Here is the combofix log .. hope I did it right! The 007 guard page popped up again last night before I went to bed (Australian time)
ComboFix 07-10-12.1 - Glenys 2007-10-13 7:34:31.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.212 [GMT 10:00]
Running from: C:\Documents and Settings\Glenys\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Glenys\Desktop\CFScript.txt
* Created a new restore point
FILE::
C:\WINDOWS\system32\sysdl132.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\ieimprover
C:\Program Files\ieimprover\bho.dat
C:\Program Files\ieimprover\er.dat
C:\Program Files\ieimprover\ie-improver.dll
C:\Program Files\ieimprover\uninstall.exe
C:\WINDOWS\system32\sysdl132.exe
.
((((((((((((((((((((((((( Files Created from 2007-09-12 to 2007-10-12 )))))))))))))))))))))))))))))))
.
2007-10-13 07:30 <DIR> d-------- C:\Program Files\Common Files\Java
2007-10-12 07:15 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-10-11 18:23 <DIR> d-------- C:\Program Files\Trend Micro
2007-10-10 22:11 <DIR> d-------- C:\Documents and Settings\Adam\Application Data\Grisoft
2007-10-10 21:23 <DIR> d-------- C:\Documents and Settings\Guest\Application Data\Grisoft
2007-10-10 20:57 <DIR> d-------- C:\Documents and Settings\Glenys\Application Data\Grisoft
2007-10-10 20:57 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-10-10 20:56 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-10-07 22:45 <DIR> d---s---- C:\Documents and Settings\Guest\UserData
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-12 21:31 --------- d-----w C:\Program Files\Java
2007-10-10 11:42 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-10-10 10:10 --------- d-----w C:\Program Files\SpywareBlaster
2007-10-09 11:38 --------- d-----w C:\Program Files\LimeWire
2007-09-11 08:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\DVD Shrink
2007-09-06 10:05 94,416 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
2007-09-06 10:05 92,848 -c--a-w C:\WINDOWS\system32\drivers\aswmon.sys
2007-09-06 10:03 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
2007-09-06 10:02 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
2007-09-06 10:00 26,624 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
2007-09-01 04:15 --------- d-----w C:\Program Files\Windows Live Safety Center
2007-08-31 21:49 --------- d-----w C:\Documents and Settings\Guest\Application Data\MySpace
.
((((((((((((((((((((((((((((( snapshot@2007-10-12_ 7.19.19.76 )))))))))))))))))))))))))))))))))))))))))
.
- 2006-10-11 14:35:14 49,248 -c--a-w C:\WINDOWS\system32\java.exe
+ 2007-09-24 12:30:28 135,168 ----a-w C:\WINDOWS\system32\java.exe
- 2006-10-11 14:35:24 53,346 -c--a-w C:\WINDOWS\system32\javaw.exe
+ 2007-09-24 12:30:30 135,168 ----a-w C:\WINDOWS\system32\javaw.exe
- 2006-10-11 16:10:56 127,078 -c--a-w C:\WINDOWS\system32\javaws.exe
+ 2007-09-24 13:31:42 139,264 ----a-w C:\WINDOWS\system32\javaws.exe
+ 2007-10-12 21:37:16 16,384 ----atw C:\WINDOWS\temp\Perflib_Perfdata_570.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SMSERIAL"="sm56hlpr.exe" [2005-06-06 19:40 C:\WINDOWS\sm56hlpr.exe]
"SoundMan"="SOUNDMAN.EXE" [2004-12-22 19:09 C:\WINDOWS\SOUNDMAN.EXE]
"LVCOMS"="C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE" [2001-09-24 08:39]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-09-06 20:06]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 09:50]
"UserFaultCheck"="C:\WINDOWS\system32\dumprep 0 -u" []
"Easy-PrintToolBox"="C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.exe" [2004-01-14 11:10]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-10-25 17:58]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-10-30 08:36]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 11:09]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 19:25]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 11:54]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-08-14 10:04]
"WebCamRT.exe"="" []
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"MySpaceIM"=C:\Program Files\MySpace\IM\MySpaceIM.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
R1 DcCam;Kodak Camera Proxy;C:\WINDOWS\system32\DRIVERS\DcCam.sys
R2 DCFS2K;Kodak DCFS2K Driver;C:\WINDOWS\system32\drivers\dcfs2k.sys
R2 ptssvc;ptssvc;C:\Program Files\KODAK\KODAK Picture Transfer Software\PTSsvc.exe
S1 Exportit;Exportit;C:\WINDOWS\system32\DRIVERS\exportit.sys
S3 DcFpoint;DcFpoint;C:\WINDOWS\system32\DRIVERS\DcFpoint.sys
S3 DcLps;Legacy Polling Service;C:\WINDOWS\system32\DRIVERS\DcLps.sys
S3 DcPTP;dcptp;C:\WINDOWS\system32\DRIVERS\DcPTP.sys
S3 w300bus;Sony Ericsson W300 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\w300bus.sys
S3 w300mdfl;Sony Ericsson W300 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\w300mdfl.sys
S3 w300mdm;Sony Ericsson W300 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\w300mdm.sys
S3 w300mgmt;Sony Ericsson W300 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\w300mgmt.sys
S3 w300obex;Sony Ericsson W300 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\w300obex.sys
.
Contents of the 'Scheduled Tasks' folder
"2007-10-08 22:03:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
.
**************************************************************************
catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2007-10-13 07:37:40
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-10-13 7:40:12 - machine was rebooted
C:\ComboFix2.txt ... 2007-10-12 07:19
.
--- E O F ---