ComboFix 08-02.05.3 - Michael 2008-02-10 15:11:45.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2347 [GMT -8:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Michael\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE
C:\arbfikac.exe
C:\qrwkjyd.exe
C:\sqmdata09.sqm
C:\sqmdata10.sqm
C:\sqmdata11.sqm
C:\sqmdata12.sqm
C:\sqmdata13.sqm
C:\sqmdata14.sqm
C:\sqmdata15.sqm
C:\sqmdata16.sqm
C:\sqmdata17.sqm
C:\sqmnoopt09.sqm
C:\sqmnoopt10.sqm
C:\sqmnoopt11.sqm
C:\sqmnoopt12.sqm
C:\sqmnoopt13.sqm
C:\sqmnoopt14.sqm
C:\sqmnoopt15.sqm
C:\sqmnoopt16.sqm
C:\sqmnoopt17.sqm
C:\WINDOWS\lelezwro.exe
C:\WINDOWS\mfcliryx.dll
C:\WINDOWS\system32\apiuser32.dll
C:\WINDOWS\system32\jnhjkfrn
C:\WINDOWS\system32\rxjddnvj.exe
C:\WINDOWS\wpydgfwj.exe
C:\WINDOWS\zwFqOxVylq.exe
C:\wpohl.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\jnhjkfrn
C:\arbfikac.exe
C:\qrwkjyd.exe
C:\SDFix
C:\SDFix\apps\assosfix.reg
C:\SDFix\apps\cliptext.exe
C:\SDFix\apps\download.exe
C:\SDFix\apps\dummy.exe
C:\SDFix\apps\dummy.sys
C:\SDFix\apps\Enable_Command_Prompt.reg
C:\SDFix\apps\ERDNT.E_E
C:\SDFix\apps\ERDNTDOS.LOC
C:\SDFix\apps\ERDNTWIN.LOC
C:\SDFix\apps\ERUNT.EXE
C:\SDFix\apps\ERUNT.LOC
C:\SDFix\apps\fix.reg
C:\SDFix\apps\FixBH.reg
C:\SDFix\apps\FIXCU.reg
C:\SDFix\apps\FIXLM.reg
C:\SDFix\apps\FixPath.exe
C:\SDFix\apps\FixRedir.reg
C:\SDFix\apps\FixSchedule.reg
C:\SDFix\apps\FixSubSystems.reg
C:\SDFix\apps\FixWebCheck.reg
C:\SDFix\apps\fixXP.reg
C:\SDFix\apps\FixXPsp2.reg
C:\SDFix\apps\HPFix.reg
C:\SDFix\apps\HPFix2.reg
C:\SDFix\apps\HPFix3.reg
C:\SDFix\apps\HPFix4.reg
C:\SDFix\apps\isadmin.exe
C:\SDFix\apps\leg2.txt
C:\SDFix\apps\legacy.txt
C:\SDFix\apps\legacybk.txt
C:\SDFix\apps\locate.com
C:\SDFix\apps\LS.exe
C:\SDFix\apps\MD5File.exe
C:\SDFix\apps\MyGcpvFix.reg
C:\SDFix\apps\MyGkFix2.reg
C:\SDFix\apps\Process.exe
C:\SDFix\apps\procs.exe
C:\SDFix\apps\psservice.exe
C:\SDFix\apps\RegDACL.exe
C:\SDFix\apps\regedit.exe
C:\SDFix\apps\Rem.txt
C:\SDFix\apps\Rem2.txt
C:\SDFix\apps\Replace\W2K.exe
C:\SDFix\apps\Replace\w2k\beep.sys
C:\SDFix\apps\Replace\w2k\null.sys
C:\SDFix\apps\Replace\XP.exe
C:\SDFix\apps\Replace\xp\beep.sys
C:\SDFix\apps\Replace\xp\null.sys
C:\SDFix\apps\Reset_AppInit_DLLs.reg
C:\SDFix\apps\RestartIt!.exe
C:\SDFix\apps\Restore_SecurityCenter.reg
C:\SDFix\apps\Restore_SharedAccess.reg
C:\SDFix\apps\sc.exe
C:\SDFix\apps\SecPro1.reg
C:\SDFix\apps\SecPro2.reg
C:\SDFix\apps\SecPro3.reg
C:\SDFix\apps\SecPro4.reg
C:\SDFix\apps\SecurityProviders.reg
C:\SDFix\apps\SF.exe
C:\SDFix\apps\shutdown.exe
C:\SDFix\apps\srv2.txt
C:\SDFix\apps\srv2bk.txt
C:\SDFix\apps\svc.txt
C:\SDFix\apps\svcbk.txt
C:\SDFix\apps\swreg.exe
C:\SDFix\apps\swsc.exe
C:\SDFix\apps\unzip.exe
C:\SDFix\apps\WINMSG.EXE
C:\SDFix\apps\winsec.reg
C:\SDFix\apps\zip.exe
C:\SDFix\attrib.exe
C:\SDFix\backups\backupreg.zip
C:\SDFix\backups\backups.zip
C:\SDFix\backups_old1\backupreg.zip
C:\SDFix\backups_old1\backups.zip
C:\SDFix\backups_old2\backupreg.zip
C:\SDFix\backups_old2\backups.zip
C:\SDFix\backups_old3\attrib.exe
C:\SDFix\backups_old3\backupreg.zip
C:\SDFix\backups_old3\backups.zip
C:\SDFix\backups_old3\find.exe
C:\SDFix\backups_old3\findstr.exe
C:\SDFix\backups_old3\regedit.exe
C:\SDFix\bpTEST1.TXT
C:\SDFix\bpTEST3.TXT
C:\SDFix\catchme.exe
C:\SDFix\Catchme.log
C:\SDFix\CheckRuns.txt
C:\SDFix\clean.reg
C:\SDFix\delzip0.txt
C:\SDFix\dest.txt
C:\SDFix\dummy.exe
C:\SDFix\dummy.sys
C:\SDFix\FileList1.txt
C:\SDFix\FileList2.txt
C:\SDFix\find.exe
C:\SDFix\Find.txt
C:\SDFix\Findbhos1.txt
C:\SDFix\FindMurlo.txt
C:\SDFix\Findrun.txt
C:\SDFix\Findrun155.txt
C:\SDFix\Findrun2.txt
C:\SDFix\Findrun3.txt
C:\SDFix\Findrun30.txt
C:\SDFix\Findrun31.txt
C:\SDFix\findstr.exe
C:\SDFix\Findzip.txt
C:\SDFix\HOSTS
C:\SDFix\ndloc.txt
C:\SDFix\Patched2.txt
C:\SDFix\regedit.exe
C:\SDFix\Report.txt
C:\SDFix\Report_old_1.txt
C:\SDFix\Report_old_2.txt
C:\SDFix\Report_old_3.txt
C:\SDFix\RunThis.bat
C:\SDFix\SDFIX_ReadMe_Online.url
C:\SDFix\TEST800.TXT
C:\SDFix\TEST801.TXT
C:\SDFix\TEST802.TXT
C:\SDFix\TEST803.TXT
C:\SDFix\TEST804.TXT
C:\SDFix\TEST805.TXT
C:\SDFix\TEST806.TXT
C:\SDFix\TEST808.TXT
C:\SDFix\TEST811.TXT
C:\SDFix\TEST812.TXT
C:\SDFix\TESTADS1.txt
C:\SDFix\TESTADS2.txt
C:\SDFix\TESTADS3.txt
C:\SDFix\TESTADS4.txt
C:\SDFix\TESTADS5.txt
C:\SDFix\TESTADS6.txt
C:\SDFix\TESTSecPro2.txt
C:\sqmdata09.sqm
C:\sqmdata10.sqm
C:\sqmdata11.sqm
C:\sqmdata12.sqm
C:\sqmdata13.sqm
C:\sqmdata14.sqm
C:\sqmdata15.sqm
C:\sqmdata16.sqm
C:\sqmdata17.sqm
C:\sqmnoopt09.sqm
C:\sqmnoopt10.sqm
C:\sqmnoopt11.sqm
C:\sqmnoopt12.sqm
C:\sqmnoopt13.sqm
C:\sqmnoopt14.sqm
C:\sqmnoopt15.sqm
C:\sqmnoopt16.sqm
C:\sqmnoopt17.sqm
C:\WINDOWS\cblmwrrl
C:\WINDOWS\cblmwrrl\Thumbs.db
C:\WINDOWS\lelezwro.exe
C:\WINDOWS\mfcliryx.dll
C:\WINDOWS\system32\apiuser32.dll
C:\WINDOWS\system32\jnhjkfrn
C:\WINDOWS\system32\rxjddnvj.exe
C:\WINDOWS\wpydgfwj.exe
C:\WINDOWS\zwFqOxVylq.exe
C:\wpohl.exe
.
((((((((((((((((((((((((( Files Created from 2008-01-10 to 2008-02-10 )))))))))))))))))))))))))))))))
.
2008-02-10 06:00 . 2004-08-03 23:56 388,608 –a—— C:\kmd.exe
2008-02-09 18:38 . 2008-02-09 18:38 d——– C:\Deckard
2008-02-08 21:28 . 2008-02-08 21:28 d——– C:\Documents and Settings\Mike's Mom\Application Data\acccore
2008-02-05 16:03 . 2008-02-05 16:03 d——– C:\Documents and Settings\Jason\WINDOWS
2008-02-04 17:07 . 2008-02-04 17:24 d——– C:\Program Files\Wolfenstein - Enemy Territory
2008-02-03 00:08 . 2008-02-04 20:48 d——– C:\vcs5BGEffects
2008-02-03 00:06 . 2008-02-03 00:16 d——– C:\Program Files\AV Vcs 6.0 DIAMOND
2008-02-02 21:01 . 2008-02-02 21:01 dr-h—– C:\Documents and Settings\Mike's Mom\Application Data\SecuROM
2008-02-02 12:10 . 2008-02-02 12:10 dr-h—– C:\Documents and Settings\Guest\Application Data\SecuROM
2008-02-02 00:18 . 2008-02-02 00:18 dr-h—– C:\Documents and Settings\Jason\Application Data\SecuROM
2008-01-31 20:50 . 2008-01-31 20:50 d——– C:\Program Files\RivaTuner v2.06
2008-01-31 15:10 . 2008-01-31 15:10 d——– C:\Program Files\uTorrent
2008-01-31 15:10 . 2008-02-10 15:04 d——– C:\Documents and Settings\Michael\Application Data\uTorrent
2008-01-30 15:12 . 2008-01-30 15:12 d——– C:\Program Files\Common Files\Motive
2008-01-30 15:12 . 2008-01-30 15:12 d——– C:\Program Files\ATT
2008-01-30 15:12 . 2008-01-30 15:12 d——– C:\Documents and Settings\All Users\Application Data\Motive
2008-01-30 14:30 . 2008-01-30 14:30 d——– C:\WINDOWS\ERUNT
2008-01-26 20:47 . 2008-01-26 20:47 d——– C:\Documents and Settings\Jason\.jagex_cache_32
2008-01-26 20:19 . 2008-01-26 20:19 d——– C:\Documents and Settings\Michael\Application Data\EPSON
2008-01-22 22:45 . 2008-01-27 22:05 d——– C:\Program Files\DNA
2008-01-22 22:45 . 2008-01-25 12:47 d——– C:\Documents and Settings\Michael\Application Data\BitTorrent
2008-01-17 16:13 . 2008-01-17 16:47 d——– C:\HLServer
2008-01-17 16:02 . 2008-01-17 16:46 d——– C:\Documents and Settings\Michael\Application Data\GetRightToGo
2008-01-12 13:22 . 2008-01-12 13:22 d——– C:\Documents and Settings\Mike's Mom\Application Data\Disney Interactive Studios
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-10 23:17 ——— d—–w C:\Program Files\Steam
2008-02-10 02:33 6,776 —-a-w C:\Documents and Settings\All Users\Application Data\ypinfo.bin
2008-02-09 03:38 ——— d—–w C:\Documents and Settings\Mike's Mom\Application Data\Yahoo!
2008-02-09 02:26 ——— d—–w C:\Documents and Settings\Michael\Application Data\LimeWire
2008-02-08 04:00 ——— d—–w C:\Program Files\WinTV
2008-02-06 23:46 22,328 —-a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-02-06 23:24 ——— d—–w C:\Program Files\HP
2008-02-06 01:14 ——— d—–w C:\Program Files\AIMTunes
2008-02-01 23:15 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-02-01 23:15 ——— d—–w C:\Program Files\Sierra
2008-01-30 22:51 ——— d—–w C:\Program Files\Real
2008-01-29 21:05 ——— d—–w C:\Documents and Settings\Michael\Application Data\Xfire
2008-01-17 23:58 ——— d—–w C:\Documents and Settings\Michael\Application Data\IGN_DLM
2008-01-10 01:30 ——— d—–w C:\Documents and Settings\Jason\Application Data\Disney Interactive Studios
2008-01-07 05:34 ——— d—–w C:\Documents and Settings\Michael\Application Data\Disney Interactive Studios
2008-01-07 01:59 ——— d—–w C:\Documents and Settings\Jason\Application Data\Ahead
2007-12-31 15:21 ——— d—–w C:\Documents and Settings\Mike's Mom\Application Data\DivX
2007-12-30 06:54 ——— d—–w C:\Program Files\Audacity
2007-12-26 06:55 ——— d—–w C:\Program Files\ACE-HIGH MP3 WAV WMA OGG Converter
2007-12-26 06:52 ——— d—–w C:\Program Files\MP3 Converter Simple
2007-12-23 16:24 ——— d—–w C:\Program Files\QuickTime
2007-12-22 23:37 ——— d—–w C:\Program Files\iTunes
2007-12-22 23:37 ——— d—–w C:\Program Files\iPod
2007-12-22 23:11 ——— d—–w C:\Program Files\Common Files\Download Manager
2007-12-22 02:35 ——— d—–w C:\Program Files\AV Vcs 5.0 DIAMOND
2007-12-20 01:56 ——— d—–w C:\Program Files\Illustrate
2007-12-17 01:02 ——— d—–w C:\Documents and Settings\Jason\Application Data\DivX
2007-12-14 22:17 ——— d—–w C:\Program Files\DivX
2007-12-12 01:12 ——— d—–w C:\Documents and Settings\valuable customer\Application Data\HP
2007-12-10 07:00 ——— d—–w C:\Program Files\OOBOX
2007-12-03 06:52 47,360 —-a-w C:\Documents and Settings\Michael\Application Data\pcouffin.sys
2007-12-03 06:43 356,352 —-a-w C:\WINDOWS\eSellerateEngine.dll
2007-10-11 03:05 22,328 —-a-w C:\Documents and Settings\Michael\Application Data\PnkBstrK.sys
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—- Directory of C:\Documents and Settings\Jason\WINDOWS —-
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-12-23 17:05 143360]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56 15360]
"Steam"="c:\program files\steam\steam.exe" [2007-11-29 17:33 1266936]
"igndlm.exe"="C:\Program Files\Download Manager\DLM.exe" [2007-03-05 13:57 1103480]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2007-09-29 12:22 50528]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 08:24 1694208]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-12-11 10:56 286720]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2007-04-12 01:33 16132608 C:\WINDOWS\RTHDCPL.exe]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-06-28 23:43 8466432]
"nwiz"="nwiz.exe" [2007-06-28 23:43 1626112 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-06-28 23:43 81920]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 05:00 79224]
"itype"="C:\Program Files\Microsoft IntelliType Pro\itype.exe" [2006-11-21 17:08 813912]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2006-11-21 17:09 842584]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 14:40 155648]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [ ]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 08:30 81920]
"PRISMSVR.EXE"="C:\WINDOWS\system32\PRISMSVR.exe" [ ]
"YBrowser"="C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe" [2006-07-21 15:19 129536]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11 132496]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-03 23:56 110592 C:\WINDOWS\system32\bthprops.cpl]
"YOP"="C:\PROGRA~1\Yahoo!\YOP\yop.exe" [2007-06-26 12:48 509224]
"YPC"="C:\PROGRA~1\Yahoo!\PARENT~1\ypc.exe" [2005-02-11 17:14 352256]
"LifeCam"="C:\Program Files\Microsoft LifeCam\LifeExp.exe" [2006-09-08 15:47 277296]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 18:51 39792]
"Zune Launcher"="c:\Program Files\Zune\ZuneLauncher.exe" [2007-11-06 19:09 166304]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-12-06 18:28 185632]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-12-11 10:56 286720]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-12-11 12:10 267048]
C:\Documents and Settings\valuable customer\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 19:24:54 98632]
C:\Documents and Settings\Guest\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 19:24:54 98632]
C:\Documents and Settings\Mike's Mom\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 19:24:54 98632]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
AutoStart IR.lnk - C:\Program Files\WinTV\Ir.exe [2007-10-10 16:33:07 106551]
Windows Desktop Search.lnk - C:\Program Files\Windows Desktop Search\WindowsSearch.exe [2006-03-26 21:44:08 257752]
Wireless Configuration Utility HW.14.lnk - C:\Program Files\TRENDnet\TEW-424UB\WlanCU.exe [2007-06-07 17:05:22 634880]
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\
0]
Source= file:///C:\WINDOWS\privacy_danger\index.htm
FriendlyName= Privacy Protection
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2006-03-13 12:11 233472]
R2 MSCamSvc;MSCamSvc;"C:\Program Files\Microsoft LifeCam\MSCamS32.exe" [2006-09-08 15:47]
R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 13:38]
R2 zumbus;Zune Bus Enumerator Driver;C:\WINDOWS\system32\DRIVERS\zumbus.sys [2007-11-06 18:58]
R2 ZuneBusEnum;Zune Bus Enumerator;c:\WINDOWS\system32\ZuneBusEnum.exe [2007-11-06 19:09]
R3 hcw18bda;Hauppauge WinTV 418 Driver;C:\WINDOWS\system32\drivers\hcw18bda.sys [2007-05-10 10:43]
R3 MSHUSBVideo;NX6000 Filter Driver;C:\WINDOWS\system32\Drivers\nx6000.sys [2006-08-23 16:33]
S1 jnhjkfrn;jnhjkfrn;C:\WINDOWS\system32\jnhjkfrn []
S2 RCService;RCService;"C:\Program Files\gigabyte\RCService\RCService.exe" []
S3 3xHybrid;3xHybrid service;C:\WINDOWS\system32\DRIVERS\3xHybrid.sys []
S3 gdrv;gdrv;C:\WINDOWS\gdrv.sys [2007-09-25 17:18]
S3 HauppaugeTVServer;HauppaugeTVServer;C:\PROGRA~1\WinTV\HCWTVS~1.EXE [2007-02-20 14:11]
S3 RTL8187B;TRENDnet TEW-424UB 54M USB Dongle;C:\WINDOWS\system32\DRIVERS\RTL8187B.sys [2007-05-04 04:40]
S3 SjyPkt;SjyPkt;C:\WINDOWS\System32\Drivers\SjyPkt.sys [2002-10-01 17:57]
S3 ZuneWlanCfgSvc;Zune Wireless Configuration Service;c:\WINDOWS\system32\ZuneWlanCfgSvc.exe [2007-11-06 19:10]
.
Contents of the 'Scheduled Tasks' folder
"2008-02-07 05:00:00 C:\WINDOWS\Tasks\!Bionic_Woman_1114_2100.job"
- C:\PROGRA~1\WinTV\Scheduler\StayAwake.exe
"2008-02-08 04:00:00 C:\WINDOWS\Tasks\!smallville.job"
- C:\PROGRA~1\WinTV\Scheduler\StayAwake.exe
"2008-02-07 06:01:13 C:\WINDOWS\Tasks\Bionic_Woman_1114_2100.job"
- C:\PROGRA~1\WinTV\BGRecorder.exeC -c3 -ntod -startr:Bionic_Woman_1114_2100###.mpg -qdef -limit:3660
"2008-02-10 22:38:00 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-02-08 04:05:14 C:\WINDOWS\Tasks\smallville.job"
- C:\PROGRA~1\WinTV\BGRecorder.exe8 -c12 -ntod -startr:smallville###.mpg -qdef -limit:3600
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-02-10 15:18:07
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
c:\Program Files\Zune\ZuneNss.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\WINDOWS\system32\YPCSER~1.EXE
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\PROGRA~1\Yahoo!\YOP\SSDK02.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2008-02-10 15:20:52 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-10 23:20:49
ComboFix2.txt 2008-02-10 14:02:32
ComboFix3.txt 2008-02-07 03:44:33
.
2008-01-09 07:46:14 — E O F —