Thank you. I did run ComboFix. I should preface and say that when I first double clicked on it, I received a Windows error box stating:
swreg.cfexe - Application Error
The insatruction at "0x7c9111de" referenced memory at "0x002000064". The memory could not be "read". Click on OK to terminate the program
When I clicked OK thru it, ComboFix proceeded to run and this is the log:
ComboFix 08-02.05.3 - Sherri 2008-02-07 8:54:34.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.499 [GMT -5:00]
Running from: C:\Documents and Settings\Sherri\Desktop\ComboFix.exe
* Created a new restore point
[color=\"red\"]
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/color]
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\x64
.
((((((((((((((((((((((((( Files Created from 2008-01-07 to 2008-02-07 )))))))))))))))))))))))))))))))
.
2008-02-06 11:57 . 2008-02-06 11:57 <DIR> d-------- C:\Program Files\Trend Micro
2008-02-06 11:35 . 2008-02-06 11:35 10,304 --a------ C:\WINDOWS\MSOPrefs.232
2008-02-06 11:35 . 2008-02-06 11:35 4,544 --a------ C:\WINDOWS\MSOClip.232
2008-01-30 14:58 . 2008-01-31 14:50 <DIR> d-------- C:\Program Files\Common Files\it-partners.com
2008-01-29 16:52 . 2008-01-29 16:52 14,848 --ahs---- C:\WINDOWS\system32\Thumbs.db
2008-01-24 12:59 . 2008-01-24 12:59 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\PopCap
2008-01-23 14:34 . 2008-01-23 14:34 <DIR> d-------- C:\Program Files\Real
2008-01-23 14:34 . 2008-01-23 14:34 <DIR> d-------- C:\Program Files\Common Files\xing shared
2008-01-23 14:34 . 2008-01-23 14:34 <DIR> d-------- C:\Program Files\Common Files\Real
2008-01-23 08:40 . 2008-01-23 08:40 <DIR> d-------- C:\Program Files\iTunes
2008-01-23 08:40 . 2008-01-23 08:40 <DIR> d-------- C:\Program Files\iPod
2008-01-23 08:40 . 2008-01-23 08:40 1,409 --a------ C:\WINDOWS\QTFont.for
2008-01-23 08:39 . 2008-01-23 08:39 <DIR> d-------- C:\Program Files\QuickTime
2008-01-14 15:01 . 2008-01-14 15:01 <DIR> d-------- C:\Program Files\Common Files\Data Dynamics
2008-01-10 15:27 . 2008-01-10 15:27 90,112 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx
2008-01-10 15:27 . 2008-01-10 15:27 57,344 --a------ C:\WINDOWS\system32\QuickTime.qts
2008-01-10 13:48 . 2008-01-10 13:48 <DIR> d-------- C:\_ResFile
2008-01-08 15:29 . 2008-01-08 15:29 <DIR> d-------- C:\Program Files\Picasa2
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-07 13:40 --------- d-----w C:\Program Files\Plaxo
2008-02-06 20:49 --------- d-----w C:\Program Files\Trillian
2008-01-31 19:52 737,280 ----a-w C:\WINDOWS\iun6002.exe
2008-01-31 19:52 --------- d-----w C:\Program Files\IDMS
2008-01-23 19:34 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-01-23 19:34 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2008-01-10 13:26 --------- d-----w C:\Program Files\Google
2007-12-12 15:31 18,027 ----a-w C:\Documents and Settings\Sherri\Desktop.zip
2007-12-12 14:47 --------- d-----w C:\Documents and Settings\Sherri\Application Data\Apple Computer
2007-12-12 14:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-12-12 14:46 --------- d-----w C:\Program Files\Common Files\Apple
2007-12-12 14:46 --------- d-----w C:\Program Files\Apple Software Update
2007-12-12 14:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
2007-12-11 19:36 --------- d-----w C:\Program Files\Lavasoft
2007-12-11 19:36 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-12-11 19:34 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-12-11 13:03 --------- d-----w C:\Program Files\McAfee
2007-12-11 13:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee
2006-06-11 22:11 45,056 --sh--r C:\WINDOWS\system32\mslogon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 04:00 15360]
"PlaxoUpdate"="C:\Program Files\Plaxo\3.7.1.2\PlaxoHelper_en.exe" [2007-12-20 09:50 283207]
"Weather"="C:\Program Files\AWS\WeatherBug\Weather.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2006-07-21 15:48 98304]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2006-07-21 15:50 86016]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2006-07-21 15:47 81920]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2006-05-01 07:07 843776]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 15:50 221184]
"McAfeeUpdaterUI"="C:\Program Files\McAfee\Common Framework\UpdaterUI.exe" [2006-10-30 03:06 131072]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 15:50 81920]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-01-10 15:27 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-15 03:22 267048]
"RoxioDragToDisc"="C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe" [2006-08-17 08:00 1116920]
"PMX Daemon"="ICO.EXE" [2007-03-08 10:58 49152 C:\WINDOWS\system32\ico.exe]
"PDVDDXSrv"="C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2006-10-20 16:23 118784]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
C:\Documents and Settings\Sherri\Start Menu\Programs\Startup\
Launch Microsoft Office Outlook.lnk - C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE [2003-07-14 22:45:18 196152]
systemnt.exe [2006-06-11 17:11:14 45056]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 15:05:56 65588]
R1 DLARTL_M;DLARTL_M;C:\WINDOWS\system32\Drivers\DLARTL_M.SYS [2006-08-11 09:35]
R2 ASFIPmon;Broadcom ASF IP Monitor;"C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe" [2006-03-17 16:25]
R3 pmxmouse;PMXMOUSE;C:\WINDOWS\system32\DRIVERS\pmxmouse.sys [2006-04-24 10:57]
R3 pmxusblf;PMXUSBLF;C:\WINDOWS\system32\DRIVERS\pmxusblf.sys [2006-04-24 10:59]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{196cd7ec-af14-11dc-81b9-001aa0da0fe6}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Toy.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{45cffb09-a274-11dc-81a4-001aa0da0fe6}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Toy.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{45cffb0e-a274-11dc-81a4-001aa0da0fe6}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Toy.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-02-07 08:56:25
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-02-07 8:56:43
.
2007-12-03 21:15:00 --- E O F ---
[quote name=\'guestolo\' post=\'421029\' date=\'Feb 6 2008, 10:52 PM\']Hi Sherri
Can you do the following please
Download this file -
Combofix.exe and save it ONLY to your desktop
Double click
combofix.exe & follow the prompts.
When finished, it shall produce a log for you.
Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall[/quote]