Here's the ComboFix log. Thanks again!ComboFix 08-02-20.1 - User1 2008-02-19 15:19:24.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1340 [GMT -5:00]
Running from: C:\Documents and Settings\User1\Desktop\ComboFix.exe
* Created a new restore point
[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\MabryObj.dll
.
((((((((((((((((((((((((( Files Created from 2008-01-20 to 2008-02-20 )))))))))))))))))))))))))))))))
.
2008-02-14 14:10 . 2008-02-19 14:30 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-02-14 14:10 . 2008-02-14 14:10 1,409 --a------ C:\WINDOWS\QTFont.for
2008-02-14 10:31 . 2008-02-14 10:32 <DIR> d-------- C:\Program Files\QuickTime
2008-01-31 23:13 . 2008-01-31 23:13 90,112 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx
2008-01-31 23:13 . 2008-01-31 23:13 57,344 --a------ C:\WINDOWS\system32\QuickTime.qts
2008-01-27 20:37 . 2008-01-27 20:37 <DIR> d-------- C:\Program Files\Common Files\xing shared
2008-01-22 16:42 . 2008-01-22 16:42 <DIR> d-------- C:\Program Files\Lavasoft
2008-01-22 16:42 . 2008-01-22 16:42 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-22 16:41 . 2008-01-22 16:41 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-20 20:19 --------- d-----w C:\Documents and Settings\All Users\Application Data\SyncClient
2008-02-19 19:36 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-02-05 15:07 --------- d-----w C:\Documents and Settings\User1\Application Data\IEPro
2008-01-28 01:37 --------- d-----w C:\Program Files\Common Files\Real
2008-01-22 22:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-22 21:37 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-01-22 21:09 --------- d-----w C:\Documents and Settings\User1\Application Data\Lavasoft
2008-01-18 01:02 --------- d-----w C:\Program Files\Winamp
2008-01-16 00:06 --------- d-----w C:\Program Files\iPod
2008-01-08 12:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\Examsoft
2008-01-07 19:44 --------- d-----w C:\Documents and Settings\User1\Application Data\MiniDm
2008-01-05 17:58 --------- d-----w C:\Program Files\IEPro
2008-01-05 17:57 --------- d-----w C:\Program Files\IE7Pro
2008-01-05 17:56 --------- d-----w C:\Documents and Settings\User1\Application Data\IE7Pro
2007-12-24 04:04 --------- d-----w C:\Documents and Settings\User1\Application Data\Apple Computer
2007-12-24 04:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-12-24 03:58 --------- d-----w C:\Program Files\Common Files\Apple
2007-12-14 16:32 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2007-12-07 02:21 824,832 ----a-w C:\WINDOWS\system32\wininet.dll
2007-12-04 18:38 550,912 ----a-w C:\WINDOWS\system32\oleaut32.dll
2007-05-01 18:19 20 -c-h--w C:\Documents and Settings\All Users\Application Data\PKP_DLec.DAT
2007-05-01 18:19 20 -c-h--w C:\Documents and Settings\All Users\Application Data\PKP_DLds.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 12:39 1289000]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-25 14:53 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-12-13 16:41 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-12-13 16:45 118784]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2006-04-06 13:58 1032192]
"SigmatelSysTrayApp"="stsystra.exe" [2006-03-24 16:30 282624 C:\WINDOWS\stsystra.exe]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 11:48 761947]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11 132496]
"McAfeeUpdaterUI"="C:\Program Files\Network Associates\Common Framework\UdaterUI.exe" [2007-10-25 15:06 136512]
"ShStatEXE"="C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.exe" [2007-08-13 20:50 111952]
"iTunesHelper"="D:\Program Files\iTunes\iTunesHelper.exe" [2008-01-15 03:22 267048]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-01-27 20:36 185896]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-01-31 23:13 385024]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-05-24 18:28:28 622653]
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-10-25 14:53:45 126136]
Wireless Sync Client.lnk - C:\Program Files\Wireless Sync\Client\Monitor.exe [2005-08-24 14:41:22 606282]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableCAD"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMMyPictures"= 1 (0x1)
[HKLM\~\startupfolder\C:^Documents and Settings^User1^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=C:\Documents and Settings\User1\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 22:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
--a------ 2006-11-13 12:39 1289000 C:\Program Files\Microsoft ActiveSync\wcescomm.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OpwareSE2]
--a------ 2003-05-08 12:00 49152 C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-01-31 23:13 385024 C:\Program Files\QuickTime\qttask.exe
S3 brfilt;Brother MFC Filter Driver;C:\WINDOWS\system32\Drivers\Brfilt.sys [2001-08-17 12:12]
S3 BrSerWDM;Brother Serial driver;C:\WINDOWS\system32\Drivers\BrSerWdm.sys [2001-08-17 12:12]
S3 BrUsbMdm;Brother MFC USB Fax Only Modem;C:\WINDOWS\system32\Drivers\BrUsbMdm.sys [2001-08-17 12:12]
S3 BrUsbScn;Brother MFC USB Scanner driver;C:\WINDOWS\system32\Drivers\BrUsbScn.sys [2001-08-17 12:12]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{81544bce-da35-11db-8d0d-0015c515507d}]
\Shell\AutoRun\command - F:\setupSNK.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a2fe02d2-6754-11db-8bc8-0015c515507d}]
\Shell\AutoRun\command - F:\LaunchU3.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-02-12 23:55:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-01-10 23:26:22 C:\WINDOWS\Tasks\SyncBack Documents Backup On Startup.job"
- d:\Program Files\2BrightSparks\SyncBack\SyncBack.exe!-m
"2008-02-06 15:00:00 C:\WINDOWS\Tasks\SyncBack Group Backup.job"
- C:\Program Files\2BrightSparks\SyncBack\SyncBack.exe
"2008-02-06 15:00:01 C:\WINDOWS\Tasks\SyncBack Group Law School Backup.job"
- C:\Program Files\2BrightSparks\SyncBack\SyncBack.exe
"2008-02-19 19:29:50 C:\WINDOWS\Tasks\SyncBack Law School Backup C to D.job"
- C:\Program Files\2BrightSparks\SyncBack\SyncBack.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-20 15:23:17
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-02-20 15:23:59
ComboFix-quarantined-files.txt 2008-02-20 20:23:51
.
2008-02-13 18:52:38 --- E O F ---