omboFix 08-05-15.3 - Jeffery 2008-05-17 20:19:18.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.675 [GMT 2:00]
Running from: C:\Documents and Settings\Jeffery\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Desktop\webmediaplayer.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\WebMediaPlayer
C:\Documents and Settings\All Users\Start Menu\Programs\WebMediaPlayer\Privacy Policy.url
C:\Documents and Settings\All Users\Start Menu\Programs\WebMediaPlayer\Terms and Conditions.url
C:\Documents and Settings\All Users\Start Menu\Programs\WebMediaPlayer\Uninstall.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\WebMediaPlayer\WebMediaPlayer.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\WebMediaPlayer\Website.url
c:\Documents and Settings\Jeffery\Local Settings\Application Data\bfzuima.dat
c:\documents and settings\jeffery\local settings\application data\bfzuima.exe
C:\Documents and Settings\Jeffery\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
C:\Program Files\webmediaplayer
C:\Program Files\webmediaplayer\resources\languages_v2.xml
C:\Program Files\webmediaplayer\resources\webmedias
C:\Program Files\webmediaplayer\skins\classic.skn
C:\Program Files\webmediaplayer\sqlite3.dll
C:\Program Files\webmediaplayer\uninst.exe
C:\Program Files\webmediaplayer\WebMediaPlayer.exe
C:\smp.bat
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\system32\msvcsv60.dll
C:\WINDOWS\system32\systemwindow.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NWSAPAGENT
-------\Service_NwSapAgent
((((((((((((((((((((((((( Files Created from 2008-04-17 to 2008-05-17 )))))))))))))))))))))))))))))))
.
2008-05-17 17:27 . 2007-09-06 00:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-05-17 17:27 . 2006-04-27 17:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-05-17 17:27 . 2008-05-15 23:22 86,528 --a------ C:\WINDOWS\system32\VACFix.exe
2008-05-17 17:27 . 2008-04-28 08:03 82,944 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-05-17 17:27 . 2008-04-28 08:03 82,944 --a------ C:\WINDOWS\system32\404Fix.exe
2008-05-17 17:27 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-05-17 17:27 . 2004-07-31 18:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-05-17 17:27 . 2007-10-04 00:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-05-17 17:27 . 2008-05-17 17:27 4,766 --a------ C:\WINDOWS\system32\tmp.reg
2008-05-16 12:38 . 2008-05-16 12:35 691,545 --a------ C:\WINDOWS\unins000.exe
2008-05-16 12:38 . 2008-05-16 12:38 2,552 --a------ C:\WINDOWS\unins000.dat
2008-05-16 11:58 . 2008-05-16 12:03 0 --a------ C:\Debug.QC6
2008-05-15 17:44 . 2008-05-15 17:44 216,064 --a------ C:\WINDOWS\tokry.dll
2008-05-15 17:05 . 2008-05-15 17:28 <DIR> d-------- C:\Program Files\FXpansion
2008-05-14 17:14 . 2008-05-14 17:14 <DIR> d-------- C:\Program Files\Audio Ease
2008-05-14 17:14 . 2008-05-14 17:14 <DIR> d-------- C:\Documents and Settings\Jeffery\Application Data\Audio Ease
2008-05-14 17:14 . 2008-05-14 17:14 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Audio Ease
2008-05-14 17:14 . 2007-09-12 13:51 491,520 --a------ C:\WINDOWS\system32\libencdec.dll
2008-05-14 16:09 . 2008-05-14 16:09 <DIR> d-------- C:\Program Files\Digidesign
2008-05-14 15:07 . 2008-05-14 15:07 16 --a------ C:\WINDOWS\system32\w3data.vss
2008-05-14 15:07 . 2008-05-14 15:07 16 --a------ C:\WINDOWS\msocreg32.dat
2008-05-14 15:06 . 2008-05-14 16:09 <DIR> d-------- C:\Program Files\IK Multimedia
2008-05-14 15:06 . 2008-05-14 15:06 <DIR> d-------- C:\Program Files\Common Files\DigiDesign
2008-05-14 15:06 . 2008-05-14 15:06 <DIR> d-------- C:\Documents and Settings\Jeffery\Application Data\InstallShield
2008-05-13 21:51 . 2003-09-04 10:02 311,295 --a------ C:\WINDOWS\LOOP.exe
2008-05-12 14:22 . 2008-05-17 20:26 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-05-12 14:22 . 2008-05-12 14:22 1,409 --a------ C:\WINDOWS\QTFont.for
2008-05-12 14:21 . 2008-05-12 14:21 <DIR> d-------- C:\Program Files\iTunes
2008-05-12 14:21 . 2008-05-12 14:21 <DIR> d-------- C:\Program Files\iPod
2008-05-12 14:17 . 2008-05-12 14:18 <DIR> d-------- C:\Program Files\QuickTime
2008-05-12 14:08 . 2008-05-12 14:08 <DIR> d-------- C:\Program Files\Apple Software Update
2008-05-10 22:11 . 2008-05-10 22:11 <DIR> d-------- C:\Program Files\Ableton
2008-05-01 11:36 . 2008-05-01 11:36 1,160 --a------ C:\WINDOWS\mozver.dat
2008-04-30 13:52 . 2008-04-30 13:52 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-04-30 13:30 . 2008-04-30 13:30 <DIR> d-------- C:\Program Files\Common Files\Macrovision Shared
2008-04-28 21:36 . 2008-04-28 21:36 <DIR> d-------- C:\Documents and Settings\Jeffery\Application Data\DivX
2008-04-28 20:43 . 2008-03-21 22:30 129,784 --------- C:\WINDOWS\system32\pxafs.dll
2008-04-28 20:43 . 2008-03-21 22:30 9,464 --------- C:\WINDOWS\system32\drivers\cdralw2k.sys
2008-04-28 20:43 . 2008-03-21 22:30 9,336 --------- C:\WINDOWS\system32\drivers\cdr4_xp.sys
2008-04-25 08:04 . 2008-04-25 08:04 <DIR> d-------- C:\ae267c39145c49d381c44c6f86ebbb
2008-04-21 17:18 . 2008-04-21 17:18 <DIR> d-------- C:\Documents and Settings\Jeffery\Application Data\BitZipper
2008-04-21 17:17 . 2008-04-21 17:18 <DIR> d-------- C:\Program Files\BitZipper
2008-04-21 07:39 . 2008-04-21 07:39 <DIR> d-------- C:\Documents and Settings\Jeffery\Application Data\Talkback
2008-04-21 07:38 . 2008-04-21 07:38 0 --a------ C:\WINDOWS\nsreg.dat
2008-04-21 07:37 . 2008-04-21 07:37 <DIR> d-------- C:\Program Files\Common Files\xing shared
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-17 18:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kontiki
2008-05-17 11:19 --------- d-----w C:\Program Files\GameSpy Arcade
2008-05-17 11:00 --------- d-----w C:\Program Files\Microsoft Games
2008-05-16 16:00 --------- d-----w C:\Program Files\Norton Security Scan
2008-05-16 12:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-16 11:03 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-05-15 15:28 --------- d-----w C:\Program Files\Vstplugins
2008-05-14 13:06 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-10 20:08 --------- d-----w C:\Documents and Settings\Jeffery\Application Data\Ableton
2008-05-09 20:56 --------- d-----w C:\Documents and Settings\Jeffery\Application Data\MSN6
2008-04-30 11:42 --------- d-----w C:\Program Files\Common Files\Adobe
2008-04-28 18:44 --------- d-----w C:\Program Files\DivX
2008-04-28 14:03 --------- d-----w C:\Program Files\Kontiki
2008-04-21 14:56 --------- d-----w C:\Program Files\BitComet
2008-04-21 05:37 --------- d-----w C:\Program Files\Common Files\Real
2008-04-06 14:30 --------- d-----w C:\Program Files\MagicISO
2008-04-06 12:34 --------- d-----w C:\Documents and Settings\Jeffery\Application Data\Ahead
2008-03-25 05:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-03-23 19:27 --------- d-----w C:\Program Files\Save Flash
2008-03-21 20:30 43,528 ------w C:\WINDOWS\system32\drivers\PxHelp20.sys
2008-03-17 10:07 --------- d-----w C:\Program Files\HistoryKill
2007-10-10 18:01 106,728 ----a-w C:\Documents and Settings\Jeffery\Application Data\GDIPFONTCACHEV1.DAT
2007-04-15 17:56 560 ----a-w C:\Documents and Settings\Jeffery\Application Data\ViewerApp.dat
2006-12-30 09:27 69,632 ----a-w C:\Documents and Settings\Jeffery\Application Data\internaldb4827.dat
2006-12-30 09:27 151 ----a-w C:\Documents and Settings\Jeffery\Application Data\internaldb9912.dat
2006-12-30 09:27 0 ----a-w C:\Documents and Settings\Jeffery\Application Data\internaldb6500.dat
2006-11-18 19:03 0 ----a-w C:\Documents and Settings\Jeffery\Application Data\internaldb5436.dat
2006-11-16 16:55 0 ----a-w C:\Documents and Settings\Jeffery\Application Data\internaldb2391.dat
2006-11-16 01:52 49 ----a-w C:\Documents and Settings\Jeffery\Application Data\internaldb41.dat
2006-11-13 00:02 0 ----a-w C:\Documents and Settings\Jeffery\Application Data\internaldb9169.dat
2006-11-13 00:02 0 ----a-w C:\Documents and Settings\Jeffery\Application Data\internaldb1869.dat
2006-11-04 13:58 9,216 ----a-w C:\Documents and Settings\Jeffery\Application Data\internaldb8467.dat
2006-11-04 13:58 0 ----a-w C:\Documents and Settings\Jeffery\Application Data\internaldb6334.dat
2001-11-23 04:08 712,704 ----a-w C:\WINDOWS\inf\OTHER\AUDIO3D.DLL
2005-03-16 17:33 56 --sh--r C:\WINDOWS\system32\B4E0BF4456.sys
2006-06-11 16:37 4,184 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{95E1D855-9232-48F7-80D9-1ADB65B7939C}]
2008-05-15 17:44 216064 --a------ C:\WINDOWS\tokry.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [2007-02-15 19:52 67128]
"BestPopUpKiller"="C:\Program Files\BestPopUpKiller\BestPopupKiller.exe" [ ]
"SpyKiller"="C:\Program Files\SpyKiller\spykiller.exe" [ ]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [ ]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 09:56 15360]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2005-11-15 21:21 1204224]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-07 19:47 68856]
"kdx"="C:\Program Files\Kontiki\KHost.exe" [2006-11-08 18:32 1040832]
"antispy"="C:\Documents and Settings\Jeffery\My Documents\Dafydd\Various\FyddNeb\IEAntiVirus\ANTIVIRUS.exe" [ ]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2003-04-06 18:19 155648]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2003-04-06 18:07 114688]
"Cmaudio"="cmicnfg.cpl" []
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 12:50 155648]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2003-12-08 18:35 32768]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [2003-08-29 15:17 188416]
"LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" [2003-08-29 15:20 77824]
"Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2002-07-25 07:20 28672]
"PicasaNet"="C:\Program Files\Hello\Hello.exe" [ ]
"CnxDslTaskBar"="C:\Program Files\Trust\Trust MD3100 USB ADSL MODEM\CnxDslTb.exe" [2006-01-10 20:30 462848]
"SMSystemAnalyzer"="C:\Program Files\iolo\System Mechanic 7\SMSystemAnalyzer.exe" [ ]
"UserFaultCheck"="C:\WINDOWS\system32\dumprep 0 -u" [ ]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-11-28 20:51 583048]
"mxomssmenu"="C:\Documents and Settings\Jeffery\My Documents\Dafydd's file OLD STUFF NOW ON EXTERNAL DRIVE\one touch external hardrive\OneTouch Status\maxmenumgr.exe" [ ]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-04-21 07:36 185896]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ALUAlert"="C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe" [2006-09-03 02:36 100032]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [ ]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 19:16:50 113664]
Belkin 802.11g Wireless PCI Card Configuration Utility.lnk - C:\Program Files\Belkin\Belkin 802.11g Wireless PCI Card Configuration Utility\utility.exe [2007-12-13 18:44:27 327765]
DSLMON.lnk - C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2007-05-07 18:38:03 839680]
hp psc 1000 series.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe [2003-04-06 02:17:18 147456]
hpoddt01.exe.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2003-04-06 02:06:58 28672]
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2007-02-15 19:52:08 67128]
Picture Package Menu.lnk - C:\Program Files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe [2006-06-10 18:55:28 151552]
Picture Package VCD Maker.lnk - C:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe [2006-06-10 18:55:17 106496]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.enc"= ITIG726.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
"C:\\Program Files\\LimeWire\\LimeWire 4.2.6\\LimeWire.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Tiscali_ADSL\\Wizard\\Offline\\CTD_FirmwareUpgrader_Tiscali.exe"=
"C:\\Program Files\\BitComet\\BitComet.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\Microsoft Games\\Halo Server\\haloded.exe"=
"C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\helpctr.exe"=
"C:\\Program Files\\Microsoft Games\\Halo Trial\\halo.exe"=
"C:\\Program Files\\Microsoft Games\\Rise of Nations\\patriots.exe"=
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"C:\\Program Files\\Kontiki\\KService.exe"=
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\VirtualDJ\\virtualdj_trial.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\Microsoft Games\\Rise of Nations\\thrones.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-03-29 19:31]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-03-29 19:35]
R2 ssoftnt4;ssoftnt4;C:\WINDOWS\system32\Drivers\ssoftnt4.sys [2004-05-21 02:30]
R3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;C:\PROGRA~1\Belkin\BELKIN~1.11G\DNINDIS5.SYS [2003-07-24 13:10]
S2 IKANLOADER2;General Purpose USB Driver (e4ldr.sys);C:\WINDOWS\system32\Drivers\e4ldr.sys [2006-03-02 19:25]
S2 Maxtor Sync Service;Maxtor Service;"C:\Documents and Settings\Jeffery\My Documents\Dafydd's file OLD STUFF NOW ON EXTERNAL DRIVE\one touch external hardrive\Sync\SyncServices.exe" []
S3 CnxEtP;Trust MD3100 USB ADSL MODEM LAN Adapter Filter Driver;C:\WINDOWS\system32\DRIVERS\CnxEtP.sys [2006-01-10 20:30]
S3 CnxEtU;Trust MD3100 USB ADSL MODEM Loader;C:\WINDOWS\system32\DRIVERS\CnxEtU.sys [2006-01-10 20:30]
S3 CnxTgN;Trust MD3100 USB ADSL MODEM LAN Adapter Driver;C:\WINDOWS\system32\DRIVERS\CnxTgN.sys [2006-01-10 20:30]
S3 e4usbaw;USB ADSL2 WAN Adapter;C:\WINDOWS\system32\DRIVERS\e4usbaw.sys [2006-05-04 18:50]
S3 PID_0920;Logitech QuickCam Express(PID_0920);C:\WINDOWS\system32\DRIVERS\LV532AV.SYS [2003-09-16 05:41]
S3 sonypvs1;Sony Digital Imaging Video2;C:\WINDOWS\system32\DRIVERS\sonypvs1.sys [2002-10-15 22:41]
S3 w200bus;Sony Ericsson W200 driver (WDM);C:\WINDOWS\system32\DRIVERS\w200bus.sys [2006-11-07 10:42]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{83c7f906-a95a-11dc-9dc9-0001297494d5}]
\Shell\AutoRun\command - E:\ReadMe.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-05-15 11:15:05 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2005-03-16 18:51:17 C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1102702365.job"
- C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe4-I
"2008-05-16 17:29:59 C:\WINDOWS\Tasks\Norton Security Scan.job"
- C:\Program Files\Norton Security Scan\Nss.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-05-17 20:26:25
Windows 5.1.2600 Service Pack 2 NTFS
detected NTDLL code modification:
ZwQuerySystemInformation
scanning hidden processes ...
C:\Program Files\iolo\Common\Lib\ioloDMVSvc.exe [1528] 0x89610A38
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\Program Files\iolo\Common\Lib\ioloHL.dll
PROCESS: C:\WINDOWS\system32\lsass.exe
-> C:\Program Files\iolo\Common\Lib\ioloHL.dll
PROCESS: C:\WINDOWS\explorer.exe
-> C:\Program Files\iolo\Common\Lib\ioloHL.dll
PROCESS: C:\WINDOWS\system32\csrss.exe
-> C:\Program Files\iolo\Common\Lib\ioloHL.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Kontiki\KService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\MDM.EXE
C:\WINDOWS\system32\ssoftsrv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\LVComS.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposts08.exe
.
**************************************************************************
.
Completion time: 2008-05-17 20:34:05 - machine was rebooted [Jeffery]
ComboFix-quarantined-files.txt 2008-05-17 18:33:45
Pre-Run: 12,241,600,512 bytes free
Post-Run: 12,167,200,768 bytes free
278 --- E O F --- 2008-05-17 10:02:16
this ifs the info i got