Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:43:43, on 09/06/08
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Abbey\Introducer Internet Offline\MSSQL$ABBEYIIOFFLINE\Binn\sqlservr.exe
C:\Program Files\Microsoft SQL Server\MSSQL$LG_LP2\Binn\sqlservr.exe
C:\MSSQL7\binn\sqlservr.exe
C:\Windows\System32\NMSSvc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\PROGRA~1\ZONELA~1\ZONEAL~1\MAILFR~1\mantispm.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {15C280AC-5C7A-41CC-841A-A21EDB6E6DA9} - c:\windows\system32\d3drmh.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {8C70764E-0C5F-4527-81A0-A47CAC0213A1} - C:\WINDOWS\system32\d3dima.dll
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" -onlytray
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) -
http://support.euro.dell.com/systemprofiler/SysPro.CABO16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=58813O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky.com/kos/eng/partne ... nicode.cabO16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} -
http://us.chat1.yimg.com/us.yimg.com/i/ ... acscom.cabO16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://gfx2.hotmail.com/mail/w2/pr02/re ... NPUpld.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/microsoftup ... 4882937265O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftup ... 4882912750O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} -
http://chat.yahoo.com/cab/yacsui.cabO16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary/Me ... b31267.cabO16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} -
http://www.belfastcity.gov.uk/webcam/AxisCamControl.ocxO16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn.com/download/MsnMe ... loader.cabO16 - DPF: {CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0) -
O16 - DPF: {D10D723F-9C66-529F-BDED-1866A82E0B52} -
http://download.pcsupercharger.com/CabP ... harger.cabO16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) -
https://mwmus.webex.com/mwmus/tool/syst ... eatgpc.cabO16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) -
http://chat.yahoo.com/cab/yvwrctl.cabO16 - DPF: {E7D4216C-DE13-4491-A56D-C731FCFEC708} (MomentumHelper.Helper) -
https://launchpad.landg.com/Fusion/pack ... Helper.CABO16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) -
http://messenger.zone.msn.com/binary/So ... b31267.cabO20 - Winlogon Notify: ndfioezd - C:\WINDOWS\SYSTEM32\d3drmh.dll
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Intel(R) NMS (NMSSvc) - Intel Corporation - C:\Windows\System32\NMSSvc.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Unknown owner - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe (file missing)
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Unknown owner - C:\Program Files\Trend Micro\BM\TMBMSRV.exe (file missing)
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Unknown owner - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe (file missing)
O23 - Service: Trend Micro Proxy Service (tmproxy) - Unknown owner - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
--
End of file - 6835 bytes
ComboFix 08-06-08.8 - Reception1 Admin 2008-06-09 15:25:54.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.863 [GMT 1:00]
Running from: C:\Documents and Settings\Reception1 Admin\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\d3drmh.dll . . . . failed to delete
.
((((((((((((((((((((((((( Files Created from 2008-05-09 to 2008-06-09 )))))))))))))))))))))))))))))))
.
2008-05-30 10:25 . 2008-05-30 10:25 <DIR> d-------- C:\Program Files\Opera
2008-05-20 10:16 . 2008-05-20 10:16 <DIR> d-------- C:\Documents and Settings\Reception1 Admin\Application Data\Nokia Multimedia Player
2008-05-20 10:12 . 2008-06-02 13:00 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-05-20 10:12 . 2008-05-20 10:12 1,409 --a------ C:\WINDOWS\QTFont.for
2008-05-19 12:37 . 2008-05-19 12:37 <DIR> d-------- C:\focus
2008-05-14 11:11 . 2008-05-20 10:28 244 --ah----- C:\sqmnoopt19.sqm
2008-05-14 11:11 . 2008-05-20 10:28 232 --ah----- C:\sqmdata19.sqm
2008-05-13 11:55 . 2008-05-20 10:28 244 --ah----- C:\sqmnoopt18.sqm
2008-05-13 11:55 . 2008-05-20 10:28 232 --ah----- C:\sqmdata18.sqm
2008-05-13 11:53 . 2008-05-20 10:26 244 --ah----- C:\sqmnoopt17.sqm
2008-05-13 11:53 . 2008-05-20 10:26 232 --ah----- C:\sqmdata17.sqm
2008-05-12 09:40 . 2008-05-20 10:25 244 --ah----- C:\sqmnoopt16.sqm
2008-05-12 09:40 . 2008-05-20 10:25 232 --ah----- C:\sqmdata16.sqm
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-09 14:37 10,114,080 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-06-09 14:30 136,460 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-06-09 11:41 --------- d-----w C:\Program Files\Folio
2008-06-09 10:38 --------- d-----w C:\Documents and Settings\Reception1 Admin\Application Data\AdobeUM
2008-05-12 10:37 --------- d-----w C:\Program Files\Northern Rock Online
2008-04-17 14:40 --------- d-----w C:\Documents and Settings\Reception1 Admin\Application Data\MailFrontier
2008-04-17 14:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\MailFrontier
2008-04-17 12:04 59,040 ----a-w C:\Documents and Settings\Reception1 Admin\Application Data\GDIPFONTCACHEV1.DAT
2008-04-17 10:58 --------- d-----w C:\Documents and Settings\Reception1 Admin\Application Data\Nokia
2008-04-17 10:47 --------- d-----w C:\Documents and Settings\Reception1 Admin\Application Data\PC Suite
2008-04-17 10:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\PC Suite
2008-04-17 10:46 0 ---ha-w C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-04-17 10:46 0 ---ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
2008-04-17 10:36 --------- d-----w C:\Program Files\PC Connectivity Solution
2008-04-17 10:36 --------- d-----w C:\Program Files\Nokia
2008-04-17 10:36 --------- d-----w C:\Program Files\DIFX
2008-04-17 10:36 --------- d-----w C:\Program Files\Common Files\PCSuite
2008-04-17 10:36 --------- d-----w C:\Program Files\Common Files\Nokia
2008-04-17 10:32 --------- d-----w C:\Documents and Settings\All Users\Application Data\Installations
2008-04-15 15:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-04-14 15:14 --------- d-----w C:\Program Files\Trend Micro
2008-04-14 14:22 --------- d-----w C:\Program Files\Intermediary Mortgages
2008-04-14 14:17 --------- d-----w C:\Program Files\Alliance and Leicester Online Forms
2008-04-09 10:21 --------- d-----w C:\Program Files\Common Files\Adobe
2008-03-18 15:29 60,968 ----a-w C:\Documents and Settings\Administrator\GoToAssistDownloadHelper.exe
2008-03-13 22:11 75,248 ----a-w C:\WINDOWS\zllsputility.exe
2008-02-07 15:00 59,040 ----a-w C:\Documents and Settings\Administrator\Application Data\GDIPFONTCACHEV1.DAT
2006-10-31 09:22 557,056 ----a-w C:\Documents and Settings\Administrator\chatlnk.exe
2005-11-28 12:39 124 ---ha-w C:\Program Files\AppUpdate.log
.
((((((((((((((((((((((((((((( snapshot@2008-05-30_12.21.16.04 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-30 11:12:54 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-09 14:31:44 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2001-09-19 13:32:26 720,896 ----a-w C:\WINDOWS\setupupd\dudrvs\4115762\a3d.dll
+ 2002-08-22 16:57:02 98,752 ----a-w C:\WINDOWS\setupupd\dudrvs\4115762\AEAUDIO.sys
+ 2001-09-19 13:47:12 720,896 ----a-w C:\WINDOWS\setupupd\dudrvs\4115762\Audio3d.dll
+ 2001-10-03 13:14:04 381,200 ----a-w C:\WINDOWS\setupupd\dudrvs\4115762\migrate.dll
+ 2002-08-23 10:13:08 3,744 ----a-w C:\WINDOWS\setupupd\dudrvs\4115762\smsens.sys
+ 2002-08-23 13:46:22 549,672 ----a-w C:\WINDOWS\setupupd\dudrvs\4115762\smwdm.sys
+ 2001-07-14 16:32:24 69,632 ----a-w C:\WINDOWS\setupupd\temp\wsdueng.dll
- 2008-05-28 10:59:02 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-06-09 13:10:47 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-05-28 10:59:02 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-06-09 13:10:47 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-05-28 10:59:02 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-06-09 13:10:47 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2008-05-13 10:25:07 4,212 ---h--w C:\WINDOWS\system32\zllictbl.dat
+ 2008-06-05 07:58:52 4,212 ---h--w C:\WINDOWS\system32\zllictbl.dat
- 2008-05-30 11:13:12 624,244 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\bases\sfdb.dat
+ 2008-06-09 14:32:17 639,140 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\bases\sfdb.dat
- 2008-05-30 09:59:04 9,268,695 ----a-w C:\WINDOWS\system32\ZoneLabs\spyware.dat
+ 2008-06-09 09:59:09 9,374,888 ----a-w C:\WINDOWS\system32\ZoneLabs\spyware.dat
- 2008-04-15 16:07:46 24,064 ----a-w C:\WINDOWS\system32\ZoneLabs\zlqrtdb.dat
+ 2008-06-06 10:14:23 418,816 ----a-w C:\WINDOWS\system32\ZoneLabs\zlqrtdb.dat
+ 2008-06-09 14:32:26 16,384 ----atw C:\WINDOWS\TEMP\Perflib_Perfdata_6f0.dat
+ 2008-06-09 14:32:29 16,384 ----atw C:\WINDOWS\TEMP\Perflib_Perfdata_7c0.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{15C280AC-5C7A-41CC-841A-A21EDB6E6DA9}]
2008-05-30 12:10 86528 --a------ c:\windows\system32\d3drmh.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8C70764E-0C5F-4527-81A0-A47CAC0213A1}]
2008-03-05 11:44 98048 --a------ C:\WINDOWS\system32\d3dima.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PC Suite Tray"="C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" [2008-03-28 11:20 1079296]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-03-13 23:11 919016]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Service Manager.lnk - C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2002-12-17 18:23:32 74308]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableCAD"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ndfioezd]
d3drmh.dll 2008-05-30 12:10 86528 C:\WINDOWS\system32\d3drmh.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.MJPG"= pvmjpg21.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdaptecDirectCD]
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IDA]
--a------ 2005-04-07 13:32 552960 c:\program files\intranets.com\intranets desktop assistant\INDesktop.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WCOLOREAL]
--a------ 2002-02-21 01:40 143360 C:\Program Files\COMPAQ\Coloreal\coloreal.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
--a------ 2006-04-03 18:12 777424 C:\Program Files\Windows Defender\MSASCui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\kav\\kis7.0\\english\\setup.exe"=
R0 miniwenw;miniwenw;C:\WINDOWS\system32\drivers\miniwenw.sys [2004-08-04 13:00]
R2 MSSQL$ABBEYIIOFFLINE;MSSQL$ABBEYIIOFFLINE;C:\Program Files\Abbey\Introducer Internet Offline\MSSQL$ABBEYIIOFFLINE\Binn\sqlservr.exe [2002-12-17 17:26]
R2 MSSQL$LG_LP2;MSSQL$LG_LP2;C:\Program Files\Microsoft SQL Server\MSSQL$LG_LP2\Binn\sqlservr.exe [2002-12-17 18:26]
R2 NMSSvc;Intel(R) NMS;C:\Windows\System32\NMSSvc.exe [2002-03-04 23:35]
R3 NMSCFG;NIC Management Service Configuration Driver;C:\WINDOWS\system32\drivers\NMSCFG.SYS [2002-03-04 23:35]
S3 pccsmcfd;PCCS Mode Change Filter Driver;C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2007-09-17 15:53]
S3 ProcObsrv;Process creation detector.;C:\Program Files\Questionmark\QS\ProcObsrv.sys [2003-08-29 04:00]
S3 SQLAgent$ABBEYIIOFFLINE;SQLAgent$ABBEYIIOFFLINE;C:\Program Files\Abbey\Introducer Internet Offline\MSSQL$ABBEYIIOFFLINE\Binn\sqlagent.EXE [2002-12-17 17:23]
S3 SQLAgent$LG_LP2;SQLAgent$LG_LP2;C:\Program Files\Microsoft SQL Server\MSSQL$LG_LP2\Binn\sqlagent.EXE [2002-12-17 18:23]
S3 upperdev;upperdev;C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2007-11-29 10:39]
S3 UsbserFilt;UsbserFilt;C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2007-11-29 10:39]
*Newly Created Service* - NMSCFG
.
Contents of the 'Scheduled Tasks' folder
"2008-05-30 02:00:00 C:\WINDOWS\Tasks\AdwareAlert Scheduled Scan.job"
- C:\Program Files\AdwareAlert\AdwareAlert.ex
- C:\Program Files\AdwareAlert
"2008-06-09 08:10:00 C:\WINDOWS\Tasks\Download.job"
- C:\Trigold\Download.exe
"2008-05-30 00:31:02 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-06-09 15:35:22
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\Windows\System32\NavLogon.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\ZoneLabs\avsys\ScanningProcess.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\MSSQL7\Binn\sqlservr.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\PROGRA~1\ZONELA~1\ZONEAL~1\MAILFR~1\mantispm.exe
C:\WINDOWS\system32\imapi.exe
.
**************************************************************************
.
Completion time: 2008-06-09 15:41:17 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-09 14:41:00
ComboFix2.txt 2008-06-05 08:42:24
ComboFix3.txt 2008-06-04 14:24:14
ComboFix4.txt 2008-06-02 08:28:43
ComboFix5.txt 2008-05-30 11:22:53
Pre-Run: 23,408,128,000 bytes free
Post-Run: 23,416,172,544 bytes free
191 --- E O F --- 2008-05-14 15:46:27