Hi again, when i ran combofix it tells me that avg is running but the only reference i can find of avg is 1 folder in program files with only a few files in it, it won't allow me to uninstall it or turn it off, it seemingly doesn't exist??
ComboFix 09-11-24.04 - Daddy 26/11/2009 10:28.3.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3582.3031 [GMT 11:00]
Running from: c:\documents and settings\Daddy\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Daddy\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((( Files Created from 2009-10-25 to 2009-11-25 )))))))))))))))))))))))))))))))
.
2009-11-25 23:16 . 2009-11-25 23:16 -------- d-----w- c:\program files\Java
2009-11-25 23:15 . 2009-11-25 23:15 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2009-11-25 23:15 . 2009-11-25 23:15 152576 ----a-w- c:\documents and settings\Daddy\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-11-25 22:54 . 2009-10-10 07:07 38208 ----a-w- c:\documents and settings\Daddy\Application Data\Macromedia\Flash Player\
www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-11-25 22:54 . 2009-10-10 07:07 38208 ----a-w- c:\documents and settings\Default User\Application Data\Macromedia\Flash Player\
www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-11-25 22:54 . 2009-11-25 22:54 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-11-25 22:52 . 2009-11-25 22:52 86016 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2009-11-25 22:52 . 2009-11-25 23:14 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-11-25 09:00 . 2009-11-25 09:00 389120 ----a-w- c:\windows\system32\CF26019.exe
2009-11-25 08:17 . 2009-11-25 08:17 85504 ----a-w- c:\program files\Inherit.exe
2009-11-15 22:11 . 2009-11-24 11:31 -------- d--h--w- c:\windows\PIF
2009-11-15 22:01 . 2009-11-15 22:01 -------- d-----w- c:\documents and settings\Daddy\Application Data\Malwarebytes
2009-11-15 22:01 . 2009-09-10 03:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-11-15 22:01 . 2009-11-15 22:14 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-11-15 22:01 . 2009-11-15 22:01 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-11-15 22:01 . 2009-09-10 03:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-11-15 05:54 . 2009-11-15 05:54 -------- d-----w- c:\program files\Trend Micro
2009-11-08 11:22 . 2009-11-15 04:55 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-11-08 09:57 . 2009-11-08 09:57 79488 ----a-w- c:\documents and settings\Daddy\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-11-08 09:27 . 2009-11-08 09:27 -------- d-----w- c:\windows\system32\wbem\Repository
2009-11-08 09:21 . 2009-11-08 09:21 -------- d-----w- c:\documents and settings\Daddy\Application Data\AVG8
2009-11-08 09:21 . 2009-11-08 09:21 -------- d-----w- C:\$AVG8.VAULT$
2009-11-04 03:08 . 2009-11-04 03:09 -------- d-----w- c:\documents and settings\Mummy\Application Data\MissTeriTale3
2009-11-03 11:25 . 2009-11-03 11:28 -------- d-----w- C:\$AVG
2009-11-03 11:24 . 2009-11-07 06:19 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-11-03 11:24 . 2009-11-08 09:24 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2009-11-03 01:39 . 2009-11-03 01:39 -------- d-----w- C:\ProgramData
2009-11-02 21:44 . 2009-10-04 07:51 3510552 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgui.exe
2009-11-01 11:36 . 2009-11-01 11:36 -------- d-----w- c:\documents and settings\Mummy\Application Data\Magic Academy 2
2009-10-28 03:52 . 2009-10-28 03:52 -------- d-----w- c:\documents and settings\Mummy\Local Settings\Application Data\STARGAZE_IMAGE_CACHE
2009-10-28 03:52 . 2009-10-28 03:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Alawar Stargaze
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-25 23:16 . 2008-12-03 07:39 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-11-25 22:56 . 2008-07-10 12:14 -------- d-----w- c:\program files\Common Files\Adobe
2009-11-25 09:29 . 2009-09-13 06:45 -------- d-----w- c:\program files\iWin Games
2009-11-25 09:29 . 2008-09-25 03:40 -------- d-----w- c:\program files\iWin
2009-11-25 09:13 . 2008-07-08 03:05 -------- d-----w- c:\program files\AVG
2009-11-25 09:09 . 2008-07-08 10:36 24056 ----a-w- c:\documents and settings\Daddy\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-15 05:04 . 2008-07-13 04:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-11-08 11:18 . 2008-07-30 07:00 -------- d-----w- c:\documents and settings\All Users\Application Data\WildTangent
2009-11-08 11:10 . 2008-08-18 05:23 -------- d-----w- c:\program files\MSN Games
2009-11-08 11:10 . 2008-09-08 06:35 -------- d-----w- c:\program files\Super Granny 3
2009-11-08 11:10 . 2008-12-28 08:05 -------- d-----w- c:\program files\Alawar
2009-11-08 11:09 . 2009-01-22 04:09 -------- d-----w- c:\program files\Snowy Treasure Hunter 3
2009-11-08 11:09 . 2008-09-08 06:35 -------- d-----w- c:\program files\Snowy Treasure Hunter 2
2009-11-08 11:09 . 2008-09-25 02:39 -------- d-----w- c:\program files\MumboJumbo
2009-11-08 11:08 . 2008-09-25 03:44 -------- d-----w- c:\program files\iWin.com
2009-11-08 11:05 . 2008-09-25 03:04 -------- d-----w- c:\program files\Fatman Adventures
2009-11-08 11:04 . 2008-09-25 02:37 -------- d-----w- c:\program files\Double Digger
2009-11-08 11:03 . 2008-09-01 02:56 -------- d-----w- c:\program files\Brave Dwarves Back For Treasures
2009-11-08 11:02 . 2008-11-23 07:45 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-11-08 10:56 . 2008-07-13 04:48 -------- d-----w- c:\program files\fuck off
2009-11-07 11:19 . 2008-07-08 03:05 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-11-04 03:44 . 2008-08-18 05:23 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-11-03 11:24 . 2008-07-08 03:06 12464 ----a-w- c:\windows\system32\avgrsstx(2).dll
2009-10-23 02:39 . 2008-12-15 01:24 -------- d-----w- c:\documents and settings\Mummy\Application Data\EleFun Games
2009-10-19 02:09 . 2009-09-30 02:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Merscom
2009-10-19 01:08 . 2009-10-19 01:08 -------- d-----w- c:\documents and settings\Mummy\Application Data\Alawar
2009-10-19 01:00 . 2009-01-19 22:38 -------- d-----w- c:\documents and settings\Mummy\Application Data\Meridian93
2009-10-19 00:24 . 2009-10-19 00:24 -------- d-----w- c:\documents and settings\All Users\Application Data\MythPeople
2009-10-16 23:27 . 2009-10-16 23:28 2025752 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgtray.exe
2009-10-13 03:13 . 2009-10-13 03:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Becky Brogan
2009-10-09 02:20 . 2009-10-09 02:20 -------- d-----w- c:\documents and settings\All Users\Application Data\SOS
2009-10-06 10:42 . 2009-10-06 10:42 152576 ----a-w- c:\documents and settings\Daddy\Application Data\Sun\Java\jre1.6.0_15\lzma.dll
2009-10-04 07:51 . 2009-10-20 22:30 2064152 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcorex.dll
2009-10-04 07:49 . 2009-10-08 06:28 1142552 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgupd.exe
2009-09-30 02:05 . 2009-09-30 02:05 -------- d-----w- c:\documents and settings\Mummy\Application Data\Merscom
2009-09-11 14:18 . 2006-02-28 12:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-04 21:03 . 2006-02-28 12:00 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-29 08:08 . 2006-02-28 12:00 916480 ------w- c:\windows\system32\wininet.dll
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of c:\program files\fuck off ----
2008-07-13 04:48 . 2008-01-28 01:43 5146448 --sha-r- c:\program files\fuck off\LGLVMLYWNBLRPT.scr
2008-07-13 04:48 . 2008-07-30 04:45 4891984 --sha-r- c:\program files\fuck off\SpybotSD.exe
((((((((((((((((((((((((((((( SnapShot@2009-11-25_09.37.16 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-11-25 23:42 . 2009-11-25 23:42 16384 c:\windows\temp\Perflib_Perfdata_7c0.dat
- 2008-07-08 10:13 . 2009-07-14 11:03 46080 c:\windows\system32\tzchange.exe
+ 2008-07-08 10:13 . 2009-10-28 15:07 46080 c:\windows\system32\tzchange.exe
+ 2009-11-25 22:59 . 2009-11-25 22:59 89101 c:\windows\system32\Macromed\Flash\uninstall_activeX.exe
+ 2009-11-25 22:58 . 2009-11-25 22:58 87618 c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
- 2008-07-11 11:44 . 2008-06-17 06:11 94208 c:\windows\system32\Adobe\Shockwave 11\SwMenu.dll
+ 2009-10-29 05:27 . 2009-10-29 05:27 94208 c:\windows\system32\Adobe\Shockwave 11\SwMenu.dll
+ 2009-10-29 05:45 . 2009-10-29 05:45 67000 c:\windows\system32\Adobe\Director\SWDNLD.EXE
+ 2009-11-25 22:54 . 2009-11-25 22:54 21504 c:\windows\Installer\69efd.msi
+ 2009-11-25 22:54 . 2009-11-25 22:54 27648 c:\windows\Installer\69ef7.msi
+ 2009-11-25 10:17 . 2009-11-25 10:17 32768 c:\windows\Installer\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}\icon.exe
- 2008-07-11 11:44 . 2008-06-17 06:13 9216 c:\windows\system32\Adobe\Shockwave 11\DynaPlayer.dll
+ 2009-10-29 05:29 . 2009-10-29 05:29 9216 c:\windows\system32\Adobe\Shockwave 11\DynaPlayer.dll
+ 2009-11-25 23:16 . 2009-11-25 23:16 149280 c:\windows\system32\javaws.exe
+ 2009-11-25 23:16 . 2009-11-25 23:16 145184 c:\windows\system32\javaw.exe
+ 2009-11-25 23:16 . 2009-11-25 23:16 145184 c:\windows\system32\java.exe
+ 2009-10-29 04:55 . 2009-10-29 04:55 132472 c:\windows\system32\Adobe\Shockwave 11\SYMCCHECKER.DLL
+ 2009-10-29 05:27 . 2009-10-29 05:27 114688 c:\windows\system32\Adobe\Shockwave 11\SwInit.exe
- 2008-07-11 11:44 . 2008-06-17 06:15 114688 c:\windows\system32\Adobe\Shockwave 11\SwInit.exe
+ 2009-10-29 05:43 . 2009-10-29 05:43 464312 c:\windows\system32\Adobe\Shockwave 11\SwHelper_1152602.exe
+ 2009-10-29 05:29 . 2009-10-29 05:29 446464 c:\windows\system32\Adobe\Shockwave 11\Proj.dll
- 2008-07-11 11:44 . 2008-06-17 06:15 446464 c:\windows\system32\Adobe\Shockwave 11\Proj.dll
+ 2009-10-29 05:28 . 2009-10-29 05:28 372736 c:\windows\system32\Adobe\Shockwave 11\Plugin.dll
+ 2009-10-29 04:55 . 2009-10-29 04:55 713216 c:\windows\system32\Adobe\Shockwave 11\gi.dll
+ 2009-10-29 05:26 . 2009-10-29 05:26 503808 c:\windows\system32\Adobe\Shockwave 11\Control.dll
+ 2009-10-29 05:44 . 2009-10-29 05:44 210360 c:\windows\system32\Adobe\Director\SwDir.dll
+ 2009-10-29 05:28 . 2009-10-29 05:28 131072 c:\windows\system32\Adobe\Director\np32dsw.dll
+ 2009-11-25 10:17 . 2009-11-25 10:17 429568 c:\windows\Installer\26248e.msi
+ 2009-07-20 13:03 . 2009-07-20 13:03 1348432 c:\windows\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9876.0_x-ww_a621d1d5\msxml4.dll
+ 2008-09-09 11:00 . 2009-07-30 23:05 1372672 c:\windows\system32\msxml6.dll
+ 2009-07-20 13:05 . 2009-07-20 13:05 1348432 c:\windows\system32\msxml4.dll
+ 2006-02-28 12:00 . 2009-07-31 04:35 1172480 c:\windows\system32\msxml3.dll
+ 2008-09-09 11:00 . 2009-07-30 23:05 1372672 c:\windows\system32\dllcache\msxml6.dll
+ 2008-11-12 06:22 . 2009-07-31 04:35 1172480 c:\windows\system32\dllcache\msxml3.dll
+ 2009-10-29 05:01 . 2009-10-29 05:01 1011712 c:\windows\system32\Adobe\Shockwave 11\iml32.dll
- 2008-07-11 11:44 . 2008-06-17 05:36 1798144 c:\windows\system32\Adobe\Shockwave 11\dirapi.dll
+ 2009-10-29 05:05 . 2009-10-29 05:05 1798144 c:\windows\system32\Adobe\Shockwave 11\dirapi.dll
+ 2009-11-25 22:56 . 2009-11-25 22:56 3940352 c:\windows\Installer\69f03.msi
+ 2009-11-25 23:16 . 2009-11-25 23:16 1757696 c:\windows\Installer\25ee3.msi
+ 2009-07-17 09:12 . 2009-07-17 09:12 1962160 c:\windows\Downloaded Program Files\CONFLICT.1\FP_AX_CAB_INSTALLER.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 152872]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-07-19 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-09-17 13574144]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-02-07 488984]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2003-12-04 176128]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 241664]
"HPHmon05"="c:\windows\system32\hphmon05.exe" [2004-02-02 495616]
"DiscWizardMonitor.exe"="c:\program files\Seagate\DiscWizard\DiscWizardMonitor.exe" [2008-06-24 1325848]
"AcronisTimounterMonitor"="c:\program files\Seagate\DiscWizard\TimounterMonitor.exe" [2008-06-24 904768]
"Seagate Scheduler2 Service"="c:\program files\Common Files\Seagate\Schedule2\schedhlp.exe" [2008-06-24 136472]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-09-17 86016]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-02 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-11-25 149280]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2008-09-17 1657376]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2007-06-13 16377344]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\Daddy\Start Menu\Programs\Startup\
Webshots.lnk - c:\program files\Webshots\Launcher.exe [2008-7-20 157000]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk.disabled [2008-11-2 1757]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-23 00:14 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AVG Anti-Spyware Guard]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" /background
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"HPHUPD05"=c:\program files\Hewlett-Packard\{D946675D-1D6C-4dc8-9E0D-B4B8EAA30EAA}\hphupd05.exe
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam10\QuickCam10.exe" /hide
"Name of App"=c:\program files\SAMSUNG\FW LiveUpdate\FWManager.exe r
"NeroFilterCheck"=c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe"
"HP Software Update"="c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"c:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\iWin Games\\iWinGames.exe"=
"c:\\Program Files\\iWin Games\\WebUpdater.exe"=
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [8/07/2008 2:06 PM 335240]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [8/07/2008 2:06 PM 108552]
R2 iWinTrusted;iWinTrusted;c:\program files\iWin Games\iWinTrusted.exe [3/09/2009 4:30 AM 78104]
R2 SgtSch2Svc;Seagate Scheduler2 Service;c:\program files\Common Files\Seagate\Schedule2\schedul2.exe [24/06/2008 7:56 PM 431384]
S2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe --> c:\progra~1\AVG\AVG8\avgemc.exe [?]
S2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [12/07/2008 1:43 PM 297752]
S3 RSUSBSTOR;RTS5121.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RTS5121.sys [28/07/2009 8:39 PM 152576]
S3 Rts516xIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys --> c:\windows\system32\DRIVERS\Rts516xIR.sys [?]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\d:\ntglm7x.sys --> d:\NTGLM7X.sys [?]
.
Contents of the 'Scheduled Tasks' folder
2009-11-16 c:\windows\Tasks\HP Usg Daily.job
- c:\program files\Hewlett-Packard\{D946675D-1D6C-4dc8-9E0D-B4B8EAA30EAA}\pexpress\hphped05.exe [2004-01-07 05:05]
2009-11-15 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SpybotSD.exe [2009-11-08 04:31]
2009-11-15 c:\windows\Tasks\Spybot - Search & Destroy Updater - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SDUpdate.exe [2009-11-08 04:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.au/
uInternet Connection Wizard,ShellNext = hxxp://redirect.zonelabs.com/redirect/route?oem=1025&prod=0&mode=1&app=inclient&version=7.0.473.000&lang=en&locale=en-AU&date=-86400&link_id=4&dest=try_product&lic=j5hvqhisiu3s4he7bhx644bu4g0
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: bigpond.com\my
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-11-26 10:47
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(896)
c:\windows\system32\relog_ap.dll
- - - - - - - > 'explorer.exe'(3832)
c:\windows\system32\WININET.dll
c:\program files\Common Files\Ahead\Lib\NeroSearchBar.dll
c:\program files\Common Files\Ahead\Lib\MFC71U.DLL
c:\program files\Common Files\Ahead\Lib\BCGCBPRO860un71.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Nokia\Nokia PC Suite 7\phonebrowser.dll
c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_eng.nlr
c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\AVG\AVG8\avgrsx.exe
c:\windows\System32\SCardSvr.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\nvsvc32.exe
c:\windows\system32\RUNDLL32.EXE
c:\program files\Common Files\Ahead\Lib\NMIndexingService.exe
c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
c:\progra~1\Webshots\webshots.scr
c:\program files\HP\hpcoretech\comp\hptskmgr.exe
.
**************************************************************************
.
Completion time: 2009-11-26 10:55 - machine was rebooted
ComboFix-quarantined-files.txt 2009-11-25 23:55
ComboFix2.txt 2009-11-25 09:45
ComboFix3.txt 2008-09-16 09:41
Pre-Run: 13,963,673,600 bytes free
Post-Run: 13,940,662,272 bytes free
- - End Of File - - EDCB3423938CBFC4E7ED7ACE53AEEE2E