up to running the combofix.txt
My system have been rebooted but symantec Auto protect is tsill catching the W32.Trats!inf on my system which tells me it is still not clean here is the combofix.txt log:
ComboFix 08-01-10.2 - rmunad 2008-01-10 10:29:40.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1284 [GMT -8:00]
Running from: C:\Documents and Settings\rmunad\Local Settings\Temporary Internet Files\Content.IE5\8PKFOVKJ\ComboFix[1].exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\Temporary
C:\Program Files\Temporary\kernInst.exe
C:\WINDOWS\b122.exe
C:\WINDOWS\mrofinu572.exe
C:\WINDOWS\system32\Cache
C:\WINDOWS\system32\mpqss.ini
C:\WINDOWS\system32\mpqss.ini2
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\taskswitch.exe
C:\WINDOWS\vVX1000.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_NPF
((((((((((((((((((((((((( Files Created from 2007-12-10 to 2008-01-10 )))))))))))))))))))))))))))))))
.
2008-01-10 10:27 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-10 07:00 . 2008-01-10 08:00 <DIR> d-------- C:\Documents and Settings\rmunad\Application Data\skypePM
2008-01-10 07:00 . 2008-01-10 07:00 32 --a------ C:\Documents and Settings\All Users\Application Data\ezsid.dat
2008-01-10 06:59 . 2008-01-10 06:59 <DIR> d-------- C:\Program Files\Common Files\Skype
2008-01-08 20:54 . 2008-01-08 20:54 707,376 --a------ C:\WINDOWS\vVX1000 .exe
2008-01-08 20:54 . 2008-01-08 20:54 45,632 --a------ C:\WINDOWS\system32\taskswitch .exe
2008-01-08 20:29 . 2008-01-08 20:29 <DIR> d-------- C:\Program Files\Trend Micro
2008-01-08 20:19 . 2008-01-08 20:55 <DIR> d-------- C:\Program Files\Dot1XCfg
2008-01-08 20:12 . 2008-01-08 20:21 <DIR> d-------- C:\WINDOWS\system32\ardCo01
2008-01-08 20:12 . 2008-01-08 20:12 <DIR> d-------- C:\Temp\cEeer12
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-10 18:24 --------- d-----w C:\Documents and Settings\rmunad\Application Data\Skype
2008-01-10 14:52 --------- d-----w C:\Program Files\LogMeIn
2008-01-09 19:47 --------- d-----w C:\Program Files\QuickTime
2008-01-09 19:47 --------- d-----w C:\Program Files\Pamela
2008-01-09 19:47 --------- d-----w C:\Program Files\Athan
2008-01-09 16:36 --------- d-----w C:\Program Files\Windows Defender
2008-01-09 16:36 --------- d-----w C:\Program Files\j2 Messenger 4.2
2008-01-09 16:36 --------- d-----w C:\Program Files\DellSupport
2008-01-09 16:36 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-01-09 16:35 --------- d-----w C:\Program Files\MSN Messenger
2008-01-09 04:55 --------- d-----w C:\Program Files\Symantec AntiVirus
2007-12-08 06:44 --------- d-----w C:\Program Files\Microsoft LifeCam
2007-12-06 22:26 --------- d-----w C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-12-04 03:54 --------- d-----w C:\Documents and Settings\rmunad\Application Data\U3
2007-12-03 02:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-11-30 17:59 --------- d-----w C:\Documents and Settings\rmunad\Application Data\.purple
2007-11-27 20:47 --------- d-----w C:\Program Files\FileZilla Server
2007-11-27 20:41 --------- d-----w C:\Documents and Settings\rmunad\Application Data\OpenOffice.org2
2007-11-27 15:16 --------- d-----w C:\Documents and Settings\rmunad\Application Data\Pamela
2007-11-27 02:34 --------- d-----w C:\Documents and Settings\rmunad\Application Data\Apple Computer
2007-11-27 02:30 --------- d-----w C:\Program Files\Apple Software Update
2007-11-27 02:30 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
2007-11-22 04:44 --------- d-----w C:\Program Files\Google
2007-11-12 14:37 --------- d-----w C:\Documents and Settings\rmunad\Application Data\FileZilla
.
<pre> ----a-w 954,368 2008-01-09 16:36:15 C:\Program Files\Athan\Athan .exe ----a-w 344,064 2008-01-09 04:54:18 C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx .exe ----a-w 155,648 2008-01-09 19:44:56 C:\Program Files\Common Files\Ahead\Lib\NeroCheck .exe ----a-w 94,208 2008-01-09 04:54:44 C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor .exe ----a-w 185,632 2008-01-09 04:54:30 C:\Program Files\Common Files\Real\Update_OB\realsched .exe ----a-w 52,896 2008-01-09 19:44:54 C:\Program Files\Common Files\Symantec Shared\ccApp .exe ----a-w 460,784 2008-01-09 19:45:06 C:\Program Files\DellSupport\DSAgnt .exe ----a-w 107,008 2008-01-09 19:44:52 C:\Program Files\j2 Messenger 4.2\J2GDllCmd .exe ----a-w 132,760 2008-01-09 16:36:11 C:\Program Files\Java\jre1.6.0_02\bin\jusched .exe ----a-w 657,168 2008-01-09 19:45:00 C:\Program Files\JiWire\BOT Mapping\JiWireBOT .exe ----a-w 63,048 2008-01-09 19:44:49 C:\Program Files\LogMeIn\x86\LogMeInSystray .exe ----a-w 1,694,208 2008-01-09 16:36:19 C:\Program Files\Messenger\msmsgs .exe ----a-w 5,674,352 2008-01-09 16:13:27 C:\Program Files\MSN Messenger\MsnMsgr .Exe ----a-w 139,320 2008-01-09 16:36:15 C:\Program Files\Network Associates\Common Framework\UpdaterUI .exe ----a-w 5,713,920 2008-01-09 16:36:26 C:\Program Files\Pamela\Pamela .exe ----a-w 286,720 2008-01-09 19:48:26 C:\Program Files\QuickTime\QTTask .exe ----a-w 0 2008-01-09 21:48:27 C:\Program Files\QuickTime\QTTask .exe ----a-w 0 2008-01-09 21:14:36 C:\Program Files\QuickTime\QTTask .exe ----a-w 0 2008-01-09 21:14:34 C:\Program Files\QuickTime\QTTask .exe ----a-w 22,880,040 2008-01-09 16:13:30 C:\Program Files\Skype\Phone\Skype .exe ----a-w 125,168 2008-01-09 04:54:28 C:\Program Files\Symantec AntiVirus\VPTray .exe ----a-w 866,584 2008-01-09 19:44:53 C:\Program Files\Windows Defender\MSASCui .exe ----a-w 0 2008-01-09 21:48:08 C:\Program Files\Yahoo!\Messenger\YahooMessenger .exe ----a-w 0 2008-01-09 21:17:33 C:\Program Files\Yahoo!\Messenger\YahooMessenger .exe ----a-w 444,160 2008-01-09 19:44:52 C:\Program Files\Zone Labs\Integrity Client\iclient .exe ----a-w 707,376 2008-01-09 04:54:34 C:\WINDOWS\vVX1000 .exe ----a-w 45,632 2008-01-09 04:54:14 C:\WINDOWS\system32\taskswitch .exe </pre>
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [ ]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2008-01-09 11:45 1694208]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger .exe" [ ]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2008-01-09 11:48 460784]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask .exe" [ ]
"LogMeIn GUI"="C:\Program Files\LogMeIn\x86\LogMeInSystray.exe" [2008-01-09 11:48 63048]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2008-01-09 11:48 866584]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-01-09 11:48 52896]
"Zone Labs Client"="C:\Program Files\Zone Labs\Integrity Client\iclient.exe" [2008-01-09 11:48 444160]
"j2 4.2"="C:\Program Files\j2 Messenger 4.2\J2GDllCmd.exe" [2008-01-09 11:48 107008]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-09-27 17:17 443968]
C:\Documents and Settings\rmunad\Start Menu\Programs\Startup\
Yahoo! Widget Engine.lnk - C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe [2007-05-04 11:39:42]
YzDock.exe.lnk - C:\Downloads\yzdock\YzDock.exe [2003-06-03 21:38:40]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26]
j2 4.2.lnk - C:\Program Files\j2 Messenger 4.2\J2GTray.exe [2007-08-31 14:24:57]
SnagIt 7.lnk - C:\Program Files\TechSmith\SnagIt 7\SnagIt32.exe [2006-06-26 14:59:21]
VPN Client.lnk - c:\WINDOWS\Installer\{D25122BC-A60E-4663-B602-B01718F12044}\Icon3E5562ED7.ico [2007-04-24 17:10:01]
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2007-04-04 22:40:24]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
LMIinit.dll 2007-11-21 09:44 87352 C:\WINDOWS\system32\LMIinit.dll
R1 RCFOX;SonicWALL IPsec Driver;C:\WINDOWS\system32\Drivers\RCFOX.sys [2004-10-15 10:46]
R2 LMIInfo;LogMeIn Kernel Information Provider;C:\Program Files\LogMeIn\x86\RaInfo.sys [2007-04-17 13:00]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;C:\WINDOWS\system32\drivers\LMIRfsDriver.sys [2007-04-05 10:55]
R2 MSExchangeMGMT;Microsoft Exchange Management;"C:\Program Files\Exchsrvr\bin\exmgmt.exe" [2003-06-23 23:00]
R2 MyDesktopWindows;MyDesktopService;C:\WINDOWS\orclobi\MyDesktop\MyDesktopService.exe [2007-10-19 10:32]
R2 QOSMyDesktop;QOS MyDesktop;C:\WINDOWS\orclobi\MyDesktop\MyDesktopQOS.exe [2006-04-21 11:14]
R2 SMTPSVC;Simple Mail Transfer Protocol (SMTP);C:\WINDOWS\system32\inetsrv\inetinfo.exe [2004-08-04 04:00]
R2 SVNService;SVNService;C:\Program Files\Subversion\bin\svnservice.exe [2006-07-07 08:18]
R3 rcvpn;SonicWALL VPN Adapter;C:\WINDOWS\system32\DRIVERS\rcvpn.sys [2003-08-20 14:01]
R3 VX1000;VX-1000;C:\WINDOWS\system32\DRIVERS\VX1000.sys [2006-10-13 17:04]
S2 MSCamSvc;MSCamSvc;"C:\Program Files\Microsoft LifeCam\MSCamS32.exe" []
S3 ICAM3NT5;Intel® PC Camera CS331;C:\WINDOWS\system32\Drivers\ICAM3D2.SYS [2001-07-18 13:52]
S3 MSSQL$DEV;MSSQL$DEV;C:\PROGRA~1\MI6841~1\MSSQL$~1\binn\sqlservr.exe [2005-05-03 23:04]
S3 npkycryp;npkycryp;C:\Program Files\WIZET\MapleStory\npkycryp.sys []
S3 SQLAgent$DEV;SQLAgent$DEV;C:\Program Files\Microsoft SQL Server\MSSQL$DEV\binn\sqlagent.exe [2005-05-03 20:42]
S3 SQLWriter;SQL Server VSS Writer;"c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" [2007-02-10 05:29]
S3 TAEReaderSvc;TA Email Reader;c:\vs projects\travel authorization\development\current\emailreader\taereadersvc\bin\debug\taereadersvc.exe [2006-09-25 12:17]
S3 vncdrv;vncdrv;C:\WINDOWS\system32\DRIVERS\vncdrv.sys [2004-06-26 12:22]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;"C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe" [2005-09-23 06:01]
.
Contents of the 'Scheduled Tasks' folder
"2007-12-09 02:53:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-01-10 18:41:41 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-10 10:45:43
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\lsass.exe [5.01.2600.2180]
-> C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork1.dll
.
Completion time: 2008-01-10 10:53:13 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-10 18:53:10