Combofix log:
“Marlene Cruz” - 2007-07-10 17:23:46 - ComboFix 07-07-10.1 - Service Pack 2
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\DOCUME~1\MARLEN~1\APPLIC~1.\searchtoolbarcorp
C:\WINDOWS\system32\bszip.dll
((((((((((((((((((((((((( Files Created from 2007-06-10 to 2007-07-10 )))))))))))))))))))))))))))))))
2007-07-10 17:17 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-07-10 16:40 d-------- C:\Program Files\Trend Micro
2007-07-10 02:07 3,968 --a------ C:\WINDOWS\system32\drivers\AvgArCln.sys
2007-07-08 10:42 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-07-08 09:32 d-------- C:\Deckard
2007-07-08 08:33 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2007-07-08 01:42 d-------- C:\00e2e8fb4dfb0eb7cb
2007-07-07 19:10 d-------- C:\DOCUME~1\MARLEN~1\APPLIC~1\Apple Computer
2007-07-07 19:09 d-------- C:\Program Files\iPod
2007-07-07 19:08 d-------- C:\Program Files\iTunes
2007-07-07 19:06 d-------- C:\Program Files\QuickTime
2007-07-07 19:05 d-------- C:\Program Files\Apple Software Update
2007-07-07 19:04 d-------- C:\Program Files\Common Files\Apple
2007-07-07 19:04 d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
2007-07-07 19:01 d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
2007-07-07 18:40 149,504 --a------ C:\WINDOWS\UNWISE.EXE
2007-06-30 00:23 d-------- C:\Program Files\BearShare Applications
2007-06-30 00:23 d-------- C:\DOCUME~1\MARLEN~1\APPLIC~1\BearShare
2007-06-29 16:20 d-------- C:\Program Files\PCFriendly
2007-06-15 19:01 d-------- C:\DOCUME~1\MARLEN~1\APPLIC~1\Walgreens
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-07-10 06:43:47 -------- d-----w C:\Program Files\Documents To Go
2007-07-10 05:54:22 -------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-07-10 05:52:19 -------- d-----w C:\Program Files\Symantec
2007-07-07 23:50:47 -------- d-----w C:\Program Files\Yahoo!
2007-07-07 23:49:29 -------- d-----w C:\Program Files\palmOne
2007-07-07 23:47:43 -------- d-----w C:\Program Files\MUSICMATCH
2007-07-07 23:41:10 -------- d-----w C:\Program Files\Dell
2007-07-07 23:38:37 -------- d–h–w C:\Program Files\InstallShield Installation Information
2007-05-22 22:56:45 -------- d-----w C:\Program Files\MTV Networks
2007-05-22 22:07:06 -------- d-----w C:\Program Files\Windows Media Connect 2
2007-05-16 15:12:02 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-04-30 15:46:10 745,600 ----a-w C:\WINDOWS\system32\aswBoot.exe
2007-04-30 15:35:28 95,872 ----a-w C:\WINDOWS\system32\AVASTSS.scr
2007-04-25 14:21:15 144,896 ----a-w C:\WINDOWS\system32\schannel.dll
2007-04-18 16:12:23 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll
2007-04-17 03:47:36 33,624 ----a-w C:\WINDOWS\system32\wups.dll
2007-04-17 03:45:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-17 03:45:48 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-04-17 03:45:42 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-04-17 03:45:36 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-04-17 03:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-04-17 03:45:20 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-17 03:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
1758-03-20 05:27:13 4,263 --sh–w C:\WINDOWS\windllreg1c.sys
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
Note empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE~\Browser Helper Objects{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
2006-12-18 04:16 59032 --a------ C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
[HKEY_LOCAL_MACHINE~\Browser Helper Objects{5CA3D70E-1895-11CF-8E15-001234567890}]
2004-12-06 01:05 118842 --a------ C:\WINDOWS\system32\dla\tfswshx.dll
[HKEY_LOCAL_MACHINE~\Browser Helper Objects{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
2007-03-14 03:43 501400 --a------ C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
[HKEY_LOCAL_MACHINE~\Browser Helper Objects{AA58ED58-01DD-4d91-8333-CF10577473F7}]
2006-10-17 15:04 2120768 -ra------ c:\program files\google\googletoolbar2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“SunJavaUpdateSched”=“C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe” [2007-03-14 03:43]
“QuickTime Task”=“C:\Program Files\QuickTime\qttask.exe” [2007-04-27 09:41]
“ISUSPM Startup”=“C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe” [2004-07-27 16:50]
“ISUSScheduler”=“C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe” [2004-07-27 16:50]
“PCSuiteTrayApplication”=“C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.exe” [2006-04-26 07:29]
“Premium Clock”=“C:\Program Files\Premium Clock\Premium.exe”
“avast!”=“C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe” [2007-04-30 10:42]
“iTunesHelper”=“C:\Program Files\iTunes\iTunesHelper.exe” [2007-06-28 09:14]
“!AVG Anti-Spyware”=“C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe” [2007-06-11 04:25]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“MSMSGS”=“C:\Program Files\Messenger\msmsgs.exe” [2004-10-13 11:24]
“PcSync”=“C:\Program Files\Nokia\Nokia PC Suite 6\PCSync2.exe” [2006-04-11 16:52]
“ctfmon.exe”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-04 05:00]
“swg”=“C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe” [2006-12-02 20:49]
[HKEY_USERS.default\software\microsoft\windows\currentversion\run]
“ALUAlert”=C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
“{57B86673-276A-48B2-BAE7-C6DBB3020EB8}”=“C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll” [2007-05-30 07:29]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Driver]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Guard]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
backup=C:\WINDOWS\pss\America Online 9.0 Tray Icon.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
backup=C:\WINDOWS\pss\QuickBooks Update Agent.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell QuickSet]
C:\Program Files\Dell\QuickSet\quickset.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DMXLauncher]
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
“C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe”
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MMTray]
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PRONoMgrWired]
C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QBReminderFlash]
“C:\Program Files\Intuit\QuickBooks 2005\Atom\QBReminder.exe”
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPLpr]
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
AutoRun\command- F:\LaunchU3.exe -a
Contents of the ‘Scheduled Tasks’ folder
2007-07-08 00:05:31 C:\WINDOWS\tasks\AppleSoftwareUpdate.job
2005-11-07 19:05:08 C:\WINDOWS\tasks\Low Battery Alarm Program.job
catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-10 17:27:39
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
Completion time: 2007-07-10 17:28:39
C:\ComboFix-quarantined-files.txt … 2007-07-10 17:28
--- E O F ---