sorry , i thought i posted the combofix log. here it is
yes, i would like for you to suggest another anti virus program,
j-a
ComboFix 08-12-28.04 - HP_Owner 2008-12-29 18:37:36.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.503.108 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\HP_Owner\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning enabled* (Outdated)
AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Outdated)
* Created a new restore point
FILE ::
c:\documents and settings\HP_Owner\Application Data\Microsoft\Windows\rjdyn.exe
c:\windows\system32\cccIknmp.ini
c:\windows\system32\cccIknmp.ini2
c:\windows\system32\dcarboet.dll
c:\windows\system32\digeste.dll
c:\windows\system32\hgGvtUKA.dll
c:\windows\system32\mlJYoppQ.dll
c:\windows\system32\npqgatst.dll
c:\windows\system32\pmnkIccc.dll
c:\windows\system32\ssqNDvwW.dll
c:\windows\system32\tstagqpn.ini
c:\windows\system32\vmdtms.dll
c:\windows\tasks\uymozobr.job
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\HP_Owner\Application Data\gadcom
c:\documents and settings\HP_Owner\Application Data\gadcom\gadcom.exe
c:\documents and settings\HP_Owner\Application Data\SpeedRunner
c:\documents and settings\HP_Owner\Application Data\SpeedRunner\config.cfg
c:\documents and settings\HP_Owner\Local Settings\Temporary Internet Files\fbk.sts
c:\windows\system32\cccIknmp.ini
c:\windows\system32\cccIknmp.ini2
c:\windows\system32\dcarboet.dll
c:\windows\system32\digeste.dll
c:\windows\system32\dqwejy.dll
c:\windows\system32\gscruhjj.dll
c:\windows\system32\hgGvtUKA.dll
c:\windows\system32\huamoclo.ini
c:\windows\system32\mlJYoppQ.dll
c:\windows\system32\olcomauh.dll
c:\windows\system32\pmnkIccc.dll
c:\windows\system32\ssqNDvwW.dll
c:\windows\system32\tstagqpn.ini
c:\windows\system32\vmdtms.dll
c:\windows\tasks\uymozobr.job
c:\windows\wiaserviv.log
—– BITS: Possible infected sites —–
hxxp://childhe.com
.
((((((((((((((((((((((((( Files Created from 2008-11-28 to 2008-12-29 )))))))))))))))))))))))))))))))
.
2008-12-22 08:11 . 2008-12-22 08:11 d——– c:\program files\SUPERAntiSpyware
2008-12-22 08:11 . 2008-12-22 08:11 d——– c:\documents and settings\HP_Owner\Application Data\SUPERAntiSpyware.com
2008-12-22 08:11 . 2008-12-22 08:11 d——– c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2008-12-21 13:42 . 2008-12-21 13:42 d——– C:\_OTMoveIt
2008-12-20 11:18 . 2008-12-27 20:10 d——– C:\rsit
2008-12-20 11:18 . 2008-12-27 20:04 d——– c:\program files\trend micro
2008-12-18 08:37 . 2008-12-18 08:37 d——– c:\program files\Malwarebytes' Anti-Malware
2008-12-18 08:37 . 2008-12-18 08:37 d——– c:\documents and settings\HP_Owner\Application Data\Malwarebytes
2008-12-18 08:37 . 2008-12-18 08:37 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-18 08:37 . 2008-12-03 19:52 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-18 08:37 . 2008-12-03 19:52 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2008-12-16 19:35 . 2008-12-16 19:58 d——– c:\documents and settings\HP_Owner\DoctorWeb
2008-12-11 10:13 . 2008-12-11 10:13 d——– c:\program files\Microsoft Silverlight
2008-12-10 20:39 . 2008-12-29 18:16 d–h—– C:\$AVG8.VAULT$
2008-12-10 20:28 . 2008-12-10 20:28 97,928 –a—— c:\windows\system32\drivers\avgldx86.sys
2008-12-10 20:28 . 2008-12-10 20:28 76,040 –a—— c:\windows\system32\drivers\avgtdix.sys
2008-12-10 20:28 . 2008-12-10 20:28 10,520 –a—— c:\windows\system32\avgrsstx.dll
2008-12-10 19:31 . 2008-12-11 09:32 d-a—— c:\documents and settings\All Users\Application Data\TEMP
2008-12-10 19:30 . 2008-12-11 09:29 d——– c:\program files\SpywareBlaster
2008-12-10 12:49 . 2008-12-10 12:49 d——– c:\documents and settings\HP_Owner\Application Data\Webroot
2008-12-10 11:57 . 2008-12-10 20:28 d——– c:\windows\system32\drivers\Avg
2008-12-10 11:57 . 2008-12-10 11:57 d——– c:\program files\AVG
2008-12-10 11:57 . 2008-12-10 20:30 d——– c:\documents and settings\All Users\Application Data\avg8
2008-12-10 11:19 . 2008-12-10 11:19 d——– c:\program files\Webroot
2008-12-06 15:13 . 2008-12-06 15:13 d——– c:\documents and settings\HP_Owner\Application Data\LaCie
2008-12-06 15:02 . 2008-12-06 15:02 d——– c:\program files\LaCie
2008-12-05 21:13 . 2008-12-05 21:13 d——– c:\program files\Common Files\Scanner
2008-12-05 21:13 . 2008-12-05 22:04 d——– c:\program files\CA Yahoo! Anti-Spy
2008-12-05 19:00 . 2008-12-05 19:00 d——– c:\documents and settings\All Users\Application Data\Yahoo!
2008-12-05 19:00 . 2008-12-05 19:00 262,144 –a—— C:\ntuser.dat
2008-12-05 18:59 . 2008-12-05 19:00 d——– c:\documents and settings\HP_Owner\Application Data\Yahoo!
2008-12-05 18:59 . 2008-12-05 18:59 d——– c:\documents and settings\All Users\Application Data\Yahoo! Companion
2008-12-04 22:41 . 2005-10-18 20:36 d——– c:\documents and settings\Administrator\WINDOWS
2008-12-04 22:41 . 2008-12-04 22:41 d——– c:\documents and settings\Administrator
2008-12-03 22:26 . 2008-12-03 23:04 d——– c:\windows\SxsCaPendDel
2008-12-02 22:01 . 2008-12-02 22:04 d——– c:\program files\Windows Live Safety Center
2008-12-02 11:17 . 2008-12-02 11:20 d——– c:\documents and settings\All Users\Application Data\Lavasoft
2008-12-01 21:12 . 2008-12-15 13:49 d——– c:\documents and settings\HP_Owner\Application Data\Twain
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-29 23:58 ——— d—–w c:\program files\Symantec AntiVirus
2008-12-22 13:09 ——— d—–w c:\program files\Common Files\Wise Installation Wizard
2008-12-21 18:37 ——— d—–w c:\program files\Java
2008-12-21 15:31 ——— d—–w c:\program files\Symantec
2008-12-21 15:22 ——— d—–w c:\program files\AIM
2008-12-21 15:22 ——— d—–w c:\documents and settings\HP_Owner\Application Data\Aim
2008-12-06 00:00 ——— d—–w c:\program files\Yahoo!
2008-12-04 03:25 ——— d—–w c:\program files\OpenOffice.org 3
2008-12-02 16:18 ——— d—–w c:\program files\Lavasoft
2008-12-02 16:18 ——— d—–w c:\documents and settings\HP_Owner\Application Data\Lavasoft
2008-12-01 23:16 ——— d—–w c:\program files\IntelliMover Data Transfer Demo
2008-12-01 23:14 ——— d—–w c:\program files\Bonjour
2008-12-01 21:06 ——— d–h–w c:\program files\InstallShield Installation Information
2008-11-30 22:21 ——— d–h–w c:\documents and settings\HP_Owner\Application Data\Move Networks
2008-11-26 21:32 ——— d—–w c:\program files\AIM6
2008-11-26 20:43 ——— d—–w c:\program files\Common Files\Software Update Utility
2008-11-26 20:43 ——— d—–w c:\documents and settings\All Users\Application Data\acccore
2008-11-26 20:42 ——— d—–w c:\documents and settings\All Users\Application Data\AOL Downloads
2008-11-22 17:03 ——— d—–w c:\program files\Common Files\Adobe
2008-11-22 15:38 ——— d—–w c:\documents and settings\HP_Owner\Application Data\OpenOffice.org
2008-11-12 11:52 ——— d—–w c:\program files\Apple Software Update
2008-11-11 15:01 ——— d—–w c:\program files\iTunes
2008-11-11 15:01 ——— d—–w c:\program files\iPod
2008-11-11 15:01 ——— d—–w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-11-11 14:59 ——— d—–w c:\program files\QuickTime
2008-11-11 14:58 ——— d—–w c:\program files\Common Files\Apple
2008-11-07 23:02 ——— d—–w c:\program files\DivX
2005-10-19 03:14 158 —-a-w c:\documents and settings\HP_Owner\Application Data\wklnhst.dat
2008-12-22 13:05 67,688 —-a-w c:\program files\mozilla firefox\components\jar50.dll
2008-12-22 13:05 54,368 —-a-w c:\program files\mozilla firefox\components\jsd3250.dll
2008-12-22 13:05 34,944 —-a-w c:\program files\mozilla firefox\components\myspell.dll
2008-12-22 13:05 46,712 —-a-w c:\program files\mozilla firefox\components\spellchk.dll
2008-12-22 13:05 172,136 —-a-w c:\program files\mozilla firefox\components\xpinstal.dll
.
((((((((((((((((((((((((((((( snapshot@2008-12-15_14.03.49.73 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-10-22 09:47:25 62,976 —-a-w c:\windows\$hf_mig$\KB955839\SP2QFE\tzchange.exe
+ 2008-10-23 10:06:59 62,976 —-a-w c:\windows\$hf_mig$\KB955839\SP3GDR\tzchange.exe
+ 2008-10-23 10:17:49 62,976 —-a-w c:\windows\$hf_mig$\KB955839\SP3QFE\tzchange.exe
+ 2007-11-30 12:39:22 17,272 —-a-w c:\windows\$hf_mig$\KB955839\spmsg.dll
+ 2007-11-30 12:39:22 231,288 —-a-w c:\windows\$hf_mig$\KB955839\spuninst.exe
+ 2007-11-30 12:39:22 26,488 —-a-w c:\windows\$hf_mig$\KB955839\update\spcustom.dll
+ 2007-11-30 12:39:22 755,576 —-a-w c:\windows\$hf_mig$\KB955839\update\update.exe
+ 2007-11-30 12:39:22 382,840 —-a-w c:\windows\$hf_mig$\KB955839\update\updspapi.dll
+ 2008-10-23 12:51:04 284,160 —-a-w c:\windows\$hf_mig$\KB956802\SP2QFE\gdi32.dll
+ 2008-10-23 12:36:14 286,720 —-a-w c:\windows\$hf_mig$\KB956802\SP3GDR\gdi32.dll
+ 2008-10-23 12:43:42 286,720 —-a-w c:\windows\$hf_mig$\KB956802\SP3QFE\gdi32.dll
+ 2008-07-08 13:02:01 17,272 —-a-w c:\windows\$hf_mig$\KB956802\spmsg.dll
+ 2008-07-08 13:02:02 231,288 —-a-w c:\windows\$hf_mig$\KB956802\spuninst.exe
+ 2008-07-08 13:02:01 26,488 —-a-w c:\windows\$hf_mig$\KB956802\update\spcustom.dll
+ 2008-07-09 07:38:29 755,576 —-a-w c:\windows\$hf_mig$\KB956802\update\update.exe
+ 2008-07-09 07:38:37 382,840 —-a-w c:\windows\$hf_mig$\KB956802\update\updspapi.dll
+ 2008-08-26 07:24:28 124,928 -c—-w c:\windows\ie7updates\KB958215-IE7\advpack.dll
+ 2008-08-26 07:24:28 347,136 -c—-w c:\windows\ie7updates\KB958215-IE7\dxtmsft.dll
+ 2008-08-26 07:24:28 214,528 -c—-w c:\windows\ie7updates\KB958215-IE7\dxtrans.dll
+ 2008-08-26 07:24:28 133,120 -c—-w c:\windows\ie7updates\KB958215-IE7\extmgr.dll
+ 2008-08-26 07:24:28 63,488 -c—-w c:\windows\ie7updates\KB958215-IE7\icardie.dll
+ 2008-08-25 08:37:59 70,656 -c—-w c:\windows\ie7updates\KB958215-IE7\ie4uinit.exe
+ 2008-08-26 07:24:28 153,088 -c—-w c:\windows\ie7updates\KB958215-IE7\ieakeng.dll
+ 2008-08-26 07:24:28 230,400 -c—-w c:\windows\ie7updates\KB958215-IE7\ieaksie.dll
+ 2008-08-23 05:54:51 161,792 -c—-w c:\windows\ie7updates\KB958215-IE7\ieakui.dll
+ 2008-08-26 07:24:28 383,488 -c—-w c:\windows\ie7updates\KB958215-IE7\ieapfltr.dll
+ 2008-08-26 07:24:29 384,512 -c—-w c:\windows\ie7updates\KB958215-IE7\iedkcs32.dll
+ 2008-10-03 17:41:15 6,066,176 -c—-w c:\windows\ie7updates\KB958215-IE7\ieframe.dll
+ 2008-08-26 07:24:29 44,544 -c—-w c:\windows\ie7updates\KB958215-IE7\iernonce.dll
+ 2008-08-26 07:24:29 267,776 -c—-w c:\windows\ie7updates\KB958215-IE7\iertutil.dll
+ 2008-08-25 08:38:00 13,824 -c—-w c:\windows\ie7updates\KB958215-IE7\ieudinit.exe
+ 2008-08-23 05:56:15 635,848 -c—-w c:\windows\ie7updates\KB958215-IE7\iexplore.exe
+ 2008-08-26 07:24:30 27,648 -c—-w c:\windows\ie7updates\KB958215-IE7\jsproxy.dll
+ 2008-08-26 07:24:30 459,264 -c—-w c:\windows\ie7updates\KB958215-IE7\msfeeds.dll
+ 2008-08-26 07:24:30 52,224 -c—-w c:\windows\ie7updates\KB958215-IE7\msfeedsbs.dll
+ 2008-08-27 08:24:32 3,593,216 -c—-w c:\windows\ie7updates\KB958215-IE7\mshtml.dll
+ 2008-08-26 07:24:30 477,696 -c—-w c:\windows\ie7updates\KB958215-IE7\mshtmled.dll
+ 2008-08-26 07:24:30 193,024 -c—-w c:\windows\ie7updates\KB958215-IE7\msrating.dll
+ 2008-08-26 07:24:30 671,232 -c—-w c:\windows\ie7updates\KB958215-IE7\mstime.dll
+ 2008-08-26 07:24:30 102,912 -c—-w c:\windows\ie7updates\KB958215-IE7\occache.dll
+ 2008-08-26 07:24:30 44,544 -c—-w c:\windows\ie7updates\KB958215-IE7\pngfilt.dll
+ 2007-03-06 01:22:39 213,216 -c—-w c:\windows\ie7updates\KB958215-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c—-w c:\windows\ie7updates\KB958215-IE7\spuninst\updspapi.dll
+ 2008-08-26 07:24:30 105,984 -c—-w c:\windows\ie7updates\KB958215-IE7\url.dll
+ 2008-08-26 07:24:31 1,159,680 -c—-w c:\windows\ie7updates\KB958215-IE7\urlmon.dll
+ 2008-08-26 07:24:31 233,472 -c—-w c:\windows\ie7updates\KB958215-IE7\webcheck.dll
+ 2008-08-26 07:24:31 826,368 -c—-w c:\windows\ie7updates\KB958215-IE7\wininet.dll
+ 2008-10-17 07:08:40 3,593,216 -c—-w c:\windows\ie7updates\KB960714-IE7\mshtml.dll
+ 2007-03-06 01:22:39 213,216 -c—-w c:\windows\ie7updates\KB960714-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:23:47 371,424 -c—-w c:\windows\ie7updates\KB960714-IE7\spuninst\updspapi.dll
+ 2008-12-22 13:11:31 18,944 —-a-r c:\windows\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF13.exe
+ 2008-12-22 13:11:31 65,024 —-a-r c:\windows\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF15.exe
- 2008-08-26 07:24:28 124,928 —-a-w c:\windows\system32\advpack.dll
+ 2008-10-16 20:38:34 124,928 —-a-w c:\windows\system32\advpack.dll
- 2008-12-15 18:36:46 16,384 —-a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2008-12-28 18:00:55 32,768 —-a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2008-12-15 18:36:46 32,768 —-a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-12-28 18:00:44 32,768 —-a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-12-27 17:01:38 78,924 —-a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat
+ 2008-12-28 18:00:44 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2008-08-26 07:24:28 124,928 ——w c:\windows\system32\dllcache\advpack.dll
+ 2008-10-16 20:38:34 124,928 —-a-w c:\windows\system32\dllcache\advpack.dll
- 2008-08-26 07:24:28 347,136 ——w c:\windows\system32\dllcache\dxtmsft.dll
+ 2008-10-16 20:38:34 347,136 —-a-w c:\windows\system32\dllcache\dxtmsft.dll
- 2008-08-26 07:24:28 214,528 ——w c:\windows\system32\dllcache\dxtrans.dll
+ 2008-10-16 20:38:34 214,528 —-a-w c:\windows\system32\dllcache\dxtrans.dll
- 2008-08-26 07:24:28 133,120 ——w c:\windows\system32\dllcache\extmgr.dll
+ 2008-10-16 20:38:35 133,120 —-a-w c:\windows\system32\dllcache\extmgr.dll
- 2008-02-20 06:51:05 282,624 —-a-w c:\windows\system32\dllcache\gdi32.dll
+ 2008-10-23 13:01:36 283,648 —-a-w c:\windows\system32\dllcache\gdi32.dll
- 2008-08-26 07:24:28 63,488 ——w c:\windows\system32\dllcache\icardie.dll
+ 2008-10-16 20:38:35 63,488 —-a-w c:\windows\system32\dllcache\icardie.dll
- 2008-08-25 08:37:59 70,656 ——w c:\windows\system32\dllcache\ie4uinit.exe
+ 2008-10-16 13:11:09 70,656 —-a-w c:\windows\system32\dllcache\ie4uinit.exe
- 2008-08-26 07:24:28 153,088 ——w c:\windows\system32\dllcache\ieakeng.dll
+ 2008-10-16 20:38:35 153,088 —-a-w c:\windows\system32\dllcache\ieakeng.dll
- 2008-08-26 07:24:28 230,400 ——w c:\windows\system32\dllcache\ieaksie.dll
+ 2008-10-16 20:38:35 230,400 —-a-w c:\windows\system32\dllcache\ieaksie.dll
- 2008-08-23 05:54:51 161,792 ——w c:\windows\system32\dllcache\ieakui.dll
+ 2008-10-15 07:04:53 161,792 —-a-w c:\windows\system32\dllcache\ieakui.dll
- 2008-08-26 07:24:28 383,488 ——w c:\windows\system32\dllcache\ieapfltr.dll
+ 2008-10-16 20:38:35 383,488 —-a-w c:\windows\system32\dllcache\ieapfltr.dll
- 2008-08-26 07:24:29 384,512 ——w c:\windows\system32\dllcache\iedkcs32.dll
+ 2008-10-16 20:38:35 384,512 —-a-w c:\windows\system32\dllcache\iedkcs32.dll
- 2008-10-03 17:41:15 6,066,176 ——w c:\windows\system32\dllcache\ieframe.dll
+ 2008-10-16 20:38:37 6,066,176 —-a-w c:\windows\system32\dllcache\ieframe.dll
- 2008-08-26 07:24:29 44,544 ——w c:\windows\system32\dllcache\iernonce.dll
+ 2008-10-16 20:38:37 44,544 —-a-w c:\windows\system32\dllcache\iernonce.dll
- 2008-08-26 07:24:29 267,776 ——w c:\windows\system32\dllcache\iertutil.dll
+ 2008-10-16 20:38:37 267,776 —-a-w c:\windows\system32\dllcache\iertutil.dll
- 2008-08-25 08:38:00 13,824 ——w c:\windows\system32\dllcache\ieudinit.exe
+ 2008-10-16 13:11:09 13,824 —-a-w c:\windows\system32\dllcache\ieudinit.exe
- 2008-08-23 05:56:15 635,848 ——w c:\windows\system32\dllcache\iexplore.exe
+ 2008-10-15 07:06:26 633,632 —-a-w c:\windows\system32\dllcache\iexplore.exe
- 2008-08-26 07:24:30 27,648 ——w c:\windows\system32\dllcache\jsproxy.dll
+ 2008-10-16 20:38:37 27,648 —-a-w c:\windows\system32\dllcache\jsproxy.dll
- 2006-10-19 01:03:58 100,864 —-a-w c:\windows\system32\dllcache\logagent.exe
+ 2008-06-18 06:09:22 100,864 —-a-w c:\windows\system32\dllcache\logagent.exe
- 2008-08-26 07:24:30 459,264 ——w c:\windows\system32\dllcache\msfeeds.dll
+ 2008-10-16 20:38:37 459,264 —-a-w c:\windows\system32\dllcache\msfeeds.dll
- 2008-08-26 07:24:30 52,224 ——w c:\windows\system32\dllcache\msfeedsbs.dll
+ 2008-10-16 20:38:37 52,224 —-a-w c:\windows\system32\dllcache\msfeedsbs.dll
- 2008-08-27 08:24:32 3,593,216 ——w c:\windows\system32\dllcache\mshtml.dll
+ 2008-12-13 06:40:02 3,593,216 —-a-w c:\windows\system32\dllcache\mshtml.dll
- 2008-08-26 07:24:30 477,696 ——w c:\windows\system32\dllcache\mshtmled.dll
+ 2008-10-16 20:38:38 477,696 —-a-w c:\windows\system32\dllcache\mshtmled.dll
- 2008-08-26 07:24:30 193,024 ——w c:\windows\system32\dllcache\msrating.dll
+ 2008-10-16 20:38:38 193,024 —-a-w c:\windows\system32\dllcache\msrating.dll
- 2008-08-26 07:24:30 671,232 ——w c:\windows\system32\dllcache\mstime.dll
+ 2008-10-16 20:38:39 671,232 —-a-w c:\windows\system32\dllcache\mstime.dll
- 2008-08-26 07:24:30 102,912 ——w c:\windows\system32\dllcache\occache.dll
+ 2008-10-16 20:38:39 102,912 —-a-w c:\windows\system32\dllcache\occache.dll
- 2008-08-26 07:24:30 44,544 ——w c:\windows\system32\dllcache\pngfilt.dll
+ 2008-10-16 20:38:39 44,544 —-a-w c:\windows\system32\dllcache\pngfilt.dll
- 2006-08-21 14:52:08 246,814 —-a-w c:\windows\system32\dllcache\strmdll.dll
+ 2008-10-03 10:15:47 247,326 —-a-w c:\windows\system32\dllcache\strmdll.dll
- 2008-08-26 07:24:30 105,984 ——w c:\windows\system32\dllcache\url.dll
+ 2008-10-16 20:38:39 105,984 —-a-w c:\windows\system32\dllcache\url.dll
- 2008-08-26 07:24:31 1,159,680 ——w c:\windows\system32\dllcache\urlmon.dll
+ 2008-10-16 20:38:39 1,160,192 —-a-w c:\windows\system32\dllcache\urlmon.dll
- 2008-08-26 07:24:31 233,472 ——w c:\windows\system32\dllcache\webcheck.dll
+ 2008-10-16 20:38:39 233,472 —-a-w c:\windows\system32\dllcache\webcheck.dll
- 2008-08-26 07:24:31 826,368 ——w c:\windows\system32\dllcache\wininet.dll
+ 2008-10-16 20:38:40 826,368 —-a-w c:\windows\system32\dllcache\wininet.dll
- 2006-10-19 02:47:20 937,984 —-a-w c:\windows\system32\dllcache\WMNetMgr.dll
+ 2008-06-18 10:03:08 938,496 —-a-w c:\windows\system32\dllcache\WMNetmgr.dll
- 2006-10-19 02:47:22 2,450,944 —-a-w c:\windows\system32\dllcache\wmvcore.dll
+ 2008-06-18 10:03:14 2,458,112 —-a-w c:\windows\system32\dllcache\WMVCore.dll
- 2008-08-26 07:24:28 347,136 ——w c:\windows\system32\dxtmsft.dll
+ 2008-10-16 20:38:34 347,136 —-a-w c:\windows\system32\dxtmsft.dll
- 2008-08-26 07:24:28 214,528 ——w c:\windows\system32\dxtrans.dll
+ 2008-10-16 20:38:34 214,528 —-a-w c:\windows\system32\dxtrans.dll
- 2008-08-26 07:24:28 133,120 ——w c:\windows\system32\extmgr.dll
+ 2008-10-16 20:38:35 133,120 —-a-w c:\windows\system32\extmgr.dll
- 2008-11-23 15:17:15 329,096 —-a-w c:\windows\system32\FNTCACHE.DAT
+ 2008-12-22 12:59:26 329,096 —-a-w c:\windows\system32\FNTCACHE.DAT
- 2008-02-20 06:51:05 282,624 —-a-w c:\windows\system32\gdi32.dll
+ 2008-10-23 13:01:36 283,648 —-a-w c:\windows\system32\gdi32.dll
- 2008-08-26 07:24:28 63,488 —-a-w c:\windows\system32\icardie.dll
+ 2008-10-16 20:38:35 63,488 —-a-w c:\windows\system32\icardie.dll
- 2008-08-25 08:37:59 70,656 ——w c:\windows\system32\ie4uinit.exe
+ 2008-10-16 13:11:09 70,656 —-a-w c:\windows\system32\ie4uinit.exe
- 2008-08-26 07:24:28 153,088 ——w c:\windows\system32\ieakeng.dll
+ 2008-10-16 20:38:35 153,088 —-a-w c:\windows\system32\ieakeng.dll
- 2008-08-26 07:24:28 230,400 ——w c:\windows\system32\ieaksie.dll
+ 2008-10-16 20:38:35 230,400 —-a-w c:\windows\system32\ieaksie.dll
- 2008-08-23 05:54:51 161,792 ——w c:\windows\system32\ieakui.dll
+ 2008-10-15 07:04:53 161,792 —-a-w c:\windows\system32\ieakui.dll
- 2008-08-26 07:24:28 383,488 —-a-w c:\windows\system32\ieapfltr.dll
+ 2008-10-16 20:38:35 383,488 —-a-w c:\windows\system32\ieapfltr.dll
- 2008-08-26 07:24:29 384,512 ——w c:\windows\system32\iedkcs32.dll
+ 2008-10-16 20:38:35 384,512 —-a-w c:\windows\system32\iedkcs32.dll
- 2008-10-03 17:41:15 6,066,176 —-a-w c:\windows\system32\ieframe.dll
+ 2008-10-16 20:38:37 6,066,176 —-a-w c:\windows\system32\ieframe.dll
- 2008-08-26 07:24:29 44,544 ——w c:\windows\system32\iernonce.dll
+ 2008-10-16 20:38:37 44,544 —-a-w c:\windows\system32\iernonce.dll
- 2008-08-26 07:24:29 267,776 —-a-w c:\windows\system32\iertutil.dll
+ 2008-10-16 20:38:37 267,776 —-a-w c:\windows\system32\iertutil.dll
- 2008-08-25 08:38:00 13,824 —-a-w c:\windows\system32\ieudinit.exe
+ 2008-10-16 13:11:09 13,824 —-a-w c:\windows\system32\ieudinit.exe
- 2008-08-26 07:24:30 27,648 ——w c:\windows\system32\jsproxy.dll
+ 2008-10-16 20:38:37 27,648 —-a-w c:\windows\system32\jsproxy.dll
- 2006-10-19 01:03:58 100,864 —-a-w c:\windows\system32\logagent.exe
+ 2008-06-18 06:09:22 100,864 —-a-w c:\windows\system32\logagent.exe
- 2008-08-26 07:24:30 459,264 —-a-w c:\windows\system32\msfeeds.dll
+ 2008-10-16 20:38:37 459,264 —-a-w c:\windows\system32\msfeeds.dll
- 2008-08-26 07:24:30 52,224 —-a-w c:\windows\system32\msfeedsbs.dll
+ 2008-10-16 20:38:37 52,224 —-a-w c:\windows\system32\msfeedsbs.dll
- 2008-08-27 08:24:32 3,593,216 —-a-w c:\windows\system32\mshtml.dll
+ 2008-12-13 06:40:02 3,593,216 —-a-w c:\windows\system32\mshtml.dll
- 2008-08-26 07:24:30 477,696 ——w c:\windows\system32\mshtmled.dll
+ 2008-10-16 20:38:38 477,696 —-a-w c:\windows\system32\mshtmled.dll
- 2008-08-26 07:24:30 193,024 ——w c:\windows\system32\msrating.dll
+ 2008-10-16 20:38:38 193,024 —-a-w c:\windows\system32\msrating.dll
- 2008-08-26 07:24:30 671,232 ——w c:\windows\system32\mstime.dll
+ 2008-10-16 20:38:39 671,232 —-a-w c:\windows\system32\mstime.dll
- 2008-08-26 07:24:30 102,912 ——w c:\windows\system32\occache.dll
+ 2008-10-16 20:38:39 102,912 —-a-w c:\windows\system32\occache.dll
- 2008-08-26 07:24:30 44,544 ——w c:\windows\system32\pngfilt.dll
+ 2008-10-16 20:38:39 44,544 —-a-w c:\windows\system32\pngfilt.dll
- 2008-07-08 13:02:01 17,272 ——w c:\windows\system32\spmsg.dll
+ 2007-07-27 14:41:40 16,760 —-a-w c:\windows\system32\spmsg.dll
- 2006-08-21 14:52:08 246,814 —-a-w c:\windows\system32\strmdll.dll
+ 2008-10-03 10:15:47 247,326 —-a-w c:\windows\system32\strmdll.dll
- 2008-07-14 11:09:18 62,976 ——w c:\windows\system32\tzchange.exe
+ 2008-10-22 09:47:07 62,976 —-a-w c:\windows\system32\tzchange.exe
- 2008-08-26 07:24:30 105,984 —-a-w c:\windows\system32\url.dll
+ 2008-10-16 20:38:39 105,984 —-a-w c:\windows\system32\url.dll
- 2008-08-26 07:24:31 1,159,680 —-a-w c:\windows\system32\urlmon.dll
+ 2008-10-16 20:38:39 1,160,192 —-a-w c:\windows\system32\urlmon.dll
- 2008-08-26 07:24:31 233,472 —-a-w c:\windows\system32\webcheck.dll
+ 2008-10-16 20:38:39 233,472 —-a-w c:\windows\system32\webcheck.dll
- 2008-08-26 07:24:31 826,368 —-a-w c:\windows\system32\wininet.dll
+ 2008-10-16 20:38:40 826,368 —-a-w c:\windows\system32\wininet.dll
- 2006-10-19 02:47:20 937,984 —-a-w c:\windows\system32\wmnetmgr.dll
+ 2008-06-18 10:03:08 938,496 —-a-w c:\windows\system32\WMNetmgr.dll
- 2006-10-19 02:47:22 2,450,944 —-a-w c:\windows\system32\wmvcore.dll
+ 2008-06-18 10:03:14 2,458,112 —-a-w c:\windows\system32\WMVCore.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—-a-w 50,760 2006-05-10 00:24:16 c:\program files\Common Files\AOL\1129690640\ee\bak\AOLSoftware.exe
—-a-w 124,520 2006-02-17 16:59:46 c:\program files\Common Files\AOL\IPHSend\bak\IPHSend.exe
—-a-w 180,269 2005-10-19 00:37:51 c:\program files\Common Files\Real\Update_OB\bak\realsched.exe
—-a-w 48,752 2005-04-08 22:52:30 c:\program files\Common Files\Symantec Shared\bak\ccApp.exe
—-a-w 48,752 2005-04-08 19:52:30 c:\program files\Common Files\Symantec Shared\ccApp.exe
—-a-w 68,856 2007-06-26 02:57:05 c:\program files\Google\GoogleToolbarNotifier\bak\GoogleToolbarNotifier.exe
—-a-w 245,760 2005-02-25 22:34:02 c:\program files\Hewlett-Packard\HP Boot Optimizer\bak\HPBootOp.exe
—-a-w 271,672 2007-07-31 22:44:42 c:\program files\iTunes\bak\iTunesHelper.exe
—-a-w 289,576 2008-10-01 23:57:12 c:\program files\iTunes\iTunesHelper.exe
—-a-w 491,520 2005-03-25 15:13:20 c:\program files\NETGEAR\WG111v2 Configuration Utility\bak\RtWLan.exe
—-a-w 286,720 2007-06-29 10:24:52 c:\program files\QuickTime\bak\qttask.exe
—-a-w 413,696 2008-09-06 20:09:14 c:\program files\QuickTime\QTTask.exe
—-a-w 85,184 2005-04-17 19:30:48 c:\program files\Symantec AntiVirus\bak\VPTray.exe
—-a-w 85,184 2005-04-17 16:30:48 c:\program files\Symantec AntiVirus\VPTray.exe
—-a-w 15,360 2004-08-04 04:00:00 c:\windows\system32\bak\ctfmon.exe
—-a-w 15,360 2004-08-04 04:00:00 c:\windows\system32\ctfmon.exe
—-a-w 126,976 2005-01-23 17:31:34 c:\windows\system32\bak\hkcmd.exe
—-a-w 659,456 2004-06-07 18:42:30 c:\windows\system32\bak\hphmon06.exe
—-a-w 98,304 2005-03-08 03:00:00 c:\windows\system32\spool\drivers\w32x86\3\bak\E_FATIAEA.EXE
—-a-w 98,304 2005-03-08 03:00:00 c:\windows\system32\spool\drivers\w32x86\3\E_FATIAEA.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}]
2008-11-20 16:21 160496 –a—— c:\program files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-12-04 1809648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EPSON Stylus CX4200 Series (Copy 2)"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIAEA.EXE" [2005-03-07 98304]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [N/A]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb10.exe" [2004-03-04 172032]
"EPSON Stylus CX4200 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIAEA.EXE" [2005-03-07 98304]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-12-10 1261336]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"MSConfig"="c:\windows\pchealth\helpctr\Binaries\MSCONFIG.EXE" [2004-08-03 158208]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
WG111v2 Smart Wizard Wireless Setting.lnk - c:\program files\NETGEAR\WG111v2 Configuration Utility\RtlWake.exe [2006-06-12 745472]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-03 14:56 352256 c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Updates from HP.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Updates from HP.lnk
backup=c:\windows\pss\Updates from HP.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^HP_Owner^Start Menu^Programs^Startup^OpenOffice.org 3.0.lnk]
path=c:\documents and settings\HP_Owner\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk
backup=c:\windows\pss\OpenOffice.org 3.0.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
–a—— 2007-03-09 11:09 63712 c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a—— 2008-10-15 01:04 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG8_TRAY]
–a—— 2008-12-10 11:57 1261336 c:\progra~1\AVG\AVG8\avgtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
c:\program files\Common Files\AOL\1129690640\ee\AOLSoftware.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
–a—— 2008-10-01 18:57 289576 c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LSBWatcher]
–a—— 2004-10-14 15:54 253952 c:\hp\drivers\hplsbwatcher\LSBurnWatcher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-09-06 15:09 413696 c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Search Protection]
–a—— 2008-10-07 10:23 111856 c:\program files\Yahoo!\Search Protection\SearchProtection.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SfKg6wIP]
c:\documents and settings\HP_Owner\Application Data\Microsoft\Windows\rjdyn.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpeedRunner]
c:\documents and settings\HP_Owner\Application Data\SpeedRunner\SpeedRunner.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpySweeper]
–a—— 2004-07-20 13:48 3210752 c:\program files\Webroot\Spy Sweeper\SpySweeper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2008-06-10 04:27 144784 c:\program files\Java\jre1.6.0_07\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Virtual PDF Printer]
c:\program files\Virtual PDF Printer\VirtualPDFPrinter.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YSearchProtection]
–a—— 2008-10-07 10:23 111856 c:\program files\Yahoo!\Search Protection\SearchProtection.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Bonjour Service"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Updates from HP\\309731\\Program\\Updates from HP.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1129690640\\ee\\aim6.exe"=
"c:\\StubInstaller.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-12-10 97928]
R1 SASDIFSV;SASDIFSV;\??\c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2008-12-04 8944]
R1 SASKUTIL;SASKUTIL;\??\c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2008-12-04 55024]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2008-12-10 875288]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-12-10 231704]
R2 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\Drivers\avgtdix.sys [2008-12-10 76040]
R2 EAPPkt;Realtek EAPPkt Protocol;c:\windows\system32\DRIVERS\EAPPkt.sys [2006-05-12 59136]
R2 YahooAUService;Yahoo! Updater;"c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe" [2008-11-09 602392]
R3 EraserUtilDrv10733;EraserUtilDrv10733;\??\c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv10733.sys [2007-10-12 112688]
R3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\DRIVERS\wg111v2.sys [2006-06-12 108160]
R3 SASENUM;SASENUM;\??\c:\program files\SUPERAntiSpyware\SASENUM.SYS [2008-12-04 7408]
S3 SavRoam;SAVRoam;"c:\program files\Symantec AntiVirus\SavRoam.exe" [2005-04-17 124608]
S3 SUSTUCAM;Susteen USB Cable Modem Driver;c:\windows\system32\DRIVERS\sustucam.sys [2007-04-04 38272]
S3 SUSTUCAP;Susteen USB Cable Port Driver;c:\windows\system32\DRIVERS\sustucap.sys [2007-04-04 38272]
S3 SUSTUCAU;Susteen USB Cable USB Driver;c:\windows\system32\DRIVERS\sustucau.sys [2007-04-04 21376]
.
Contents of the 'Scheduled Tasks' folder
2008-12-27 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
.
- - - - ORPHANS REMOVED - - - -
BHO-{18F32C3A-1037-491D-A118-5719F2F4AE41} - c:\windows\system32\pmnkIccc.dll
BHO-{937add2e-7664-4911-87f8-fcae2ba65286} - c:\windows\system32\dqwejy.dll
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=pavilion&pf=desktop
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=pavilion&pf=desktop
uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=pavilion&pf=desktop
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.0\resources\en-US\local\search.html
IE: Add To HP Organize… - c:\progra~1\HEWLET~1\HPORGA~1\bin/module.main/favorites\ie_add_to.html
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\hc7ttvx3.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrie7&query=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrab&query=
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-12-29 18:57:05
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(720)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Symantec Shared\ccSetMgr.exe
c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Symantec AntiVirus\DefWatch.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\HPZipm12.exe
c:\program files\Symantec AntiVirus\Rtvscan.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-12-29 19:08:07 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-30 00:07:58
ComboFix2.txt 2008-12-16 01:48:29
ComboFix3.txt 2008-12-15 19:10:38
Pre-Run: 91,509,575,680 bytes free
Post-Run: 92,307,664,896 bytes free
510 — E O F — 2008-12-19 04:37:19