWS\system32\jrtbwqaf.ini
2007-12-13 20:19 . 2007-12-13 20:19 <DIR> d-------- C:\Program Files\Real
2007-12-13 20:19 . 2007-12-13 20:19 <DIR> d-------- C:\Program Files\Common Files\Oberon Media
2007-12-09 22:15 . 2007-12-13 20:15 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Exetender
2007-12-09 22:15 . 2007-12-09 22:15 68 --a------ C:\WINDOWS\GPlrLanc.dat
2007-12-09 22:14 . 2007-12-12 22:40 <DIR> d-------- C:\Remote Programs
2007-12-09 22:14 . 2007-12-13 20:15 <DIR> d-------- C:\Program Files\Metaboli Player
2007-12-08 14:27 . 2007-12-08 14:27 147,456 --a------ C:\WINDOWS\system32\vbzip10.dll
2007-12-08 14:23 . 2007-12-08 14:23 <DIR> d-------- C:\WINDOWS\system32\daSgo05
2007-12-08 14:23 . 2007-12-29 16:49 <DIR> d-------- C:\Temp
2007-12-08 09:24 . 2007-12-08 09:31 <DIR> d-------- C:\Program Files\Prima Games
2007-12-07 20:21 . 2007-12-07 20:21 4,096 --a------ C:\WINDOWS\d3dx.dat
2007-12-07 19:40 . 2007-12-09 18:14 <DIR> d-------- C:\Program Files\Oberon Media
2007-12-06 20:53 . 2007-12-06 22:00 <DIR> d-------- C:\Program Files\Private Eye Greatest Unsolved Mysteries
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-29 16:55 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-12-29 14:50 --------- d-----w C:\Program Files\Norton Security Scan
2007-12-27 18:30 --------- d-----w C:\Documents and Settings\Ellen Allen\Application Data\SiteAdvisor
2007-12-26 23:20 --------- d-----w C:\Documents and Settings\Nathan Allen\Application Data\LimeWire
2007-12-26 17:41 --------- d-----w C:\Program Files\SiteAdvisor
2007-12-13 20:20 --------- d-----w C:\Program Files\McAfee
2007-12-13 20:19 --------- d-----w C:\Program Files\QuickTime
2007-12-09 22:14 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-09 19:25 --------- d-----w C:\Program Files\Common Files\Real
2007-12-08 09:30 --------- d-----w C:\Program Files\Common Files\Adobe
2007-12-07 21:25 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-04 17:09 --------- d-----w C:\Program Files\Windows Live Toolbar
2007-12-02 17:01 --------- d-----w C:\Documents and Settings\LocalService\Application Data\SiteAdvisor
2007-11-08 20:33 32,320 ----a-w C:\Documents and Settings\Ellen Allen\Application Data\GDIPFONTCACHEV1.DAT
2007-02-11 11:23 32,320 ----a-w C:\Documents and Settings\Nathan Allen\Application Data\GDIPFONTCACHEV1.DAT
2006-12-28 17:41 0 ----a-w C:\Documents and Settings\Ellen Allen\Application Data\wklnhst.dat
2007-02-16 16:19 168 -csh--r C:\WINDOWS\system32\D89B8F0DD6.sys
2007-02-16 16:21 5,642 -csha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4D728346-1DC2-4A3A-9978-A182CB287EA4}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4f41171d-4643-49e5-a28d-934df558e6e2}]
C:\WINDOWS\system32\vbtgnrfx.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B21F0EC6-0DB6-41EB-81A5-C669D1263BA5}]
C:\WINDOWS\system32\ddabb.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 10:00]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-03 19:23]
"Router"="C:\Program Files\Router\Router.exe" []
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2005-11-01 03:12]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 18:48]
"Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY.exe" [2006-11-01 04:48]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-09-08 05:20]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 16:50]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 16:50]
"@"="" []
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2005-10-26 17:17]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 10:00 C:\WINDOWS\system32\bthprops.cpl]
"Corel Photo Downloader"="C:\Program Files\Corel\Corel Snapfire Plus\Corel Photo Downloader.exe" [2006-08-14 14:20]
"MskAgentexe"="C:\Program Files\McAfee\MSK\MskAgent.exe" [2007-01-17 16:30]
"SiteAdvisor"="C:\Program Files\SiteAdvisor\6172\SiteAdv.exe" [2007-04-10 18:35]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-10-14 20:49]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-10-14 20:46]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-10-14 20:50]
"SigmatelSysTrayApp"="stsystra.exe" [2006-03-24 23:30 C:\WINDOWS\stsystra.exe]
"fc5fefc7"="C:\WINDOWS\system32\tqcxkfqt.dll" []
"combofix"="C:\WINDOWS\system32\cmd.exe" [2004-08-04 10:00]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 10:00]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-12-20 18:19:52]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\rqrpolk]
rqrpolk.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
"LoadAppInit_DLLs"=1 (0x1)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
2005-06-06 23:46 57344 --a------ C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe /startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
R2 hnmwrlspkt;HomeNet Manager Wireless Protocol;C:\WINDOWS\system32\DRIVERS\hnm_wrls_pkt.sys [2006-07-14 01:01]
R2 wsppkt;Wireless Security Protocol;C:\WINDOWS\system32\DRIVERS\wsp_pkt.sys [2006-07-14 01:02]
S3 usb2vcom;USB to Serial Bridge Controller;C:\WINDOWS\system32\Drivers\usb2vcom.sys [2005-12-28 15:42]
S3 w300bus;Sony Ericsson W300 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\w300bus.sys [2006-03-13 16:49]
S3 w300mdfl;Sony Ericsson W300 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\w300mdfl.sys [2006-03-13 16:50]
S3 w300mdm;Sony Ericsson W300 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\w300mdm.sys [2006-03-13 16:50]
S3 w300mgmt;Sony Ericsson W300 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\w300mgmt.sys [2006-03-13 16:50]
S3 w300obex;Sony Ericsson W300 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\w300obex.sys [2006-03-13 16:50]
.
Contents of the 'Scheduled Tasks' folder
"2007-12-29 16:27:08 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2007-01-18 20:15:03 C:\WINDOWS\Tasks\Low Battery Alarm Program.job"
"2007-04-18 21:31:11 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe'
"2007-04-18 21:31:10 C:\WINDOWS\Tasks\McQcTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe
"2007-10-08 19:24:52 C:\WINDOWS\Tasks\Norton Security Scan.job"
- C:\Program Files\Norton Security Scan\Nss.exe
"2007-12-29 16:50:01 C:\WINDOWS\Tasks\User_Feed_Synchronization-{136FABBF-C4F5-4BBA-A191-99063CF123E1}.job"
- C:\WINDOWS\system32\msfeedssync.exe
.
**************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-12-29 16:57:17
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-29 17:00:15 - machine was rebooted
.
2007-12-13 23:42:46 --- E O F ---