Hi,
I uploaded the file and here is the latest log. Thanks a lot.
ComboFix 08-05-29.1 - Samantha 2008-06-03 6:29:16.4 - NTFSx86
Running from: C:\Documents and Settings\Samantha\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Samantha\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
C:\WINDOWS\system32\drivers\lvuvc.hs
C:\WINDOWS\system32\g32.exe
C:\WINDOWS\system32\tcntlkdm.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\drivers\lvuvc.hs
C:\WINDOWS\system32\g32.exe
C:\WINDOWS\system32\tcntlkdm.exe
.
((((((((((((((((((((((((( Files Created from 2008-05-03 to 2008-06-03 )))))))))))))))))))))))))))))))
.
2008-06-02 19:04 . 2008-06-02 19:04 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-06-02 19:04 . 2008-06-02 19:04 <DIR> d-------- C:\WINDOWS\LastGood
2008-06-02 19:04 . 2008-06-02 19:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-05-31 12:13 . 2008-05-31 16:35 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-05-31 12:13 . 2008-05-31 12:13 1,409 --a------ C:\WINDOWS\QTFont.for
2008-05-30 20:29 . 2008-05-30 20:29 <DIR> d-------- C:\5826e718f4b816e238
2008-05-16 14:58 . 2004-08-04 00:56 116,224 --a------ C:\WINDOWS\system32\dllcache\xrxwiadr.dll
2008-05-16 14:58 . 2001-08-17 22:37 99,865 --a------ C:\WINDOWS\system32\dllcache\xlog.exe
2008-05-16 14:58 . 2004-08-04 05:00 28,288 --a------ C:\WINDOWS\system32\dllcache\xjis.nls
2008-05-16 14:58 . 2001-08-17 22:37 27,648 --a------ C:\WINDOWS\system32\dllcache\xrxftplt.exe
2008-05-16 14:58 . 2001-08-17 22:36 23,040 --a------ C:\WINDOWS\system32\dllcache\xrxwbtmp.dll
2008-05-16 14:58 . 2004-08-03 22:29 19,455 --a------ C:\WINDOWS\system32\dllcache\wvchntxx.sys
2008-05-16 14:58 . 2001-08-17 22:36 17,408 --a------ C:\WINDOWS\system32\dllcache\xrxscnui.dll
2008-05-16 14:58 . 2001-08-17 12:11 16,970 --a------ C:\WINDOWS\system32\dllcache\xem336n5.sys
2008-05-16 14:58 . 2001-08-17 22:37 4,608 --a------ C:\WINDOWS\system32\dllcache\xrxflnch.exe
2008-05-16 14:56 . 2001-08-17 13:28 765,884 --a------ C:\WINDOWS\system32\dllcache\usrti.sys
2008-05-16 14:55 . 2001-08-17 13:28 794,654 --a------ C:\WINDOWS\system32\dllcache\usr1801.sys
2008-05-16 14:54 . 2001-08-17 22:36 525,568 --a------ C:\WINDOWS\system32\dllcache\tridxp.dll
2008-05-16 14:53 . 2004-08-04 05:00 571,392 --a------ C:\WINDOWS\system32\dllcache\tintlgnt.ime
2008-05-16 14:52 . 2001-08-17 12:18 285,760 --a------ C:\WINDOWS\system32\dllcache\stlnata.sys
2008-05-16 14:51 . 2004-08-04 05:00 456,704 --a------ C:\WINDOWS\system32\dllcache\smtpsvc.dll
2008-05-16 14:50 . 2004-08-03 22:41 404,990 --a------ C:\WINDOWS\system32\dllcache\slntamr.sys
2008-05-16 14:49 . 2001-08-17 22:36 386,560 --a------ C:\WINDOWS\system32\dllcache\sgiul50.dll
2008-05-16 14:48 . 2001-08-17 22:36 495,616 --a------ C:\WINDOWS\system32\dllcache\sblfx.dll
2008-05-16 14:47 . 2001-08-17 13:28 899,146 --a------ C:\WINDOWS\system32\dllcache\r2mdkxga.sys
2008-05-16 14:46 . 2004-08-04 05:00 482,304 --a------ C:\WINDOWS\system32\dllcache\pintlgnt.ime
2008-05-16 14:45 . 2001-08-17 14:05 351,616 --a------ C:\WINDOWS\system32\dllcache\ovcodek2.sys
2008-05-16 14:44 . 2001-08-17 12:50 198,144 --a------ C:\WINDOWS\system32\dllcache\nv3.sys
2008-05-16 14:43 . 2004-08-03 22:31 132,695 --a------ C:\WINDOWS\system32\dllcache\netwlan5.sys
2008-05-16 14:42 . 2004-08-04 05:00 1,875,968 --a------ C:\WINDOWS\system32\dllcache\msir3jp.lex
2008-05-16 14:41 . 2001-08-17 13:28 802,683 --a------ C:\WINDOWS\system32\dllcache\ltsm.sys
2008-05-16 14:40 . 2004-08-04 05:00 1,158,818 --a------ C:\WINDOWS\system32\dllcache\korwbrkr.lex
2008-05-16 14:39 . 2004-08-04 05:00 811,064 --a------ C:\WINDOWS\system32\dllcache\imjp81k.dll
2008-05-16 14:38 . 2004-08-04 05:00 13,463,552 --a------ C:\WINDOWS\system32\dllcache\hwxjpn.dll
2008-05-16 14:37 . 2001-08-17 13:28 542,879 --a------ C:\WINDOWS\system32\dllcache\hsf_msft.sys
2008-05-16 14:36 . 2001-08-17 14:56 1,733,120 --a------ C:\WINDOWS\system32\dllcache\g400d.dll
2008-05-16 14:35 . 2001-08-17 12:15 455,680 --a------ C:\WINDOWS\system32\dllcache\fus2base.sys
2008-05-16 14:34 . 2001-08-17 13:28 634,134 --a------ C:\WINDOWS\system32\dllcache\el656ct5.sys
2008-05-16 14:33 . 2001-08-17 12:14 952,007 --a------ C:\WINDOWS\system32\dllcache\diwan.sys
2008-05-16 14:32 . 2001-08-17 22:36 256,512 --a------ C:\WINDOWS\system32\dllcache\devcon32.dll
2008-05-16 14:31 . 2004-08-04 05:00 1,677,824 --a------ C:\WINDOWS\system32\dllcache\chsbrkr.dll
2008-05-16 14:30 . 2004-08-04 00:56 1,888,992 --a------ C:\WINDOWS\system32\dllcache\ati3duag.dll
2008-05-16 14:29 . 2001-08-17 13:28 762,780 --a------ C:\WINDOWS\system32\dllcache\3cwmcru.sys
2008-05-16 14:28 . 2004-08-04 05:00 2,134,528 --a------ C:\WINDOWS\system32\dllcache\smtpsnap.dll
2008-05-16 14:28 . 2004-08-04 05:00 189,440 --a------ C:\WINDOWS\system32\dllcache\smtpadm.dll
2008-05-16 14:28 . 2001-08-17 14:56 66,048 --a------ C:\WINDOWS\system32\dllcache\s3legacy.dll
2008-05-16 14:28 . 2003-03-24 16:52 32,827 --a------ C:\WINDOWS\system32\dllcache\tcptest.exe
2008-05-16 14:28 . 2003-03-24 16:52 20,536 --a------ C:\WINDOWS\system32\dllcache\shtml.dll
2008-05-16 14:28 . 2003-03-24 16:52 16,437 --a------ C:\WINDOWS\system32\dllcache\shtml.exe
2008-05-16 14:28 . 2003-03-24 16:52 16,384 --a------ C:\WINDOWS\system32\dllcache\tcptsat.dll
2008-05-16 14:28 . 2004-08-04 05:00 8,192 --a------ C:\WINDOWS\system32\dllcache\staxmem.dll
2008-05-16 14:28 . 2004-08-04 05:00 7,168 --a------ C:\WINDOWS\system32\dllcache\wamregps.dll
2008-05-16 12:20 . 2008-05-16 12:20 <DIR> d-------- C:\Program Files\Trend Micro
2008-05-16 12:03 . 2008-02-22 02:33 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-05-15 22:28 . 2008-05-15 22:28 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-05-15 22:28 . 2008-05-16 08:01 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-15 22:18 . 2008-05-15 22:18 <DIR> d-------- C:\Program Files\CCleaner
2008-05-15 22:11 . 2008-05-15 22:11 9,662 --a------ C:\WINDOWS\system32\ZoneAlarmIconUS.ico
2008-05-15 22:09 . 2008-05-15 22:09 <DIR> d-------- C:\VundoFix Backups
2008-05-15 21:46 . 2008-05-15 21:46 4,286 --a------ C:\WINDOWS\system32\Jamster.ico
2008-05-15 21:27 . 2008-05-15 21:27 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-05-15 21:27 . 2008-05-15 21:27 <DIR> d-------- C:\Documents and Settings\Samantha\Application Data\Malwarebytes
2008-05-15 21:27 . 2008-05-15 21:27 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-05-15 21:27 . 2008-05-05 20:46 27,048 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-05-15 21:27 . 2008-05-05 20:46 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-05-14 19:09 . 2008-05-14 19:09 <DIR> d-------- C:\Program Files\Webroot
2008-05-14 19:09 . 2003-10-15 23:42 150,528 --a------ C:\WINDOWS\unSpySweeper.exe
2008-05-14 19:04 . 2008-05-14 19:05 <DIR> d-------- C:\Program Files\SpywareBlaster
2008-05-14 17:59 . 2008-05-26 16:30 <DIR> d--hs---- C:\WINDOWS\U2FtYW50aGEg
2008-05-14 17:57 . 2008-05-30 20:41 <DIR> d-------- C:\Temp
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-26 02:41 5,427 ----a-w C:\WINDOWS\system32\EGATHDRV.SYS
2008-06-03 01:53 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-05-18 10:39 --------- d-----w C:\Program Files\DNA
2008-05-16 19:03 --------- d-----w C:\Program Files\Java
2008-04-22 03:33 15,740 ----a-w C:\Documents and Settings\Samantha\Application Data\ViewerApp.dat
2008-04-19 06:40 --------- d-----w C:\Program Files\Picasa2
2008-04-15 02:39 --------- d-----w C:\Program Files\iTunes
2008-04-15 02:39 --------- d-----w C:\Program Files\iPod
2008-04-15 02:35 --------- d-----w C:\Program Files\Bonjour
2008-04-15 02:34 --------- d-----w C:\Program Files\QuickTime
2008-04-15 02:31 --------- d-----w C:\Program Files\Apple Software Update
2008-03-27 08:12 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-27 08:12 151,583 ----a-w C:\WINDOWS\system32\dllcache\msjint40.dll
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\dllcache\win32k.sys
2008-03-19 09:47 1,845,248 ------w C:\WINDOWS\system32\win32k.sys
2008-03-15 04:36 147,456 ----a-w C:\WINDOWS\system32\vbzip10.dll
2007-10-12 17:31 31,448 ----a-w C:\Documents and Settings\Samantha\Application Data\GDIPFONTCACHEV1.DAT
2005-07-29 23:24 472 --sha-r C:\WINDOWS\U2FtYW50aGEg\oZIQsqcXu3H0.vbs
.
((((((((((((((((((((((((((((( snapshot@2008-05-29_19.26.50.41 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-02-26 11:48:44 297,984 ----a-w C:\WINDOWS\$hf_mig$\KB932823-v3\SP2QFE\msctf.dll
+ 2007-03-06 01:22:36 14,048 ----a-w C:\WINDOWS\$hf_mig$\KB932823-v3\spmsg.dll
+ 2007-03-06 01:22:41 213,216 ----a-w C:\WINDOWS\$hf_mig$\KB932823-v3\spuninst.exe
+ 2007-03-06 01:22:34 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB932823-v3\update\spcustom.dll
+ 2007-03-06 01:22:59 716,000 ----a-w C:\WINDOWS\$hf_mig$\KB932823-v3\update\update.exe
+ 2007-03-06 01:23:51 371,424 ----a-w C:\WINDOWS\$hf_mig$\KB932823-v3\update\updspapi.dll
- 2008-05-30 02:15:12 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-31 21:20:47 2,048 --s-a-w C:\WINDOWS\bootstat.dat
- 2008-08-26 04:41:18 8,220 ----a-w C:\WINDOWS\SoftwareDistribution\EventCache\{D8D0C305-3ABD-4DDF-AD8B-7D19FCD21C08}.bin
+ 2008-05-31 21:19:45 13,848 ----a-w C:\WINDOWS\SoftwareDistribution\EventCache\{D8D0C305-3ABD-4DDF-AD8B-7D19FCD21C08}.bin
- 2004-08-04 12:00:00 294,400 ----a-w C:\WINDOWS\system32\dllcache\msctf.dll
+ 2008-02-26 11:59:50 294,912 ----a-w C:\WINDOWS\system32\dllcache\msctf.dll
+ 2005-05-24 19:27:16 213,048 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 22:47:20 94,208 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 22:49:54 950,272 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
- 2008-04-06 05:56:20 19,836,024 ----a-w C:\WINDOWS\system32\MRT.exe
+ 2008-05-09 21:35:04 16,863,864 ----a-w C:\WINDOWS\system32\MRT.exe
- 2004-08-04 12:00:00 294,400 ------w C:\WINDOWS\system32\MSCTF.dll
+ 2008-02-26 11:59:50 294,912 ----a-w C:\WINDOWS\system32\msctf.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2007-06-08 07:59 224248]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00 15360]
"SpySweeper"="C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" [2004-02-25 11:48 665088]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2005-09-15 13:57 110592]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-09-15 13:57 512000]
"TPKMAPHELPER"="C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe" [2005-10-28 19:04 864256]
"TpShocks"="TpShocks.exe" [2005-11-07 11:14 106496 C:\WINDOWS\system32\TpShocks.exe]
"TP4EX"="tp4ex.exe" [2005-10-17 01:11 65536 C:\WINDOWS\system32\TP4EX.exe]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-11-28 13:55 98304]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-11-28 13:52 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-11-28 13:55 118784]
"EZEJMNAP"="C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" [2005-11-17 02:22 237568]
"TPHOTKEY"="C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe" [2005-12-15 14:00 94208]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2005-12-15 14:19 925696]
"suScheduler"="C:\Program Files\ThinkVantage\SystemUpdate\UCLauncher.exe" [2005-08-01 17:32 40960]
"LPManager"="C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe" [2006-01-25 01:03 106496]
"AMSG"="C:\Program Files\ThinkVantage\AMSG\Amsg.exe" [2005-11-14 15:23 487424]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-08-01 05:10 122940]
"ISUSPM Startup"="c:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 16:50 221184]
"ISUSScheduler"="c:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 16:50 81920]
"cssauth"="C:\Program Files\IBM ThinkVantage\Client Security Solution\cssauth.exe" [2005-12-21 18:08 1996336]
"PDService.exe"="C:\Program Files\IBM ThinkVantage\SafeGuard PrivateDisk\pdservice.exe" [2005-11-15 13:13 49152]
"DiskeeperSystray"="C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe" [2005-11-29 10:55 196696]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-05-16 12:00 29744]
"ACTray"="C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe" [2006-01-31 22:19 409600]
"ACWLIcon"="C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe" [2006-01-31 22:12 98304]
"PWRMGRTR"="C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL" [2005-12-07 01:12 151552]
"BLOG"="C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL" [2005-12-07 01:12 208896]
"HostManager"="C:\Program Files\Common Files\AOL\1144550042\ee\AOLSoftware.exe" [2006-05-09 17:24 50760]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"ShStatEXE"="C:\Program Files\Network Associates\VirusScan\SHSTAT.exe" [2004-09-22 20:00 94208]
"McAfeeUpdaterUI"="C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" [2004-08-06 03:50 139320]
"Network Associates Error Reporting Service"="C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe" [2003-10-07 09:48 147514]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 23:12 49152]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2005-12-09 15:32 225280]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2007-06-08 07:59 224248]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2004-08-04 05:00 53760 C:\WINDOWS\system32\narrator.exe]
C:\Documents and Settings\Samantha\Start Menu\Programs\Startup\
DING!.lnk - C:\Program Files\Southwest Airlines\Ding\Ding.exe [2006-06-22 14:15:48 462848]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-04-04 09:11:03 24576]
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-02-19 08:49:22 124912]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-11 23:23:26 282624]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04 83360]
Picture Package Menu.lnk - C:\Program Files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe [2006-06-17 11:05:54 151552]
Picture Package VCD Maker.lnk - C:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe [2006-06-17 11:05:49 106496]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ACNotify]
ACNotify.dll 2006-01-31 22:13 32768 C:\Program Files\ThinkPad\ConnectUtilities\ACNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
psqlpwd.dll 2005-12-08 14:59 39936 C:\WINDOWS\system32\psqlpwd.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2]
notifyf2.dll 2005-07-05 23:45 28672 C:\WINDOWS\system32\notifyf2.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
tphklock.dll 2005-11-30 20:16 24576 C:\WINDOWS\system32\tphklock.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders schannel.dll, digest.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\ThinkVantage\\SystemUpdate\\jre\\bin\\javaw.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\Common Files\\AOL\\1144550042\\ee\\aolsoftware.exe"=
"C:\\Program Files\\Common Files\\AOL\\1144550042\\ee\\aim6.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\NetMeeting\\conf.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\AIM6\\aim6.exe"=
"C:\\Program Files\\AIM\\aim.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
R0 Shockprf;Shockprf;C:\WINDOWS\system32\drivers\Shockprf.sys [2005-11-30 15:58]
R1 ANC;ANC;C:\WINDOWS\system32\drivers\ANC.SYS [2005-11-08 09:27]
R1 IBMTPCHK;IBMTPCHK;C:\WINDOWS\system32\Drivers\IBMBLDID.sys [2006-01-13 00:33]
R1 ShockMgr;ShockMgr;C:\WINDOWS\system32\drivers\ShockMgr.sys [2005-06-20 12:18]
R2 ibmfilter;ibmfilter;C:\WINDOWS\system32\drivers\ibmfilter.sys [2005-12-21 17:14]
R2 PrivateDisk;PrivateDisk;C:\Program Files\IBM ThinkVantage\SafeGuard PrivateDisk\PrivateDiskM.sys [2005-11-15 13:11]
R3 LVPrcMon;Logitech LVPrcMon Driver;C:\WINDOWS\system32\drivers\LVPrcMon.sys [2005-12-09 15:37]
*Newly Created Service* - ENTDRV51
.
Contents of the 'Scheduled Tasks' folder
"2008-05-01 18:21:13 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-06-03 03:58:40 C:\WINDOWS\Tasks\PMTask.job"
- C:\PROGRA~1\ThinkPad\UTILIT~1\PWMIDTSK.EXE
"2006-04-08 15:39:45 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-03 06:42:05
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\Program Files\ThinkPad\ConnectUtilities\AcSvcStub.dll
-> C:\Program Files\ThinkPad\ConnectUtilities\AcLocSettings.dll
-> C:\Program Files\ThinkPad\ConnectUtilities\ACHelper.dll
-> C:\WINDOWS\system32\tphklock.dll
-> C:\WINDOWS\system32\notifyf2.dll
.
Completion time: 2008-06-03 6:50:05
ComboFix-quarantined-files.txt 2008-06-03 13:49:32
ComboFix2.txt 2008-05-31 17:36:30
ComboFix3.txt 2008-05-31 04:03:58
ComboFix4.txt 2008-05-30 02:27:23
Pre-Run: 719,622,144 bytes free
Post-Run: 705,208,320 bytes free
262 --- E O F --- 2008-05-31 21:13:58
|