Hi MrC,
I have run the conbofix scan and pasted the log here below
ComboFix 07-11-08.1 - BKibaara 2007-11-08 11:09:10.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.467 [GMT 3:00]
Running from: C:\tmp\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
C:\WINDOWS\autorun.inf
C:\WINDOWS\system32\x64
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2007-10-08 to 2007-11-08 )))))))))))))))))))))))))))))))
.
2007-11-08 11:08 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-11-06 12:25 d——– C:\kmdp
2007-11-05 12:43 d——– C:\Maize innovations
2007-11-05 11:08 d——– C:\Co-operatives
2007-11-01 08:47 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2007-10-30 14:55 d——– C:\Documents and Settings\BKibaara\Application Data\Ahead
2007-10-29 16:45 d——– C:\rural struc 07
2007-10-29 11:32 d——– C:\Program Files\Common Files\Nero
2007-10-29 11:32 2,670,592 ——— C:\WINDOWS\UNNeroVision.exe
2007-10-29 11:32 155,648 –a—— C:\WINDOWS\system32\NeroCheck.exe
2007-10-29 11:32 24,064 ——— C:\WINDOWS\system32\msxml3a.dll
2007-10-29 11:31 d——– C:\Program Files\Ahead
2007-10-29 11:31 d——– C:\Documents and Settings\All Users\Application Data\Ahead
2007-10-29 11:31 1,568,768 ——— C:\WINDOWS\system32\ImagX7.dll
2007-10-29 11:31 476,320 ——— C:\WINDOWS\system32\ImagXpr7.dll
2007-10-29 11:31 471,040 ——— C:\WINDOWS\system32\ImagXRA7.dll
2007-10-29 11:31 364,544 ——— C:\WINDOWS\system32\TwnLib4.dll
2007-10-29 11:31 262,144 ——— C:\WINDOWS\system32\ImagXR7.dll
2007-10-29 11:31 106,496 –a—— C:\WINDOWS\system32\TwnLib20.dll
2007-10-29 11:31 38,912 ——— C:\WINDOWS\system32\picn20.dll
2007-10-29 11:26 d——– C:\tmp
2007-10-29 11:26 d——– C:\Program Files\Common Files\Ahead
2007-10-29 10:59 d–h—– C:\WINDOWS\system32\GroupPolicy
2007-10-26 11:07 d——– C:\WWF
2007-10-25 18:21 552 –a—— C:\WINDOWS\system32\d3d8caps.dat
2007-10-25 18:09 d——– C:\Documents and Settings\BKibaara\Application Data\U3
2007-10-22 14:13 d——– C:\Tavneet
2007-10-16 08:52 294,912 -ra—— C:\WINDOWS\system32\hptcpmui.dll
2007-10-16 08:52 192,512 -ra—— C:\WINDOWS\system32\hptcpmon.dll
2007-10-16 08:52 118,784 -ra—— C:\WINDOWS\system32\hptcpmib.dll
2007-10-10 10:53 582,656 ——— C:\WINDOWS\system32\dllcache\rpcrt4.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-08 08:07 ——— d—–w C:\Documents and Settings\BKibaara\Application Data\Skype
2007-11-05 06:33 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2007-11-01 11:58 ——— d—–w C:\Program Files\SPSS
2007-10-25 05:15 ——— d—–w C:\Program Files\Norton AntiVirus
2007-10-25 05:15 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2007-10-25 05:14 805 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2007-10-25 05:14 60,800 —-a-w C:\WINDOWS\system32\S32EVNT1.DLL
2007-10-25 05:14 123,952 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-10-25 05:14 10,740 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2007-10-25 05:14 ——— d—–w C:\Program Files\Symantec
2007-10-16 05:52 ——— d—–w C:\Program Files\Hewlett-Packard
2007-09-24 09:33 ——— d—–w C:\Program Files\Google
2007-09-18 11:44 10,662 —-a-w C:\WINDOWS\system32\drivers\srtspx.cat
2007-09-18 11:44 10,662 —-a-w C:\WINDOWS\system32\drivers\srtspl.cat
2007-09-18 11:44 10,658 —-a-w C:\WINDOWS\system32\drivers\srtsp.cat
2007-09-18 11:44 1,430 —-a-w C:\WINDOWS\system32\drivers\srtspl.inf
2007-09-18 11:44 1,421 —-a-w C:\WINDOWS\system32\drivers\srtspx.inf
2007-09-18 11:44 1,415 —-a-w C:\WINDOWS\system32\drivers\srtsp.inf
2007-09-18 11:43 43,696 —-a-w C:\WINDOWS\system32\drivers\srtspx.sys
2007-09-18 11:43 317,616 —-a-w C:\WINDOWS\system32\drivers\srtspl.sys
2007-09-18 11:43 278,576 —-a-w C:\WINDOWS\system32\drivers\srtsp.sys
2007-09-10 09:33 45,056 —-a-w C:\WINDOWS\NCUNINST.EXE
2007-09-10 09:25 ——— d—–w C:\Program Files\Common Files\SWF Studio
2007-08-21 06:15 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2007-08-21 06:15 683,520 ——w C:\WINDOWS\system32\dllcache\inetcomm.dll
2007-08-20 10:04 824,832 ——w C:\WINDOWS\system32\dllcache\wininet.dll
2007-08-20 10:04 671,232 ——w C:\WINDOWS\system32\dllcache\mstime.dll
2007-08-20 10:04 63,488 ——w C:\WINDOWS\system32\dllcache\icardie.dll
2007-08-20 10:04 6,058,496 ——w C:\WINDOWS\system32\dllcache\ieframe.dll
2007-08-20 10:04 52,224 ——w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-08-20 10:04 477,696 ——w C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-08-20 10:04 459,264 ——w C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-08-20 10:04 44,544 ——w C:\WINDOWS\system32\dllcache\iernonce.dll
2007-08-20 10:04 384,512 ——w C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-08-20 10:04 383,488 ——w C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-08-20 10:04 3,584,512 ——w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-08-20 10:04 27,648 ——w C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-08-20 10:04 267,776 ——w C:\WINDOWS\system32\dllcache\iertutil.dll
2007-08-20 10:04 232,960 ——w C:\WINDOWS\system32\dllcache\webcheck.dll
2007-08-20 10:04 230,400 ——w C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-08-20 10:04 214,528 ——w C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-08-20 10:04 193,024 ——w C:\WINDOWS\system32\dllcache\msrating.dll
2007-08-20 10:04 153,088 ——w C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-08-20 10:04 132,608 ——w C:\WINDOWS\system32\dllcache\extmgr.dll
2007-08-20 10:04 124,928 ——w C:\WINDOWS\system32\dllcache\advpack.dll
2007-08-20 10:04 105,984 ——w C:\WINDOWS\system32\dllcache\url.dll
2007-08-20 10:04 102,400 ——w C:\WINDOWS\system32\dllcache\occache.dll
2007-08-20 10:04 1,152,000 ——w C:\WINDOWS\system32\dllcache\urlmon.dll
2007-08-17 10:21 625,152 ——w C:\WINDOWS\system32\dllcache\iexplore.exe
2007-08-17 10:20 63,488 ——w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-08-17 10:20 13,824 ——w C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-08-17 07:34 161,792 ——w C:\WINDOWS\system32\dllcache\ieakui.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2006-07-21 13:48]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2006-07-21 13:50]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2006-07-21 13:47]
"RTHDCPL"="RTHDCPL.EXE" [2006-07-04 18:26 C:\WINDOWS\RTHDCPL.exe]
"PTHOSTTR"="C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.exe" [2006-06-09 01:02]
"SDMSSplash"="C:\Program Files\HP_SDMS\SDMSSplash\launcher.exe" [2006-03-10 11:53]
"SetRefresh"="C:\Program Files\Compaq\SetRefresh\SetRefresh.exe" [2003-11-20 21:01]
"CognizanceTS"="C:\PROGRA~1\HPQ\IAM\Bin\AsTsVcc.dll" [2003-12-22 22:12]
"Recguard"="C:\WINDOWS\Sminst\Recguard.exe" [2006-05-12 23:50]
"Reminder"="C:\WINDOWS\Creator\Remind_XP.exe" [2006-04-01 01:44]
"Scheduler"="C:\WINDOWS\SMINST\Scheduler.exe" [2006-04-24 21:42]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-10 08:59]
"osCheck"="C:\Program Files\Norton AntiVirus\osCheck.exe" [2007-01-14 10:11]
"StatusClient"="C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe" [2002-12-16 16:51]
"TomcatStartup"="C:\Program Files\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe" [2003-03-31 19:28]
"googletalk"="C:\Program Files\Google\Google Talk\googletalk.exe" [2007-01-02 00:22]
"Bron"="C:\WINDOWS\Font\lsass.exe" []
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 18:30]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-25 11:54]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-02-28 05:00]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 19:24]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2006-07-06 18:53]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-03-27 15:22]
"Fomine WinPopup"="C:\Program Files\Winpopup LAN Messenger\WinPopup.exe" [2007-07-02 15:05]
"Winpopup LAN Messenger"="C:\Program Files\Winpopup LAN Messenger\WinPopup.exe" [2007-07-02 15:05]
"IncrediMail"="C:\Program Files\IncrediMail\bin\IncMail.exe" [2007-06-12 11:28]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IfxWlxEN]
IfxWlxEN.dll 2006-04-07 07:00 434176 C:\WINDOWS\system32\IfxWlxEN.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OneCard]
C:\Program Files\HPQ\IAM\Bin\AsWlnPkg.dll 2006-06-07 22:26 40448 C:\Program Files\HPQ\IAM\Bin\AsWlnPkg.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Notification Packages"= scecli AsWlnPkg
R1 PersonalSecureDrive;PersonalSecureDrive;C:\WINDOWS\system32\drivers\psd.sys
R2 ASChannel;Local Communication Channel;C:\WINDOWS\System32\svchost.exe -k Cognizance
R3 IFXTPM;IFXTPM;C:\WINDOWS\system32\DRIVERS\IFXTPM.SYS
S3 NAL;Nal Service ;\??\C:\WINDOWS\system32\Drivers\iqvw32.sys
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Cognizance ASChannel
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{65fe392a-3042-11dc-80fa-000ffe6b483a}]
\Shell\Auto\command - F:\Cn911.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Cn911.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{69131d34-18b4-11dc-80e8-806d6172696f}]
\Shell\AutoRun\command - C:\
\Shell\explore\Command - Open.exe
\Shell\open\Command - Open.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{69131d35-18b4-11dc-80e8-806d6172696f}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9d983136-667a-11dc-8124-000ffe6b483a}]
\Shell\Auto\command - Cn911.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Cn911.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ab5a6d84-3367-11dc-80fc-000ffe6b483a}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Sys.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e5f3522e-82c1-11dc-8156-000ffe6b483a}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL protector.exe
\Shell\infected\command - G:\protector.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ea6306f5-6809-11dc-8127-000ffe6b483a}]
\Shell\Auto\command - F:\Long.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Long.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ed7a98ea-2abf-11dc-80f3-000ffe6b483a}]
\Shell\Auto\command - RailaO.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RailaO.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f2ffa437-7179-11dc-8139-000ffe6b483a}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fea1304b-815f-11dc-8151-000ffe6b483a}]
\Shell\AutoRun\command - F:\
\Shell\explore\Command - F:\Open.exe
\Shell\open\Command - F:\Open.exe
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2007-09-10 17:00:00 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - BKibaara.job"
- C:\Program Files\Norton AntiVirus\Navw32.exe
.
**************************************************************************
catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-11-08 11:10:55
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-08 11:11:24
.
— E O F —