Hej sådan ser det ud efter jeg har kørt combofix jeg sender lige en ny hijack log
ComboFix 08-02-25.3 - Hans Henrik 2008-02-26 14:24:52.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1030.18.1121 [GMT 1:00]
Running from: C:\Documents and Settings\Hans Henrik\Skrivebord\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
The following files were disabled during the run:C:\Programmer\Enigma Software Group\SpyHunter\SpyHunterMonitor.dll
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Programmer\myglobalsearch
C:\Programmer\myglobalsearch\bar\History\search
C:\WINDOWS\dgtxrdfknf.dll
C:\WINDOWS\ekvgsnw.dll
C:\WINDOWS\system32\AutoRun.inf
.
((((((((((((((((((((((((( Files Created from 2008-01-26 to 2008-02-26 )))))))))))))))))))))))))))))))
.
2008-02-26 14:13 . 2008-02-26 14:13 <DIR> d-------- C:\Programmer\Enigma Software Group
2008-02-26 12:54 . 2008-02-26 14:13 32 --a------ C:\WINDOWS\NPFMSG.CFG
2008-02-26 12:16 . 2008-02-26 12:55 <DIR> d-------- C:\virusfighter
2008-02-26 11:58 . 2008-02-26 12:42 <DIR> d-------- C:\Programmer\XoftSpySE
2008-02-26 11:14 . 2008-02-26 11:14 552 --a------ C:\WINDOWS\system32\d3d8caps.dat
2008-02-26 10:50 . 2008-02-26 10:50 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-26 10:49 . 2008-02-26 10:49 <DIR> d-------- C:\Programmer\Yahoo!
2008-02-26 10:27 . 2008-02-26 06:35 323,584 --a------ C:\WINDOWS\bxlrvps.dll
2008-02-26 10:27 . 2008-02-26 06:35 200,704 --a------ C:\WINDOWS\alofkmn.dll
2008-02-26 10:27 . 2008-02-26 06:35 102,400 --a------ C:\WINDOWS\fkxvkns.exe
2008-02-26 10:23 . 2008-02-26 10:23 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-02-26 10:23 . 2008-02-26 10:23 1,409 --a------ C:\WINDOWS\QTFont.for
2008-02-20 00:22 . 2008-02-20 00:25 <DIR> d--hs---- C:\Documents and Settings\Hans Henrik\Phone Browser
2008-01-30 23:02 . 2008-01-30 23:02 <DIR> d-------- C:\Programmer\Citrix
2008-01-30 23:02 . 2008-01-30 23:02 <DIR> d-------- C:\Documents and Settings\Hans Henrik\Application Data\ICAClient
2008-01-29 13:11 . 2008-01-29 13:11 <DIR> d-------- C:\Documents and Settings\Hans Henrik\Application Data\HP
2008-01-28 19:14 . 2008-01-28 19:14 <DIR> d-------- C:\Programmer\HCA
2008-01-27 21:06 . 2008-01-27 21:06 <DIR> d-------- C:\Documents and Settings\Dorthe\Application Data\HPAppData
2008-01-27 01:06 . 2008-01-27 01:06 <DIR> d-------- C:\Documents and Settings\Hans Henrik\Application Data\Nokia Multimedia Player
2008-01-27 00:23 . 2008-01-27 00:23 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WEBREG
2008-01-27 00:19 . 2008-01-27 00:19 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\HPSSUPPLY
2008-01-27 00:18 . 2008-01-27 00:18 <DIR> d-------- C:\Documents and Settings\Hans Henrik\Application Data\HPAppData
2008-01-27 00:14 . 2008-01-27 00:14 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\HP Product Assistant
2008-01-27 00:10 . 2008-01-27 00:10 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
2008-01-27 00:10 . 2007-05-02 09:56 954,368 -ra------ C:\WINDOWS\system32\hpotiop5.dll
2008-01-27 00:10 . 2007-05-02 10:01 675,840 -ra------ C:\WINDOWS\system32\hpowiax5.dll
2008-01-27 00:10 . 2007-03-08 05:20 364,544 -ra------ C:\WINDOWS\system32\hppldcoi.dll
2008-01-27 00:10 . 2007-03-08 05:20 309,760 -ra------ C:\WINDOWS\system32\difxapi.dll
2008-01-27 00:10 . 2007-05-02 10:00 303,104 -ra------ C:\WINDOWS\system32\hpovst12.dll
2008-01-27 00:10 . 2007-05-02 11:03 267,864 -ra------ C:\WINDOWS\system32\hpzids01.dll
2008-01-27 00:10 . 2008-01-27 00:23 160,513 --a------ C:\WINDOWS\hpoins21.dat
2008-01-27 00:10 . 2007-03-15 15:32 118,272 --a------ C:\WINDOWS\system32\hpz3l5ha.dll
2008-01-27 00:10 . 2007-09-05 19:26 8,138 --------- C:\WINDOWS\hpomdl21.dat
2008-01-26 16:01 . 2008-01-26 16:01 <DIR> d-------- C:\Programmer\Grimm's Hatchery
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-26 12:09 --------- d-----w C:\Programmer\Steam
2008-02-26 11:53 5 ----a-w C:\NPF_USER.DAT
2008-02-26 11:48 --------- d-----w C:\Programmer\SPAMfighter
2008-02-26 11:16 --------- d--h--w C:\Programmer\InstallShield Installation Information
2008-02-26 11:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\NPF
2008-02-26 08:42 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-02-26 08:41 107,832 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
2008-02-25 13:54 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-02-25 08:06 --------- d-----w C:\Programmer\Fælles filer\Symantec Shared
2008-02-15 09:24 --------- d-----w C:\Programmer\Fælles filer\Adobe
2008-02-06 23:35 107,888 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2008-01-26 23:19 --------- d-----w C:\Programmer\HP
2008-01-25 00:45 413,696 ----a-w C:\WINDOWS\system32\wrap_oal.dll
2008-01-25 00:45 110,592 ----a-w C:\WINDOWS\system32\OpenAL32.dll
2008-01-25 00:45 --------- d-----w C:\Programmer\Eidos
2008-01-24 15:06 --------- d-----w C:\Programmer\EA GAMES
2008-01-20 17:08 --------- d-----w C:\Documents and Settings\Dorthe\Application Data\Nero
2008-01-19 19:54 --------- d-----w C:\Documents and Settings\Hans Henrik\Application Data\Nero
2008-01-19 19:53 --------- d-----w C:\Programmer\Fælles filer\Nero
2008-01-19 19:52 --------- d-----w C:\Programmer\Nero
2008-01-19 19:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nero
2008-01-19 14:23 --------- d-----w C:\Programmer\LucasArts
2008-01-19 14:23 --------- d-----w C:\Programmer\GameSpy Arcade
2008-01-18 14:32 --------- d-----w C:\Programmer\Java
2008-01-18 14:31 --------- d-----w C:\Programmer\Fælles filer\Java
2008-01-16 13:07 66,872 ----a-w C:\WINDOWS\system32\PnkBstrA.exe
2008-01-12 23:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
2008-01-12 18:20 --------- d-----w C:\Programmer\cs
2008-01-12 09:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\Logitech
2008-01-11 17:01 --------- d-----w C:\Documents and Settings\Spille konto\Application Data\SPAMfighter
2008-01-11 16:54 --------- d-----w C:\Documents and Settings\Spille konto\Application Data\Logitech
2008-01-11 16:53 --------- d-----w C:\Documents and Settings\Spille konto\Application Data\PC Suite
2008-01-11 12:26 --------- d-----w C:\Documents and Settings\Hans Henrik\Application Data\Nokia
2008-01-10 23:17 --------- d-----w C:\Programmer\Google
2008-01-10 22:48 --------- d-----w C:\Documents and Settings\Hans Henrik\Application Data\IEPro
2008-01-10 21:49 --------- d-----w C:\Programmer\CodecInstaller
2008-01-10 21:48 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE
2008-01-10 21:48 249,856 ------w C:\WINDOWS\Setup1.exe
2008-01-10 21:46 --------- d-----w C:\Documents and Settings\Hans Henrik\Application Data\vlc
2008-01-10 21:37 --------- d-----w C:\Programmer\VideoLAN
2008-01-10 18:43 --------- d-----w C:\Programmer\Fælles filer\Ankiro
2008-01-07 23:34 --------- d-----w C:\Documents and Settings\Hans Henrik\Application Data\ErrorSmart
2008-01-04 16:26 --------- d-----w C:\Programmer\Pan Vision
2008-01-03 15:02 --------- d-----w C:\Programmer\Trymedia
2008-01-03 14:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\Fugazo
2008-01-03 14:26 --------- d-----w C:\Programmer\Hotgames.com
2008-01-03 14:18 --------- d-----w C:\Documents and Settings\Hans Henrik\Application Data\PlayFirst
2008-01-03 14:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\PlayFirst
2008-01-01 13:59 --------- d-----w C:\Documents and Settings\All Users\Application Data\Trymedia
2007-12-31 16:31 --------- d-----w C:\Programmer\Fælles filer\Oberon Media
2007-12-30 23:01 --------- d-----w C:\Documents and Settings\Dorthe\Application Data\Logitech
2007-12-30 17:16 --------- d-----w C:\Programmer\Diner Dash Flo On The Go
2007-12-30 17:15 --------- d-----w C:\Programmer\ReflexiveArcade
2007-12-29 17:37 --------- d-----w C:\Documents and Settings\Hans Henrik\Application Data\Microsoft Games
2007-12-29 17:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Games
2007-12-29 17:35 --------- d-----w C:\Programmer\Microsoft Games
2007-12-29 00:06 --------- d-----w C:\Documents and Settings\Hans Henrik\Application Data\Logitech
2007-12-29 00:06 --------- d-----w C:\Documents and Settings\All Users\Application Data\LogiShrd
2007-12-29 00:05 0 ---ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_LHidFilt_01005.Wdf
2007-12-29 00:05 --------- d-----w C:\Programmer\Fælles filer\Logishrd
2007-12-29 00:03 --------- d-----w C:\Programmer\WIDCOMM
2007-12-29 00:02 --------- d-----w C:\Programmer\Logitech
2007-12-29 00:02 --------- d-----w C:\Documents and Settings\Hans Henrik\Application Data\InstallShield
2007-12-28 23:58 --------- d-----w C:\Programmer\Fælles filer\Logitech
2007-12-27 18:41 --------- d-----w C:\Programmer\BellesBeautyBoutique_at
2007-12-26 14:48 --------- d-----w C:\Documents and Settings\Dorthe\Application Data\PC Suite
2007-12-26 14:48 --------- d-----w C:\Documents and Settings\Dorthe\Application Data\Nokia
2007-12-26 10:35 --------- d-----w C:\Documents and Settings\Dorthe\Application Data\FSW2
2007-12-13 18:09 972,072 ----a-w C:\WINDOWS\UNNeroMediaHome.exe
2007-12-12 23:34 22,328 ----a-w C:\Documents and Settings\Hans Henrik\Application Data\PnkBstrK.sys
2007-12-07 02:13 824,832 ----a-w C:\WINDOWS\system32\wininet.dll
2007-12-05 01:53 356,352 ----a-w C:\WINDOWS\system32\NVUNINST.EXE
2007-12-04 18:41 550,912 ----a-w C:\WINDOWS\system32\oleaut32.dll
2007-12-04 08:59 972,072 ----a-w C:\WINDOWS\UNRecode.exe
2007-12-03 17:04 95,600 ----a-w C:\WINDOWS\system32\NeroCo.dll
2006-06-23 22:48 32,768 ----a-r C:\WINDOWS\inf\UpdateUSB.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
2007-03-02 16:52 1298024 -ra------ C:\Programmer\HP\Smart Web Printing\hpswp_printenhancer.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{053F9267-DC04-4294-A72C-58F732D338C0}]
2007-03-02 16:52 177768 -ra------ C:\Programmer\HP\Smart Web Printing\hpswp_framework.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-26 16:53 15360]
"MSMSGS"="C:\Programmer\Messenger\msmsgs.exe" [2004-10-13 17:24 1694208]
"swg"="C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-04 09:53 68856]
"Steam"="c:\programmer\steam\steam.exe" [2008-01-04 18:18 1266936]
"RegistryCleanFixMFC"="C:\Programmer\RegistryCleaner\registrycleaner.exe" [ ]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Programmer\Fælles filer\Nero\Lib\NMIndexStoreSvr.exe" [2007-12-13 19:10 1688872]
"PC Suite Tray"="C:\Programmer\Nokia\Nokia PC Suite 6\PCSuite.exe" [2007-12-10 10:12 695808]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 01:41 8523776]
"nwiz"="nwiz.exe" [2007-12-05 01:41 1626112 C:\WINDOWS\system32\nwiz.exe]
"RTHDCPL"="RTHDCPL.EXE" [2007-03-21 15:49 16126464 C:\WINDOWS\RTHDCPL.exe]
"JMB36X IDE Setup"="C:\WINDOWS\RaidTool\xInsIDE.exe" [2007-03-20 15:36 36864]
"36X Raid Configurer"="C:\WINDOWS\system32\xRaidSetup.exe" [2007-03-21 17:23 1953792]
"Norman ZANDA"="C:\virusfighter\Bin\ZLH.exe" [2005-05-25 13:11 135168]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-09-21 03:10 55824 C:\WINDOWS\KHALMNPR.Exe]
"Easy Synchronization"="C:\Programmer\Logitech\Easy Synchronization\LogitechEasySync.exe" [2005-10-05 11:00 53248]
"HP Software Update"="C:\Programmer\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 21:34 49152]
"GrooveMonitor"="C:\Programmer\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 23:47 31016]
"QuickTime Task"="C:\Programmer\QuickTime\qttask.exe" [2007-11-13 01:10 286720]
"Bluetooth Connection Assistant"="LBTWIZ.exe" []
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-12-05 01:41 81920]
"SPAMfighter Agent"="C:\Programmer\SPAMfighter\SFAgent.exe" [2008-01-02 17:03 308880]
"SunJavaUpdateSched"="C:\Programmer\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"NeroFilterCheck"="C:\Programmer\Fælles filer\Nero\Lib\NeroCheck.exe" [2007-03-01 14:57 153136]
"NBKeyScan"="C:\Programmer\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-12-03 14:21 2213160]
"Adobe Reader Speed Launcher"="C:\Programmer\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"SpyHunter Security Suite"="C:\Programmer\Enigma Software Group\SpyHunter\SpyHunter3.exe" [2008-01-23 14:47 847872]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Easy Synchronization"="C:\Programmer\Logitech\Easy Synchronization\LogitechEasySync.exe" [2005-10-05 11:00 53248]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-26 16:53 15360]
"Nokia.PCSync"="C:\Programmer\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-11-07 17:35 1294336]
C:\Documents and Settings\Dorthe\Menuen Start\Programmer\Start\
Screen Clipper and Launcher til OneNote 2007.lnk - C:\Programmer\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 19:24:54 98632]
C:\Documents and Settings\Hans Henrik\Menuen Start\Programmer\Start\
Screen Clipper and Launcher til OneNote 2007.lnk - C:\Programmer\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 19:24:54 98632]
C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\
BTTray.lnk - C:\Programmer\WIDCOMM\Bluetooth Software\BTTray.exe [2006-11-29 22:37:20 561213]
HP Digital Imaging Monitor.lnk - C:\Programmer\HP\Digital Imaging\bin\hpqtra08.exe [2007-03-11 21:26:24 210520]
HP Image Zone Fast Start.lnk - C:\Programmer\HP\Digital Imaging\bin\hpqthb08.exe [2004-11-04 18:50:52 53248]
Logitech SetPoint.lnk - C:\Programmer\Logitech\SetPoint\SetPoint.exe [2007-12-29 01:05:27 784912]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{FE24CD78-7C63-465D-8787-4EDF7FC79895}"= C:\Programmer\Logitech\Easy Synchronization\shellexecutehook.dll [2005-10-05 11:00 69632]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"bxlrvps"= {E82A912C-B77E-4985-BE27-283210886B5B} - C:\WINDOWS\bxlrvps.dll [2008-02-26 06:35 323584]
"alofkmn"= {75D673CE-F475-4305-9043-A4F9ED1434D3} - C:\WINDOWS\alofkmn.dll [2008-02-26 06:35 200704]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
c:\programmer\fælles filer\logishrd\bluetooth\LBTWlgn.dll 2007-11-15 10:10 72208 c:\Programmer\Fælles filer\Logishrd\Bluetooth\LBTWLgn.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"D:\\spil\\UnrealEngine3\\Binaries\\MOHA.exe"=
"C:\\Programmer\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Programmer\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\WINDOWS\\system32\\PnkBstrA.exe"=
"C:\\WINDOWS\\system32\\PnkBstrB.exe"=
"C:\\Programmer\\Microsoft Games\\Zoo Tycoon 2\\zt.exe"=
"C:\\Programmer\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"C:\\Programmer\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Programmer\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Programmer\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Programmer\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Programmer\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Programmer\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Programmer\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Programmer\\HP\\Digital Imaging\\bin\\hpqcopy.exe"=
"C:\\Programmer\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Programmer\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Programmer\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Programmer\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Programmer\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"C:\\Programmer\\Joost\\xulrunner\\tvprunner.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"15081:TCP"= 15081:TCP:vandværk
R0 NDIS_RD;Firewall Engine Type-R2;C:\WINDOWS\system32\drivers\NDIS_RD.sys [2004-12-06 10:18]
R1 TDI_RD;Firewall Engine Type-R;C:\WINDOWS\system32\drivers\tdi_rd.sys [2004-10-13 22:01]
R2 SPAMfighter Update Service;SPAMfighter Update Service;C:\Programmer\SPAMfighter\sfus.exe [2008-01-02 17:03]
R3 AtcL001;NDIS Miniport Driver for Attansic L1 Gigabit Ethernet Controller;C:\WINDOWS\system32\DRIVERS\atl01_xp.sys [2007-03-15 15:12]
R3 SWUSBFLT;VIA-filterdriver til Microsoft SideWinder;C:\WINDOWS\system32\DRIVERS\SWUSBFLT.sys [2001-08-17 21:02]
S3 nvcfsr;nvcfsr;C:\Norman\Nvc\bin\nvcfsr.sys [2007-01-09 14:25]
S3 NvcMFlt;NvcMFlt;C:\WINDOWS\system32\DRIVERS\nvcw32mf.sys [2007-05-31 13:51]
S3 nvcoafl51;nvcoafl51;C:\Norman\Nvc\bin\nvcoafl51.sys [2007-01-09 14:25]
S3 nvcoaft51;nvcoaft51;C:\Norman\Nvc\bin\nvcoaft51.sys [2007-01-09 14:25]
S3 nvcoarc51;nvcoarc51;C:\Norman\Nvc\bin\nvcoarc51.sys [2007-01-09 14:25]
S3 nvcoas;Norman Virus Control on-access component;C:\Norman\Nvc\bin\nvcoas.exe [2007-05-24 12:32]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
"2008-02-25 09:00:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Programmer\Apple Software Update\SoftwareUpdate.exe
"2008-01-07 23:34:45 C:\WINDOWS\Tasks\ErrorSmart Scheduled Scan.job"
- C:\Programmer\ErrorSmart\ErrorSmart.ex
- C:\Programmer\ErrorSmart
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-02-26 14:27:57
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\Programmer\Enigma Software Group\SpyHunter\SpyHunterMonitor.dll
PROCESS: C:\WINDOWS\system32\lsass.exe [5.01.2600.2180]
-> C:\Programmer\Enigma Software Group\SpyHunter\SpyHunterMonitor.dll
.
Completion time: 2008-02-26 14:28:28
ComboFix-quarantined-files.txt 2008-02-26 13:28:26
.
2008-02-13 09:43:28 --- E O F ---