jsmitty
2008-05-21, 02:50
I am trying to follow up on a previous thread (http://forums.spybot.info/showthread.php?t=28015) I made that was archived due to not responding.
I was asked to run combo fix, and post the log.
ComboFix 08-05-20.1 - Jacob 2008-05-20 16:14:01.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.653 [GMT -7:00]
Running from: C:\Documents and Settings\Jacob\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Jacob\Application Data\SpamBlockerUtility_Icons
C:\Documents and Settings\Jacob\Application Data\SpamBlockerUtility_Icons\Repair+System+Registry.ico
C:\Documents and Settings\Jacob\Application Data\SpamBlockerUtility_Icons\Software_Online_8.ico
C:\Documents and Settings\Stacey\Application Data\ShoppingReport
C:\Documents and Settings\Stacey\Application Data\ShoppingReport\cs\Config.xml
C:\Documents and Settings\Stacey\Application Data\ShoppingReport\cs\db\Aliases.dbs
C:\Documents and Settings\Stacey\Application Data\ShoppingReport\cs\db\Sites.dbs
C:\Documents and Settings\Stacey\Application Data\ShoppingReport\cs\dwld\WhiteList.xip
C:\Documents and Settings\Stacey\Application Data\ShoppingReport\cs\report\aggr_storage.xml
C:\Documents and Settings\Stacey\Application Data\ShoppingReport\cs\report\send_storage.xml
C:\Documents and Settings\Stacey\Application Data\ShoppingReport\cs\res1\WhiteList.dbs
C:\Documents and Settings\Stacey\Application Data\SpamBlockerUtility_Icons
C:\Documents and Settings\Stacey\Application Data\SpamBlockerUtility_Icons\3bSoftware_icon_1.ico
C:\Documents and Settings\Stacey\Application Data\SpamBlockerUtility_Icons\Repair+System+Registry.ico
C:\Documents and Settings\Stacey\Application Data\WeatherDPA
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\temp\tn3
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\drivers\mcstrmm.sys
C:\WINDOWS\system32\ioabjugm.dll
C:\WINDOWS\system32\mgujbaoi.ini
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\MSuCdMoq.ini
C:\WINDOWS\system32\MSuCdMoq.ini2
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\ssqnlIxu.dll
C:\WINDOWS\system32\uxIlnqss.ini
C:\WINDOWS\system32\uxIlnqss.ini2
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_MCSTRMM
-------\Service_mcstrmm
((((((((((((((((((((((((( Files Created from 2008-04-20 to 2008-05-20 )))))))))))))))))))))))))))))))
.
2008-05-13 18:18 . 2008-05-13 18:18 <DIR> d-------- C:\Documents and Settings\Jacob\Application Data\Malwarebytes
2008-05-13 18:17 . 2008-05-13 18:17 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-05-13 18:17 . 2008-05-13 18:17 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-05-13 18:17 . 2008-05-05 20:46 27,048 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-05-13 18:17 . 2008-05-05 20:46 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-05-13 14:09 . 2008-05-13 14:09 <DIR> d-------- C:\Program Files\Trend Micro
2008-05-13 13:48 . 2008-05-13 13:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-05-13 13:47 . 2008-05-13 13:47 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-05-08 15:03 . 2008-05-08 15:03 0 --a------ C:\drivers
2008-05-08 15:02 . 2008-05-08 15:02 0 --a------ C:\system32
2008-05-07 07:19 . 2008-05-07 07:19 <DIR> d--hs---- C:\Documents and Settings\TEMP\!
2008-05-07 07:18 . 2008-05-08 13:18 <DIR> d-------- C:\Documents and Settings\TEMP
2008-05-06 21:04 . 2008-05-13 16:29 <DIR> dr-h----- C:\$VAULT$.AVG
2008-05-06 19:25 . 2008-05-06 19:41 <DIR> d--hs---- C:\Documents and Settings\Jacob\!
2008-05-06 19:23 . 2008-05-06 21:04 <DIR> d-------- C:\WINDOWS\system32\xdb4
2008-05-06 19:23 . 2008-05-13 16:29 <DIR> d-------- C:\WINDOWS\system32\din3
2008-05-06 19:23 . 2008-05-06 19:23 <DIR> d-------- C:\WINDOWS\system32\cNF
2008-05-06 19:23 . 2008-05-06 21:04 <DIR> d-------- C:\WINDOWS\system32\cdTMP
2008-05-06 19:23 . 2008-05-13 16:29 <DIR> d-------- C:\WINDOWS\system32\bkEur05
2008-05-06 19:23 . 2008-05-06 21:04 <DIR> d-------- C:\WINDOWS\system32\12033
2008-05-06 19:23 . 2008-05-06 19:23 <DIR> d-------- C:\Temp\maxsv15
2008-04-20 15:18 . 2008-05-08 14:34 1,768 --a------ C:\WINDOWS\wininit.ini
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-15 15:00 --------- d-----w C:\Documents and Settings\Jacob\Application Data\AVG7
2008-05-14 10:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-05-13 20:27 --------- d-----w C:\Documents and Settings\Jacob\Application Data\LimeWire
2008-05-08 22:26 --------- d-----w C:\Documents and Settings\Stacey\Application Data\AVG7
2008-04-20 22:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\SBUSA
2008-04-10 17:04 --------- d-----w C:\Program Files\Common Files\Adobe
2008-04-04 22:22 --------- d-----w C:\Program Files\Common Files\Hewlett-Packard
2008-04-04 22:21 --------- d-----w C:\Program Files\HP
2008-03-29 23:07 --------- d-----w C:\Documents and Settings\Stacey\Application Data\Move Networks
2008-03-28 12:10 --------- d-----w C:\Program Files\Common Files\Real
2008-03-28 12:09 8,413 ----a-w C:\WINDOWS\system32\drivers\mcstrm.sys
2008-03-28 12:09 --------- d-----w C:\Program Files\Rhapsody
2008-03-28 12:08 --------- d-----w C:\Program Files\Real
2008-03-28 11:34 --------- d-----w C:\Documents and Settings\Jacob\Application Data\Apple Computer
2008-03-28 11:03 --------- d-----w C:\Program Files\iTunes
2008-03-28 11:02 --------- d-----w C:\Program Files\QuickTime
2008-03-28 11:02 --------- d-----w C:\Program Files\Apple Software Update
2008-03-28 11:02 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
2008-03-28 10:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-03-28 10:42 --------- d-----w C:\Documents and Settings\Stacey\Application Data\LimeWire
2008-03-28 06:35 --------- d-----w C:\Documents and Settings\Stacey\Application Data\Apple Computer
2008-03-27 10:09 --------- d-----w C:\Program Files\iPod
2008-03-27 10:06 --------- d-----w C:\Program Files\Common Files\Apple
2008-03-27 09:43 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-03-26 21:48 --------- d-----w C:\Program Files\BurnAware Free Edition
2008-03-24 12:40 --------- d-----w C:\Program Files\Java
2008-03-24 12:38 --------- d-----w C:\Program Files\Common Files\Java
2008-03-24 01:06 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg7
2008-03-24 01:03 --------- d-----w C:\Documents and Settings\LocalService\Application Data\AVG7
2008-03-24 01:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BA3CA6BC-FEA1-4654-9F12-BAFC4F8F1381}]
C:\WINDOWS\system32\qoMdCuSM.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 16:56 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 08:00 33648]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2004-02-10 12:55 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2004-02-10 12:51 118784]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-19 14:10 267048]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-02-01 00:13 385024]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-03-23 18:03 219136]
C:\Documents and Settings\Jacob\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2007-08-24 05:45:42 101784]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vtUKEwTK]
vtUKEwTK.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Rhapsody\\rhapsody.exe"=
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-20 16:33:28
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\verclsid.exe
.
**************************************************************************
.
Completion time: 2008-05-20 16:42:42 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-20 23:42:38
Pre-Run: 63,808,196,608 bytes free
Post-Run: 64,025,276,416 bytes free
161 --- E O F --- 2008-05-14 10:07:18
I was asked to run combo fix, and post the log.
ComboFix 08-05-20.1 - Jacob 2008-05-20 16:14:01.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.653 [GMT -7:00]
Running from: C:\Documents and Settings\Jacob\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Jacob\Application Data\SpamBlockerUtility_Icons
C:\Documents and Settings\Jacob\Application Data\SpamBlockerUtility_Icons\Repair+System+Registry.ico
C:\Documents and Settings\Jacob\Application Data\SpamBlockerUtility_Icons\Software_Online_8.ico
C:\Documents and Settings\Stacey\Application Data\ShoppingReport
C:\Documents and Settings\Stacey\Application Data\ShoppingReport\cs\Config.xml
C:\Documents and Settings\Stacey\Application Data\ShoppingReport\cs\db\Aliases.dbs
C:\Documents and Settings\Stacey\Application Data\ShoppingReport\cs\db\Sites.dbs
C:\Documents and Settings\Stacey\Application Data\ShoppingReport\cs\dwld\WhiteList.xip
C:\Documents and Settings\Stacey\Application Data\ShoppingReport\cs\report\aggr_storage.xml
C:\Documents and Settings\Stacey\Application Data\ShoppingReport\cs\report\send_storage.xml
C:\Documents and Settings\Stacey\Application Data\ShoppingReport\cs\res1\WhiteList.dbs
C:\Documents and Settings\Stacey\Application Data\SpamBlockerUtility_Icons
C:\Documents and Settings\Stacey\Application Data\SpamBlockerUtility_Icons\3bSoftware_icon_1.ico
C:\Documents and Settings\Stacey\Application Data\SpamBlockerUtility_Icons\Repair+System+Registry.ico
C:\Documents and Settings\Stacey\Application Data\WeatherDPA
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\temp\tn3
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\drivers\mcstrmm.sys
C:\WINDOWS\system32\ioabjugm.dll
C:\WINDOWS\system32\mgujbaoi.ini
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\MSuCdMoq.ini
C:\WINDOWS\system32\MSuCdMoq.ini2
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\ssqnlIxu.dll
C:\WINDOWS\system32\uxIlnqss.ini
C:\WINDOWS\system32\uxIlnqss.ini2
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_MCSTRMM
-------\Service_mcstrmm
((((((((((((((((((((((((( Files Created from 2008-04-20 to 2008-05-20 )))))))))))))))))))))))))))))))
.
2008-05-13 18:18 . 2008-05-13 18:18 <DIR> d-------- C:\Documents and Settings\Jacob\Application Data\Malwarebytes
2008-05-13 18:17 . 2008-05-13 18:17 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-05-13 18:17 . 2008-05-13 18:17 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-05-13 18:17 . 2008-05-05 20:46 27,048 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-05-13 18:17 . 2008-05-05 20:46 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-05-13 14:09 . 2008-05-13 14:09 <DIR> d-------- C:\Program Files\Trend Micro
2008-05-13 13:48 . 2008-05-13 13:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-05-13 13:47 . 2008-05-13 13:47 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-05-08 15:03 . 2008-05-08 15:03 0 --a------ C:\drivers
2008-05-08 15:02 . 2008-05-08 15:02 0 --a------ C:\system32
2008-05-07 07:19 . 2008-05-07 07:19 <DIR> d--hs---- C:\Documents and Settings\TEMP\!
2008-05-07 07:18 . 2008-05-08 13:18 <DIR> d-------- C:\Documents and Settings\TEMP
2008-05-06 21:04 . 2008-05-13 16:29 <DIR> dr-h----- C:\$VAULT$.AVG
2008-05-06 19:25 . 2008-05-06 19:41 <DIR> d--hs---- C:\Documents and Settings\Jacob\!
2008-05-06 19:23 . 2008-05-06 21:04 <DIR> d-------- C:\WINDOWS\system32\xdb4
2008-05-06 19:23 . 2008-05-13 16:29 <DIR> d-------- C:\WINDOWS\system32\din3
2008-05-06 19:23 . 2008-05-06 19:23 <DIR> d-------- C:\WINDOWS\system32\cNF
2008-05-06 19:23 . 2008-05-06 21:04 <DIR> d-------- C:\WINDOWS\system32\cdTMP
2008-05-06 19:23 . 2008-05-13 16:29 <DIR> d-------- C:\WINDOWS\system32\bkEur05
2008-05-06 19:23 . 2008-05-06 21:04 <DIR> d-------- C:\WINDOWS\system32\12033
2008-05-06 19:23 . 2008-05-06 19:23 <DIR> d-------- C:\Temp\maxsv15
2008-04-20 15:18 . 2008-05-08 14:34 1,768 --a------ C:\WINDOWS\wininit.ini
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-15 15:00 --------- d-----w C:\Documents and Settings\Jacob\Application Data\AVG7
2008-05-14 10:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-05-13 20:27 --------- d-----w C:\Documents and Settings\Jacob\Application Data\LimeWire
2008-05-08 22:26 --------- d-----w C:\Documents and Settings\Stacey\Application Data\AVG7
2008-04-20 22:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\SBUSA
2008-04-10 17:04 --------- d-----w C:\Program Files\Common Files\Adobe
2008-04-04 22:22 --------- d-----w C:\Program Files\Common Files\Hewlett-Packard
2008-04-04 22:21 --------- d-----w C:\Program Files\HP
2008-03-29 23:07 --------- d-----w C:\Documents and Settings\Stacey\Application Data\Move Networks
2008-03-28 12:10 --------- d-----w C:\Program Files\Common Files\Real
2008-03-28 12:09 8,413 ----a-w C:\WINDOWS\system32\drivers\mcstrm.sys
2008-03-28 12:09 --------- d-----w C:\Program Files\Rhapsody
2008-03-28 12:08 --------- d-----w C:\Program Files\Real
2008-03-28 11:34 --------- d-----w C:\Documents and Settings\Jacob\Application Data\Apple Computer
2008-03-28 11:03 --------- d-----w C:\Program Files\iTunes
2008-03-28 11:02 --------- d-----w C:\Program Files\QuickTime
2008-03-28 11:02 --------- d-----w C:\Program Files\Apple Software Update
2008-03-28 11:02 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
2008-03-28 10:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-03-28 10:42 --------- d-----w C:\Documents and Settings\Stacey\Application Data\LimeWire
2008-03-28 06:35 --------- d-----w C:\Documents and Settings\Stacey\Application Data\Apple Computer
2008-03-27 10:09 --------- d-----w C:\Program Files\iPod
2008-03-27 10:06 --------- d-----w C:\Program Files\Common Files\Apple
2008-03-27 09:43 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-03-26 21:48 --------- d-----w C:\Program Files\BurnAware Free Edition
2008-03-24 12:40 --------- d-----w C:\Program Files\Java
2008-03-24 12:38 --------- d-----w C:\Program Files\Common Files\Java
2008-03-24 01:06 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg7
2008-03-24 01:03 --------- d-----w C:\Documents and Settings\LocalService\Application Data\AVG7
2008-03-24 01:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BA3CA6BC-FEA1-4654-9F12-BAFC4F8F1381}]
C:\WINDOWS\system32\qoMdCuSM.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 16:56 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 08:00 33648]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2004-02-10 12:55 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2004-02-10 12:51 118784]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-19 14:10 267048]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-02-01 00:13 385024]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-03-23 18:03 219136]
C:\Documents and Settings\Jacob\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2007-08-24 05:45:42 101784]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vtUKEwTK]
vtUKEwTK.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Rhapsody\\rhapsody.exe"=
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-20 16:33:28
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\verclsid.exe
.
**************************************************************************
.
Completion time: 2008-05-20 16:42:42 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-20 23:42:38
Pre-Run: 63,808,196,608 bytes free
Post-Run: 64,025,276,416 bytes free
161 --- E O F --- 2008-05-14 10:07:18