New CF log and HJT to follow
Thanks __RiP_ChAiN_. I actaully downloaded CF before I changed the HJT settings. I didn't run it though until when you instructed me to.
Here are my logs: HJT in seperate reply.
CF:
ComboFix 08-04-02.1 - Danny 2008-04-04 11:22:05.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.380 [GMT 1:00]
Running from: D:\Documents and Settings\Danny\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\a.bat
C:\WINDOWS\base64.tmp
C:\WINDOWS\bdn.com
C:\WINDOWS\FVProtect.exe
C:\WINDOWS\Installer\{d76ae28d-da07-4cec-809e-b205275ad830}\WinDrive.dll
C:\WINDOWS\iTunesMusic.exe
C:\WINDOWS\mssecu.exe
C:\WINDOWS\system32\driver
C:\WINDOWS\system32\driver\bcm43xx.cat
C:\WINDOWS\system32\driver\RNDISMP.sys
C:\WINDOWS\system32\driver\RNDISMPK.sys
C:\WINDOWS\system32\driver\usb8023.sys
C:\WINDOWS\system32\driver\usb8023k.sys
C:\WINDOWS\system32\MabryObj.dll
C:\WINDOWS\system32akttzn.exe
C:\WINDOWS\system32anticipator.dll
C:\WINDOWS\system32awtoolb.dll
C:\WINDOWS\system32bdn.com
C:\WINDOWS\system32bsva-egihsg52.exe
C:\WINDOWS\system32dpcproxy.exe
C:\WINDOWS\system32emesx.dll
C:\WINDOWS\system32h@tkeysh@@k.dll
C:\WINDOWS\system32hoproxy.dll
C:\WINDOWS\system32hxiwlgpm.dat
C:\WINDOWS\system32hxiwlgpm.exe
C:\WINDOWS\system32medup012.dll
C:\WINDOWS\system32medup020.dll
C:\WINDOWS\system32msgp.exe
C:\WINDOWS\system32msnbho.dll
C:\WINDOWS\system32mssecu.exe
C:\WINDOWS\system32msvchost.exe
C:\WINDOWS\system32mtr2.exe
C:\WINDOWS\system32mwin32.exe
C:\WINDOWS\system32netode.exe
C:\WINDOWS\system32newsd32.exe
C:\WINDOWS\system32ps1.exe
C:\WINDOWS\system32psof1.exe
C:\WINDOWS\system32psoft1.exe
C:\WINDOWS\system32regc64.dll
C:\WINDOWS\system32regm64.dll
C:\WINDOWS\system32Rundl1.exe
C:\WINDOWS\system32smp
C:\WINDOWS\system32smp\msrc.exe
C:\WINDOWS\system32sncntr.exe
C:\WINDOWS\system32ssurf022.dll
C:\WINDOWS\system32ssvchost.com
C:\WINDOWS\system32ssvchost.exe
C:\WINDOWS\system32sysreq.exe
C:\WINDOWS\system32taack.dat
C:\WINDOWS\system32taack.exe
C:\WINDOWS\system32temp#01.exe
C:\WINDOWS\system32thun.dll
C:\WINDOWS\system32thun32.dll
C:\WINDOWS\system32VBIEWER.OCX
C:\WINDOWS\system32vbsys2.dll
C:\WINDOWS\system32vcatchpi.dll
C:\WINDOWS\system32winlogonpc.exe
C:\WINDOWS\system32winsystem.exe
C:\WINDOWS\system32WINWGPX.EXE
C:\WINDOWS\userconfig9x.dll
C:\WINDOWS\winsystem.exe
C:\WINDOWS\zip1.tmp
C:\WINDOWS\zip2.tmp
C:\WINDOWS\zip3.tmp
C:\WINDOWS\zipped.tmp
D:\Documents and Settings\A nother\Desktopblackbird.jpg
D:\Documents and Settings\A nother\DesktopEditorFKWP1.5.exe
D:\Documents and Settings\A nother\DesktopEditorFKWP2.0.exe
D:\Documents and Settings\A nother\Desktopfilemanagerclient.exe
D:\Documents and Settings\A nother\Desktopfkwp1.5.exe
D:\Documents and Settings\A nother\Desktopfkwp2.0.exe
D:\Documents and Settings\A nother\Desktopfwebd.exe
D:\Documents and Settings\A nother\DesktopFWebdEditor.exe
D:\Documents and Settings\A nother\DesktopTrojan.Win32.BlackBird.exe
D:\Documents and Settings\A nother\Desktopvirii
D:\Documents and Settings\Danny\Desktop\Error Cleaner.url
D:\Documents and Settings\Danny\Desktop\Privacy Protector.url
D:\Documents and Settings\Danny\Desktop\Spyware&Malware Protection.url
D:\Documents and Settings\Danny\Desktopblackbird.jpg
D:\Documents and Settings\Danny\DesktopEditorFKWP1.5.exe
D:\Documents and Settings\Danny\DesktopEditorFKWP2.0.exe
D:\Documents and Settings\Danny\Desktopfilemanagerclient.exe
D:\Documents and Settings\Danny\Desktopfkwp1.5.exe
D:\Documents and Settings\Danny\Desktopfkwp2.0.exe
D:\Documents and Settings\Danny\Desktopfwebd.exe
D:\Documents and Settings\Danny\DesktopFWebdEditor.exe
D:\Documents and Settings\Danny\DesktopTrojan.Win32.BlackBird.exe
D:\Documents and Settings\Danny\Desktopvirii
D:\Documents and Settings\Danny\Favorites\Error Cleaner.url
D:\Documents and Settings\Danny\Favorites\Privacy Protector.url
D:\Documents and Settings\Danny\Favorites\Spyware&Malware Protection.url
.
((((((((((((((((((((((((( Files Created from 2008-03-04 to 2008-04-04 )))))))))))))))))))))))))))))))
.
2008-03-30 13:14 . 2008-03-30 13:14 <DIR> d-------- D:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-03-30 13:14 . 2008-03-30 13:14 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-03-28 18:17 . 2008-03-28 18:17 94,208 --a------ C:\WINDOWS\system32\azcfsjmf.exe
2008-03-28 18:17 . 2008-03-28 18:17 268 --ah----- C:\sqmdata01.sqm
2008-03-28 18:17 . 2008-03-28 18:17 244 --ah----- C:\sqmnoopt01.sqm
2008-03-28 16:47 . 2008-03-28 16:47 106,496 --a------ C:\WINDOWS\system32\edebcrcf.exe
2008-03-28 12:27 . 2008-03-28 12:27 98,304 --a------ C:\WINDOWS\system32\adatozkr.exe
2008-03-28 11:07 . 2008-03-28 11:07 <DIR> d-------- C:\VundoFix Backups
2008-03-28 10:15 . 2008-03-28 10:45 5,624 --a------ C:\WINDOWS\system32\tmp.reg
2008-03-28 10:07 . 2008-03-28 10:07 <DIR> d-------- C:\Program Files\Trend Micro
2008-03-28 01:29 . 2008-03-28 01:29 90,112 --a------ C:\WINDOWS\system32\dujopkrm.exe
2008-03-27 20:13 . 2008-03-27 20:13 <DIR> d-------- C:\Program Files\PC-Cleaner
2008-03-26 18:42 . 2008-03-26 18:45 <DIR> d-------- C:\NSS
2008-03-26 18:19 . 2008-03-26 18:19 98,304 --a------ C:\WINDOWS\system32\yfypuzqx.exe
2008-03-26 12:44 . 2008-03-26 13:32 <DIR> d-------- D:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-03-26 12:44 . 2008-03-26 12:44 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-03-26 09:34 . 2008-03-26 09:34 98,304 --a------ C:\WINDOWS\system32\gxwfuvsp.exe
2008-03-26 09:31 . 2008-03-26 09:31 268 --ah----- C:\sqmdata00.sqm
2008-03-26 09:31 . 2008-03-26 09:31 244 --ah----- C:\sqmnoopt00.sqm
2008-03-25 21:50 . 2006-04-20 13:49 <DIR> d-------- D:\Documents and Settings\Administrator\Application Data\You've Got Pictures Screensaver
2008-03-25 16:53 . 2008-03-25 16:53 <DIR> d-------- D:\Documents and Settings\All Users\Application Data\exctipab
2008-03-07 15:03 . 2008-03-07 15:03 625,032 --a------ C:\WINDOWS\system32\SymNeti.dll
2008-03-07 15:03 . 2008-03-07 15:03 242,056 --a------ C:\WINDOWS\system32\SymRedir.dll
2008-03-07 14:40 . 2008-03-07 14:40 13,035 --a------ C:\WINDOWS\system32\drivers\SymRedir.cat
2008-03-07 14:40 . 2008-03-07 14:40 1,358 --a------ C:\WINDOWS\system32\drivers\SymRedir.inf
2008-03-07 14:39 . 2008-03-07 14:39 191,536 --a------ C:\WINDOWS\system32\drivers\symtdi.sys
2008-03-07 14:39 . 2008-03-07 14:39 145,968 --a------ C:\WINDOWS\system32\drivers\symfw.sys
2008-03-07 14:39 . 2008-03-07 14:39 39,984 --a------ C:\WINDOWS\system32\drivers\symids.sys
2008-03-07 14:39 . 2008-03-07 14:39 37,936 --a------ C:\WINDOWS\system32\drivers\symndisv.sys
2008-03-07 14:39 . 2008-03-07 14:39 35,120 --a------ C:\WINDOWS\system32\drivers\symndis.sys
2008-03-07 14:39 . 2008-03-07 14:39 27,696 --a------ C:\WINDOWS\system32\drivers\symredrv.sys
2008-03-07 14:39 . 2008-03-07 14:39 12,848 --a------ C:\WINDOWS\system32\drivers\symdns.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-04 10:20 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-04-04 09:22 --------- d-----w D:\Documents and Settings\All Users\Application Data\Symantec
2008-04-03 23:46 --------- d-----w C:\Program Files\LogMeIn
2008-03-26 08:10 --------- d-----w C:\Program Files\M-Audio Audiophile USB
2008-03-26 07:56 --------- d-----w C:\Program Files\WinAce
2008-03-24 12:21 --------- d-----w C:\Program Files\Norton SystemWorks Premier
2008-03-20 22:40 --------- d-----w C:\Program Files\Java
2008-03-11 10:55 --------- d-----w C:\Program Files\Norton Internet Security
2008-03-06 21:32 706 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.inf
2008-03-06 21:32 23,904 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.sys
2008-03-06 21:32 10,537 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.cat
2008-02-14 10:20 --------- d-----w C:\Program Files\ProjectPoint-2008
2008-02-04 17:26 --------- d-----w D:\Documents and Settings\Danny\Application Data\ProjectPoint-2008
2008-01-11 05:53 44,544 ----a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
2006-07-21 11:14 0 ----a-w D:\Documents and Settings\Danny\Application Data\wklnhst.dat
2005-09-14 09:58 20,480 ----a-w C:\Program Files\Common Files\UninstallDrv.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{2D4651A7-58C8-4530-8787-88C8B6DC774E}"= "C:\WINDOWS\qvdntlmw.dll" [ ]
[HKEY_CLASSES_ROOT\clsid\{2d4651a7-58c8-4530-8787-88c8b6dc774e}]
[HKEY_CLASSES_ROOT\qvdntlmw.1]
[HKEY_CLASSES_ROOT\TypeLib\{990E5B1C-5E9A-4D82-8C75-30D770D0F339}]
[HKEY_CLASSES_ROOT\qvdntlmw]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SmpcSys"="C:\APPS\SMP\SmpSys.exe" [2005-11-17 09:51 975360]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 14:00 15360]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54 5674352]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-03-27 15:22 4670968]
"gjsxffqb"="C:\WINDOWS\system32\yfypuzqx.exe" [2008-03-26 18:19 98304]
"byozigxj"="C:\WINDOWS\system32\dujopkrm.exe" [2008-03-28 01:29 90112]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 14:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 14:00 455168]
"SMSERIAL"="sm56hlpr.exe" [2005-10-18 12:14 557056 C:\WINDOWS\sm56hlpr.exe]
"nwiz"="nwiz.exe" [2005-08-02 16:35 1519616 C:\WINDOWS\system32\nwiz.exe]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 17:07 61952 C:\WINDOWS\system32\HdAShCut.exe]
"RTHDCPL"="RTHDCPL.EXE" [2005-12-09 16:49 15691264 C:\WINDOWS\RTHDCPL.exe]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2006-04-20 13:49 26112]
"Vade Retro Outlook Express"="C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_oe.exe" [2004-10-04 13:03 310272]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-10 06:59 115816]
"Ulead AutoDetector v2"="C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe" [2004-11-26 11:43 90112]
"PCMService"="c:\apps\Powercinema\PCMService.exe" [2005-11-16 14:11 143360]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-04 14:00 208952]
"LogMeIn GUI"="C:\Program Files\LogMeIn\x86\LogMeInSystray.exe" [2007-04-17 14:03 63048]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-04-20 13:49 98304]
"TomTomHOME.exe"="C:\Program Files\TomTom HOME\TomTomHOME.exe" [2006-10-30 15:34 3576512]
"M-Audio Taskbar Icon"="C:\WINDOWS\System32\M-AudioTaskBarIcon.exe" [2006-03-16 10:54 99840]
"PinnacleDriverCheck"="C:\WINDOWS\system32\\PSDrvCheck.exe" [2003-11-10 16:06 406016]
"NSRKey"="C:\PROGRA~1\NORTON~3\NSR\Agent\NSRTray.exe" [2007-03-26 15:45 1582696]
"Norton Save and Restore"="C:\PROGRA~1\NORTON~3\NSR\Agent\NSRTray.exe" [2007-03-26 15:45 1582696]
"osCheck"="C:\Program Files\Norton Internet Security\osCheck.exe" [2007-01-14 08:11 771704]
"PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-03-23 13:20 227328]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-08-17 11:18 1838592]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-11-28 20:51 583048]
"NSWosCheck"="C:\Program Files\Norton SystemWorks Premier\osCheck.exe" [2007-12-03 02:41 25472]
"basicsmssmenu"="C:\Program Files\Seagate\Basics\Basics Status\MaxMenuMgrBasics.exe" [2007-10-09 17:21 169328]
"LWBMOUSE"="C:\Program Files\Belkin\Wireless Mouse Driver\MOUSE32A.EXE" [2005-08-22 18:16 356352]
"LWBKEYBOARD"="C:\Program Files\Belkin\Belkin keypad driver\KbdAp32A.exe" [2005-08-22 18:19 392704]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 14:00 15360]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 15:58 1744896]
D:\Documents and Settings\Danny\Start Menu\Programs\Startup\
RC.exe.lnk - C:\Program Files\DTV\DVB-T USB 2.0\RC.exe [2006-01-06 11:16:41 49152]
D:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-05-15 01:19:50 217193]
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-05-14 12:09:23 113664]
DSLMON.lnk - C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2006-05-04 16:46:40 962667]
EPSON Status Monitor 3 Environment Check 2.lnk - C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE [2006-05-05 12:33:19 127488]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
LMIinit.dll 2007-11-21 19:03 87352 C:\WINDOWS\system32\LMIinit.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%ProgramFiles%\\AOL 9.0\\aol.exe"=
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\logo_ubi.exe"=
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\pandora.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\apps\\skype\\phone\\Skype.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Pinnacle\\Studio 10\\programs\\RM.exe"=
"C:\\Program Files\\Pinnacle\\Studio 10\\programs\\Studio.exe"=
"C:\\Program Files\\Pinnacle\\Studio 10\\programs\\PMSRegisterFile.exe"=
"C:\\Program Files\\Pinnacle\\Studio 10\\programs\\umi.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
R1 BUFADPT;BUFADPT;C:\WINDOWS\system32\BUFADPT.SYS [2005-07-06 05:52]
R2 Basics Service;Basics Service;"C:\Program Files\Seagate\Basics\Service\SyncServicesBasics.exe" [2007-10-09 17:21]
R2 BCMNTIO;BCMNTIO;C:\PROGRA~1\CheckIt\DIAGNO~1\BCMNTIO.sys [2004-03-05 17:09]
R2 LMIInfo;LogMeIn Kernel Information Provider;C:\Program Files\LogMeIn\x86\RaInfo.sys [2007-04-17 14:00]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;C:\WINDOWS\system32\drivers\LMIRfsDriver.sys [2007-04-05 11:55]
R2 MAPMEM;MAPMEM;C:\PROGRA~1\CheckIt\DIAGNO~1\MAPMEM.sys [2004-03-05 17:09]
R2 MAudioAudiophileService;M-Audio Audiophile Installer;C:\Program Files\M-Audio\Audiophile USB\MAUSBAPInst.exe [2006-03-14 11:52]
R2 Norton Save and Restore;Norton Save and Restore;C:\PROGRA~1\NORTON~3\NSR\Agent\VProSvc.exe [2007-03-26 15:45]
R3 SIS163u;SiS163 USB Wireless LAN Adapter Driver;C:\WINDOWS\system32\DRIVERS\sis163u.sys [2007-08-02 16:38]
R3 SISNPF;SIS Netgroup Packet Filter;C:\WINDOWS\system32\drivers\SISNPF.sys [2005-12-23 12:16]
S3 LMASFltr;LMASFltr;C:\WINDOWS\system32\drivers\LMASFltr.sys [2002-12-05 01:25]
S3 maavsusb;M-Audio USB Audiophile;C:\WINDOWS\system32\drivers\MA763003.sys []
S3 MADFU003;MADFU003;C:\WINDOWS\system32\DRIVERS\MADFU003.sys [2006-03-16 10:53]
S3 MAUSBAP;Service for M-Audio Audiophile (WDM);C:\WINDOWS\system32\DRIVERS\mausbap.sys [2006-03-16 10:55]
S3 MMAUSB;M Audio USB ASIO Driver;C:\WINDOWS\system32\Drivers\MMAUSB.SYS [2002-12-05 01:25]
S3 Symantec RemoteAssist;Symantec RemoteAssist;"C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe" [2008-01-29 17:09]
S3 USBNP4X4;M-Audio Audiophile USB Midi;C:\WINDOWS\system32\drivers\usbnp4x4.sys [2006-03-16 10:53]
S3 WDM_Capture_220A;DVB-T TV Receiver;C:\WINDOWS\system32\Drivers\WDM_Capture_220A.sys [2004-09-06 21:40]
S3 WDM_Loader_220A;DVB-T TV Loader;C:\WINDOWS\system32\Drivers\WDM_Loader_220A.sys [2005-12-28 10:37]
*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2008-04-04 10:07:00 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-03-25 08:58:54 C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - Danny.job"
- C:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exeh/TASK:
"2008-03-24 12:21:21 C:\WINDOWS\Tasks\Norton SystemWorks One Button Checkup.job"
- C:\Program Files\Norton SystemWorks Premier\OBC.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-04-04 11:24:48
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-04-04 11:25:38
ComboFix-quarantined-files.txt 2008-04-04 10:25:29
Pre-Run: 5,728,780,288 bytes free
Post-Run: 5,953,912,832 bytes free
.
2008-03-20 17:39:55 --- E O F ---
HJT to follow. Thanks again