here is my log:
ComboFix 10-01-04.01 - claire 01/05/2010 14:09:43.2.2 - x86
Microsoft
Windows Vista
Home Premium 6.0.6002.2.1252.1.1033.18.3062.2075 [GMT -6:00]
Running from: c:\users\claire\Desktop\commy.exe
Command switches used :: /stepdel
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
c:\$recycle.bin\S-1-5-21-3878062665-890052964-3471927553-500
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2009-12-05 to 2010-01-05 )))))))))))))))))))))))))))))))
.
2010-01-05 20:15 . 2010-01-05 20:15 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-01-03 09:00 . 2010-01-03 09:00 -------- d-----w- c:\program files\MSXML 4.0
2010-01-02 06:49 . 2010-01-02 06:50 -------- d-----w- c:\program files\Microsoft Location Finder
2010-01-02 06:49 . 2010-01-02 06:50 -------- d-----w- c:\program files\Microsoft Streets and Trips Essentials
2010-01-02 06:46 . 2010-01-02 06:47 -------- d-----w- c:\program files\Encarta
2010-01-02 06:41 . 2010-01-02 06:45 -------- d-----w- c:\program files\Microsoft Digital Image 2006
2010-01-02 06:39 . 2010-01-02 06:40 -------- d-----w- c:\program files\microsoft money
2010-01-02 06:28 . 2010-01-02 06:28 -------- d-----w- c:\windows\system32\URTTEMP
2010-01-02 06:27 . 2010-01-02 06:27 -------- d-----w- c:\program files\Microsoft Works Suite 2006
2010-01-01 21:08 . 2010-01-01 21:32 -------- d-----w- c:\program files\Snood 4
2009-12-31 19:11 . 2009-12-31 19:11 -------- d-----w- c:\programdata\Norton
2009-12-31 19:11 . 2009-12-31 19:11 -------- d-----w- c:\windows\system32\drivers\NSS
2009-12-31 19:11 . 2009-12-31 19:11 -------- d-----w- c:\program files\Norton Security Scan
2009-12-31 19:11 . 2009-12-31 19:11 -------- d-----w- c:\programdata\NortonInstaller
2009-12-31 19:11 . 2009-12-31 19:11 -------- d-----w- c:\program files\NortonInstaller
2009-12-28 04:53 . 2009-12-28 04:54 -------- d-----w- c:\windows\system32\Adobe
2009-12-26 07:15 . 2009-12-26 07:15 690952 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2009-12-09 22:30 . 2009-11-09 12:31 24064 ----a-w- c:\windows\system32\nshhttp.dll
2009-12-09 22:30 . 2009-11-09 12:30 30720 ----a-w- c:\windows\system32\httpapi.dll
2009-12-09 22:30 . 2009-11-09 10:36 411648 ----a-w- c:\windows\system32\drivers\http.sys
2009-12-08 22:57 . 2009-10-07 11:36 243712 ----a-w- c:\windows\system32\rastls.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-03 09:03 . 2009-09-26 03:39 -------- d-----w- c:\program files\Microsoft Works
2010-01-02 06:52 . 2009-09-26 00:30 94808 ----a-w- c:\users\claire\AppData\Local\GDIPFONTCACHEV1.DAT
2009-12-31 19:11 . 2009-09-26 03:41 -------- d-----w- c:\programdata\Symantec
2009-12-20 21:43 . 2009-09-26 03:51 -------- d-----w- c:\program files\Java
2009-12-14 05:55 . 2009-10-02 01:31 204 ----a-w- c:\users\claire\AppData\Roaming\wklnhst.dat
2009-12-09 23:04 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-12-09 22:30 . 2009-09-26 03:47 -------- d-----w- c:\programdata\Microsoft Help
2009-12-03 01:03 . 2009-09-26 01:05 -------- d-----w- c:\programdata\McAfee
2009-11-27 09:19 . 2009-11-27 09:19 -------- d-----w- c:\program files\Windows Portable Devices
2009-11-27 09:19 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-11-27 09:19 . 2009-11-27 09:19 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-11-26 19:49 . 2009-11-26 19:49 680 ----a-w- c:\users\claire\AppData\Local\d3d9caps.dat
2009-11-26 17:31 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Calendar
2009-11-26 17:31 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar
2009-11-26 17:31 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Journal
2009-11-26 17:31 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Collaboration
2009-11-26 17:31 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Photo Gallery
2009-11-26 17:30 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender
2009-11-21 06:40 . 2009-12-08 22:58 916480 ----a-w- c:\windows\system32\wininet.dll
2009-11-21 06:34 . 2009-12-08 22:58 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-11-21 06:34 . 2009-12-08 22:58 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-11-21 04:59 . 2009-12-08 22:58 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-11-17 00:48 . 2009-11-17 00:48 652296 ----a-w- c:\programdata\Microsoft\eHome\Packages\SportsTemplate\SportsTemplateCore\Microsoft.MediaCenter.Sports.UI.dll
2009-11-17 00:47 . 2009-11-17 00:47 416128 ----a-w- c:\programdata\Microsoft\eHome\Packages\NetTV\Browse\NetTVResources.dll
2009-11-01 16:31 . 2009-11-01 16:31 79144 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2009-10-29 09:17 . 2009-11-25 09:00 2048 ----a-w- c:\windows\system32\tzres.dll
2009-10-11 10:17 . 2009-09-26 01:37 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-10-08 21:08 . 2009-11-27 09:01 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
2009-10-08 21:08 . 2009-11-27 09:01 234496 ----a-w- c:\windows\system32\oleacc.dll
2009-10-08 21:07 . 2009-11-27 09:01 4096 ----a-w- c:\windows\system32\oleaccrc.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-09-26 39408]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-01-02 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-01-02 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-01-02 133656]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-07-12 178712]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-04-26 865840]
"Camera Assistant Software"="c:\program files\Camera Assistant Software for Gateway\traybar.exe" [2007-09-13 638976]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2009-10-19 30192]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-10-29 1218008]
"McENUI"="c:\progra~1\McAfee\MHN\McENUI.exe" [2009-07-08 1176808]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-10-29 141600]
"SigmatelSysTrayApp"="sttray.exe" [2007-09-07 405504]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"NetFxUpdate_v1.1.4322"="c:\windows\Microsoft.NET\Framework\v1.1.4322\netfxupdate.exe" [2004-08-10 106496]
c:\users\claire\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2008-10-25 98696]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):d4,e9,fe,19,bf,6e,ca,01
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [9/25/2009 7:15 PM 93320]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [1/20/2008 8:23 PM 21504]
S3 GoogleDesktopManager-093009-130223;Google Desktop Manager 5.9.909.30391;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [9/25/2009 9:50 PM 30192]
S3 NETw2v32;Intel(R) PRO/Wireless 2200BG Network Connection Driver for Windows Vista;c:\windows\System32\drivers\NETw2v32.sys [11/2/2006 4:25 AM 2589184]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
2009-09-26 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-10-21 17:22]
2010-01-01 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-10-21 17:22]
2010-01-01 c:\windows\Tasks\Norton Security Scan for claire.job
- c:\program files\Norton Security Scan\Engine\2.7.0.52\Nss.exe [2009-12-31 19:11]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.att.net/
mStart Page = hxxp://www.gateway.com/g/startpage.html?Ch=Retail&SubCH=ODT&Br=GTW&Loc=ENG_US&Sys=PTB&M=M-6827
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-05 14:15
Windows 6.0.6002 Service Pack 2 NTFS
scanning hȋdden processes ...
scanning hȋdden autostart entries ...
scanning hȋdden files ...
c:\users\claire\AppData\Local\Temp\catchme.dll 53248 bytes executable
scan completed successfully
hȋdden files: 1
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
Completion time: 2010-01-05 14:18:20
ComboFix-quarantined-files.txt 2010-01-05 20:18
Pre-Run: 59,338,997,760 bytes free
Post-Run: 59,284,090,880 bytes free
- - End Of File - - 21F33F6E7A349B77449BEB974C4C50E7