Hi shelf life,
Here is the log from combofix:
ComboFix 08-05-26.2 - Ahmad 2008-05-26 23:10:20.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1321 [GMT -4:00]
Running from: C:\Documents and Settings\Ahmad\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\qoMFULEX.dll
.
((((((((((((((((((((((((( Files Created from 2008-04-27 to 2008-05-27 )))))))))))))))))))))))))))))))
.
2008-05-26 17:43 . 2008-05-26 17:43 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-05-26 17:43 . 2008-05-26 17:43 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-05-26 17:43 . 2008-05-26 17:43 <DIR> d-------- C:\Documents and Settings\Ahmad\Application Data\Malwarebytes
2008-05-26 17:43 . 2008-05-05 20:46 27,048 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-05-26 17:43 . 2008-05-05 20:46 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-05-25 01:51 . 2008-05-25 01:51 <DIR> d-------- C:\Program Files\AskSBar
2008-05-25 01:51 . 2008-01-04 20:34 20,336 --a------ C:\WINDOWS\system32\drivers\SSFS0BB9.sys
2008-05-25 01:50 . 2008-05-25 01:50 164 --a------ C:\install.dat
2008-05-24 19:53 . 2008-05-24 19:53 <DIR> d-------- C:\!KillBox
2008-05-24 18:52 . 2008-05-24 18:52 244 --ah----- C:\sqmnoopt11.sqm
2008-05-24 18:52 . 2008-05-24 18:52 232 --ah----- C:\sqmdata11.sqm
2008-05-24 17:15 . 2008-05-24 17:15 244 --ah----- C:\sqmnoopt10.sqm
2008-05-24 17:15 . 2008-05-24 17:15 244 --ah----- C:\sqmnoopt09.sqm
2008-05-24 17:15 . 2008-05-24 17:15 232 --ah----- C:\sqmdata10.sqm
2008-05-24 17:15 . 2008-05-24 17:15 232 --ah----- C:\sqmdata09.sqm
2008-05-24 12:22 . 2008-05-24 15:57 <DIR> d-------- C:\Program Files\Panda Security
2008-05-24 09:50 . 2008-05-24 09:50 3,196 --a------ C:\WINDOWS\system32\tmp.reg
2008-05-23 20:38 . 2008-05-23 20:38 <DIR> d-------- C:\Program Files\Lavasoft
2008-05-23 20:38 . 2008-05-23 20:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-05-23 20:06 . 2008-05-23 20:06 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-05-23 18:43 . 2008-05-23 18:43 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Webroot
2008-05-23 18:21 . 2008-05-23 18:21 <DIR> d-------- C:\Documents and Settings\NetworkService\Application Data\Webroot
2008-05-23 17:52 . 2008-05-24 12:16 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-05-23 17:08 . 2008-05-23 17:08 244 --ah----- C:\sqmnoopt08.sqm
2008-05-23 17:08 . 2008-05-23 17:08 232 --ah----- C:\sqmdata08.sqm
2008-05-23 17:06 . 2008-05-23 17:06 <DIR> d-------- C:\Documents and Settings\Ahmad\Application Data\TmpRecentIcons
2008-05-23 04:42 . 2008-05-26 08:54 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Google Updater
2008-05-23 03:45 . 2008-05-23 03:45 244 --ah----- C:\sqmnoopt07.sqm
2008-05-23 03:45 . 2008-05-23 03:45 232 --ah----- C:\sqmdata07.sqm
2008-05-16 11:58 . 2008-05-16 11:58 12,632 --a------ C:\WINDOWS\system32\lsdelete.exe
2008-05-16 02:05 . 2008-05-16 02:05 <DIR> d--h----- C:\WINDOWS\PIF
2008-05-06 21:30 . 2008-05-06 21:37 <DIR> d-------- C:\Program Files\GMATPrep
2008-05-05 17:23 . 2008-05-05 17:23 268 --ah----- C:\sqmdata06.sqm
2008-05-05 17:23 . 2008-05-05 17:23 244 --ah----- C:\sqmnoopt06.sqm
2008-05-05 16:46 . 2008-05-05 16:46 244 --ah----- C:\sqmnoopt05.sqm
2008-05-05 16:46 . 2008-05-05 16:46 232 --ah----- C:\sqmdata05.sqm
2008-05-05 16:41 . 2008-05-05 16:41 244 --ah----- C:\sqmnoopt04.sqm
2008-05-05 16:41 . 2008-05-05 16:41 232 --ah----- C:\sqmdata04.sqm
2008-05-05 14:54 . 2008-05-05 14:54 244 --ah----- C:\sqmnoopt03.sqm
2008-05-05 14:54 . 2008-05-05 14:54 232 --ah----- C:\sqmdata03.sqm
2008-05-05 14:43 . 2008-05-05 14:43 244 --ah----- C:\sqmnoopt02.sqm
2008-05-05 14:43 . 2008-05-05 14:43 232 --ah----- C:\sqmdata02.sqm
2008-05-05 14:10 . 2008-05-05 14:10 244 --ah----- C:\sqmnoopt01.sqm
2008-05-05 14:10 . 2008-05-05 14:10 232 --ah----- C:\sqmdata01.sqm
2008-05-05 13:03 . 2008-05-05 13:03 244 --ah----- C:\sqmnoopt00.sqm
2008-05-05 13:03 . 2008-05-05 13:03 232 --ah----- C:\sqmdata00.sqm
2008-05-04 13:36 . 2008-05-04 13:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\PopCap
2008-05-03 19:09 . 2008-05-03 19:10 <DIR> d-------- C:\Documents and Settings\Ahmad\Application Data\Move Networks
2008-05-02 16:42 . 2008-05-02 16:55 <DIR> d-------- C:\ETS
2008-04-29 11:20 . 2008-04-29 11:20 15,648 --a------ C:\WINDOWS\system32\drivers\NSDriver.sys
2008-04-29 11:19 . 2008-04-29 11:19 15,648 --a------ C:\WINDOWS\system32\drivers\Awrtrd.sys
2008-04-29 11:19 . 2008-04-29 11:19 12,960 --a------ C:\WINDOWS\system32\drivers\Awrtpd.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-24 23:58 --------- d-----w C:\Program Files\Trend Micro
2008-05-23 21:38 --------- d-----w C:\Program Files\Google
2008-05-07 01:30 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-06 17:23 12,319 ----a-w C:\WINDOWS\system32\drivers\tmfilter.cat
2008-05-02 21:03 --------- d-----w C:\Program Files\Common Files\Adobe
2008-05-02 20:22 3,444 ----a-w C:\WINDOWS\system32\drivers\tmpreflt.inf
2008-05-02 20:22 205,328 ----a-w C:\WINDOWS\system32\drivers\tmxpflt.sys
2008-05-02 20:22 2,583 ----a-w C:\WINDOWS\system32\drivers\tmxpflt.inf
2008-05-02 20:21 36,368 ----a-w C:\WINDOWS\system32\drivers\tmpreflt.sys
2008-05-02 20:21 265,304 ----a-w C:\WINDOWS\system32\drivers\Tmfilter.sys
2008-05-02 20:17 2,544 ----a-w C:\WINDOWS\system32\drivers\vsapint.inf
2008-05-02 20:17 1,169,240 ----a-w C:\WINDOWS\system32\drivers\vsapint.sys
2008-04-26 21:27 --------- d-----w C:\Documents and Settings\Ahmad\Application Data\Apple Computer
2008-04-26 15:44 --------- d-----w C:\Documents and Settings\Ahmad\Application Data\Leadertech
2008-04-25 22:39 --------- d-----w C:\Program Files\Warcraft III
2008-04-22 22:18 2,829 ----a-w C:\WINDOWS\War3Unin.pif
2008-04-22 22:18 139,264 ----a-w C:\WINDOWS\War3Unin.exe
2008-04-22 20:21 --------- d-----w C:\Program Files\Windows Live Toolbar
2008-04-22 20:20 --------- d-----w C:\Program Files\Windows Live Favorites
2008-04-22 20:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-04-22 20:10 --------- d-----w C:\Program Files\Windows Live
2008-04-22 01:22 --------- d-----w C:\Documents and Settings\Ahmad\Application Data\Windows Live Writer
2008-04-21 23:40 --------- d-----w C:\Program Files\Microsoft SQL Server Compact Edition
2008-04-20 13:50 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-03-27 08:12 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-01 13:06 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2}]
2008-05-25 01:51 66912 --a------ C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}"= "C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL" [2008-05-25 01:51 267592]
[HKEY_CLASSES_ROOT\clsid\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}"= C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL [2008-05-25 01:51 267592]
[HKEY_CLASSES_ROOT\clsid\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 15:00 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-09-10 08:02 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-06 00:56 64512]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-10 15:00 33280 C:\WINDOWS\system32\rundll32.exe]
"nwiz"="nwiz.exe" [2005-09-18 10:32 1519616 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="RUNDLL32.exe" [2004-08-10 15:00 33280 C:\WINDOWS\system32\rundll32.exe]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 20:24 32768]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 15:28 577536 C:\WINDOWS\soundman.exe]
"Trend Micro AntiVirus 2007"="C:\Program Files\Trend Micro\AntiVirus 2007\tavui.exe" [2007-07-05 20:09 4609288]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 11:09 63712]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-12-11 11:56 286720]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-12-11 13:10 267048]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"SpySweeper"="C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" [2008-01-04 20:56 5367664]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
.
Contents of the 'Scheduled Tasks' folder
"2008-05-27 03:00:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-05-27 02:25:01 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-05-26 23:21:20
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\ehome\ehrecvr.exe
C:\WINDOWS\ehome\ehSched.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Trend Micro\AntiVirus 2007\tavsvc.exe
C:\Program Files\Trend Micro\AntiVirus 2007\components\TmProxy.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\ehome\ehmsas.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Webroot\Spy Sweeper\ssu.exe
.
**************************************************************************
.
Completion time: 2008-05-26 23:24:33 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-27 03:24:28
Pre-Run: 292,125,945,856 bytes free
Post-Run: 292,316,839,936 bytes free
179 --- E O F --- 2008-05-16 07:01:50