I missed getting into safe mode so I tried to run it again. The first time around (the txt isn't here now, I guess it just keeps the last one) it said EVERYTHING that was input was deleted .suscessfully.
Logfile of The Avenger Version 2.0, (c) by Swandog46
Swandog46's Public Anti-Malware Tools
Platform: Windows XP
*******************
Script file opened successfully.
Script file read successfully.
Backups directory opened successfully at C:\Avenger
*******************
Beginning to process script file:
Rootkit scan active.
Hidden driver "clbdriver" found!
ImagePath: \??\globalroot\systemroot\system32\drivers\clbdriv er.sys
Start Type: 1 (System)
Rootkit scan completed.
Error: file "C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\clbcatex. dll" not found!
Deletion of file "C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\clbcatex. dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\clbcatq.d ll" not found!
Deletion of file "C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\clbcatq.d ll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "C:\WINDOWS\system32\drivers\clbdriver.sys" not found!
Deletion of file "C:\WINDOWS\system32\drivers\clbdriver.sys" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "C:\WINDOWS\system32\clb.dll" not found!
Deletion of file "C:\WINDOWS\system32\clb.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "C:\WINDOWS\system32\clbcatex.dll" not found!
Deletion of file "C:\WINDOWS\system32\clbcatex.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "C:\WINDOWS\system32\clbcatq.dll" not found!
Deletion of file "C:\WINDOWS\system32\clbcatq.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "C:\WINDOWS\system32\clbdll.dll" not found!
Deletion of file "C:\WINDOWS\system32\clbdll.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "C:\WINDOWS\system32\clbinit.dll" not found!
Deletion of file "C:\WINDOWS\system32\clbinit.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "C:\WINDOWS\system32\dllcache\clb.dll" not found!
Deletion of file "C:\WINDOWS\system32\dllcache\clb.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "C:\WINDOWS\system32\dllcache\clbcatex.dll" not found!
Deletion of file "C:\WINDOWS\system32\dllcache\clbcatex.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "C:\WINDOWS\$NtUninstallKB902400$\clbcatex.dll " not found!
Deletion of file "C:\WINDOWS\$NtUninstallKB902400$\clbcatex.dll " failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "C:\WINDOWS\$NtUninstallKB902400$\clbcatq.dll" not found!
Deletion of file "C:\WINDOWS\$NtUninstallKB902400$\clbcatq.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "C:\WINDOWS\system32\51C0F3D8F4.sys" not found!
Deletion of file "C:\WINDOWS\system32\51C0F3D8F4.sys" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "C:\WINDOWS\system32\KGyGaAvL.sys" not found!
Deletion of file "C:\WINDOWS\system32\KGyGaAvL.sys" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "C:\Program Files\Common Files\Real\Plugins\clbascauth.dll" not found!
Deletion of file "C:\Program Files\Common Files\Real\Plugins\clbascauth.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "C:\StubInstaller.exe" not found!
Deletion of file "C:\StubInstaller.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Folder "C:\WINDOWS\Temp" deleted successfully.
Error: folder "C:\Documents and Settings\Irene Hawthorne\Application Data\Gtek" not found!
Deletion of folder "C:\Documents and Settings\Irene Hawthorne\Application Data\Gtek" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: folder "C:\Documents and Settings\Rob\Application Data\Gtek" not found!
Deletion of folder "C:\Documents and Settings\Rob\Application Data\Gtek" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Completed script processing.
*******************
Finished! Terminate.
ComboFix 08-06-03.1 - Irene Hawthorne 2008-06-03 20:16:52.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.242 [GMT -4:00]
Running from: C:\Documents and Settings\Administrator\My Documents\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Dwayne\My Documents\Online Security Guide.url
C:\Documents and Settings\Dwayne\My Documents\Security Troubleshooting.url
C:\Program Files\RcvSystem
C:\WINDOWS\system32\clbdll.dll
C:\WINDOWS\system32\clbinit.dll
C:\WINDOWS\system32\dfhkj.ini
C:\WINDOWS\system32\dfhkj.ini2
C:\WINDOWS\system32\drivers\clbdriver.sys
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mdm.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_CLBDRIVER
((((((((((((((((((((((((( Files Created from 2008-05-04 to 2008-06-04 )))))))))))))))))))))))))))))))
.
2008-06-03 17:12 . 1999-05-05 22:22 471,040 --a------ C:\WINDOWS\system32\KERNEL032.DLL
2008-06-03 15:19 . 2008-06-03 15:19 268 --ah----- C:\sqmdata16.sqm
2008-06-03 15:19 . 2008-06-03 15:19 244 --ah----- C:\sqmnoopt16.sqm
2008-06-03 03:39 . 2008-06-03 03:39 <DIR> d-------- C:\WINDOWS\system32\SmitfraudFix
2008-06-02 21:31 . 2008-06-02 21:31 <DIR> d-------- C:\WINDOWS\ERUNT
2008-06-02 19:12 . 2008-06-02 19:12 3,548 --a------ C:\WINDOWS\system32\tmp.reg
2008-06-02 19:03 . 2008-06-02 19:03 1,392,671 --a------ C:\WINDOWS\system32\fix.exe
2008-06-02 17:45 . 2008-06-03 03:35 <DIR> d-------- C:\Documents and Settings\Irene Hawthorne\Application Data\Azureus
2008-05-29 16:44 . 2008-05-29 16:44 <DIR> d-------- C:\Documents and Settings\Irene Hawthorne\Application Data\Lavasoft
2008-05-27 22:22 . 2008-05-27 22:38 <DIR> d-------- C:\Program Files\Security Task Manager
2008-05-27 22:22 . 2008-06-03 17:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SecTaskMan
2008-05-24 16:36 . 2008-05-24 16:35 691,545 --a------ C:\WINDOWS\unins000.exe
2008-05-24 16:36 . 2008-05-24 16:37 2,538 --a------ C:\WINDOWS\unins000.dat
2008-05-23 16:00 . 2004-08-04 06:00 4,224 --a------ C:\WINDOWS\system32\beep.sys
2008-05-20 13:41 . 2008-05-20 13:41 244 --ah----- C:\sqmnoopt15.sqm
2008-05-20 13:41 . 2008-05-20 13:41 232 --ah----- C:\sqmdata15.sqm
2008-05-16 03:04 . 2008-05-16 03:04 118 --a------ C:\WINDOWS\system32\MRT.INI
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2008-06-04 00:23 --------- d-----w C:\Program Files\Symantec AntiVirus
2008-06-04 00:05 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-06-03 21:31 --------- d-----w C:\Documents and Settings\Guest\Application Data\Talkback
2008-06-03 21:30 --------- d-----w C:\Program Files\BitZip
2008-06-03 21:30 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Talkback
2008-06-03 07:39 --------- d--h--r C:\Documents and Settings\Irene Hawthorne\Application Data\yahoo!
2008-06-03 07:39 --------- d-----w C:\Program Files\Yahoo!
2008-06-03 07:39 --------- d-----w C:\Program Files\Conduit
2008-06-03 07:39 --------- d-----w C:\Program Files\BitZipperSearch
2008-06-03 07:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\yahoo!
2008-06-03 07:35 --------- d-----w C:\Program Files\GetTiffany
2008-06-03 06:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-06-03 01:24 --------- d-----w C:\Program Files\Azureus
2008-05-31 08:07 --------- d-----w C:\Documents and Settings\Irene Hawthorne\Application Data\AVG7
2008-05-31 07:47 --------- d-----w C:\Program Files\CaptureWebCam
2008-05-29 22:51 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg7
2008-05-29 20:43 --------- d-----w C:\Program Files\Mail PassView
2008-05-27 01:02 --------- d-----w C:\Program Files\MSN Messenger
2008-05-27 01:02 --------- d-----w C:\Program Files\Cain
2008-05-26 07:06 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-25 18:58 --------- d-----w C:\Program Files\LimeWire
2008-05-25 18:58 --------- d-----w C:\Program Files\FrostWire
2008-05-25 18:58 --------- d-----w C:\Program Files\eMule
2008-05-25 18:45 --------- d-----w C:\Documents and Settings\Administrator\Application Data\AVG7
2008-05-23 20:00 7,168 ----a-w C:\WINDOWS\system32\drivers\beep.sys
2008-04-16 00:25 --------- d-----w C:\Program Files\Java
2008-04-06 18:08 --------- d-----w C:\Program Files\Google
.
Code:
<pre>
----a-w 40,048 2007-12-24 00:27:42 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl .exe
----a-w 1,404,928 2007-12-24 00:25:59 C:\Program Files\Analog Devices\Core\smax4pnp .exe
----a-w 81,920 2007-12-24 00:26:15 C:\Program Files\Common Files\InstallShield\UpdateService\issch .exe
----a-w 249,856 2007-12-24 00:26:07 C:\Program Files\Common Files\InstallShield\UpdateService\isuspm .exe
----a-w 185,632 2007-12-24 00:27:49 C:\Program Files\Common Files\Real\Update_OB\realsched .exe
----a-w 66,680 2007-12-24 00:26:41 C:\Program Files\Common Files\Symantec Shared\ccApp .exe
----a-w 94,208 2007-12-24 00:25:56 C:\Program Files\Dell\Media Experience\DMXLauncher .exe
----a-w 460,784 2007-12-24 00:28:25 C:\Program Files\DellSupport\DSAgnt .exe
----a-w 68,856 2007-12-24 00:28:05 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe
----a-w 579,072 2007-12-24 00:27:33 C:\Program Files\Grisoft\AVG7\avgcc .exe
----a-w 49,152 2007-12-24 00:27:07 C:\Program Files\HP\HP Software Update\HPWuSchd2 .exe
----a-w 256,576 2007-12-24 00:27:08 C:\Program Files\iTunes\iTunesHelper .exe
----a-w 1,121,792 2007-12-24 00:27:13 C:\Program Files\McAfee\SpamKiller\MSKDetct .exe
----a-w 124,128 2007-12-24 00:26:54 C:\Program Files\Symantec AntiVirus\VPTray .exe
----a-w 1,880,064 2007-12-24 00:27:34 C:\Program Files\verizon\Servicepoint\VerizonServicepoint .exe
----a-w 438,359 2007-12-24 00:27:28 C:\Program Files\verizon\SmartBridge\MotiveSB .exe
----a-w 12,288 2007-12-24 00:26:34 C:\Program Files\Winamp\Winampa .exe
----a-w 15,360 2007-12-24 01:16:24 C:\WINDOWS\system32\ctfmon .exe
----a-w 77,824 2007-12-24 00:26:23 C:\WINDOWS\system32\hkcmd .exe
----a-w 114,688 2007-12-24 00:26:27 C:\WINDOWS\system32\igfxpers .exe
----a-w 94,208 2007-12-24 00:26:20 C:\WINDOWS\system32\igfxtray .exe
----a-w 122,940 2007-12-24 00:26:17 C:\WINDOWS\system32\DLA\DLACTRLW .EXE
</pre>
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A94867E7-7C1B-4693-AA98-DBC7E6ED5804}]
C:\WINDOWS\system32\jkhfd.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [ ]
"AIM"="C:\Program Files\AIM\aim.exe" [2006-08-01 16:35 67112]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe" [2008-04-05 19:03 68856]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 06:00 15360]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [ ]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [ ]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [ ]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [ ]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [ ]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [ ]
"WinampAgent"="C:\Program Files\Winamp\Winampa.exe" [ ]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [ ]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [ ]
"MSKDetectorExe"="C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" [ ]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [ ]
"Motive SmartBridge"="C:\PROGRA~1\verizon\SMARTB~1\MotiveS B.exe" [ ]
"VerizonServicepoint.exe"="C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe " [ ]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [ ]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [ ]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"combofix"="C:\WINDOWS\system32\CF21007.exe" [2004-08-04 06:00 388608]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-10-22 15:40 219136]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-04-12 10:12:50 24576]
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2006-12-02 22:48:26 125624]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 16:05:56 65588]
[hkey_local_machine\software\microsoft\windows\curr entversion\explorer\shellexecutehooks]
"{CA4F0D8D-5F2B-4F16-838A-8D52249EAB21}"= C:\WINDOWS\system32\efcayaw.dll [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\efcayaw]
efcayaw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=perfnesys.dll,C:\Program,Files\Perm issionResearch\prai.dll,perfnesys.dll,C:\Program Files\PermissionResearch\prai.dll perfnesys.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.yv12"= yv12vfw.dll
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\America Online 9.0\\waol.exe"=
"C:\\Documents and Settings\\Rob\\Desktop\\warez.exe"=
"C:\\StubInstaller.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\WINDOWS\\system32\\LEXPPS.EXE"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLAcsd.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"C:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"C:\\Program Files\\GetTiffany\\gettiffany.exe"=
"C:\\Program Files\\Atari\\Scrabble Online\\scrabbleo.exe"=
"C:\\Program Files\\Azureus\\Azureus.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\Warez P2P Client\\My Shared Folder\\iMesh6.exe"=
"C:\\Program Files\\Hasbro Interactive\\Scrabble v2.0\\Scrabble v2.0.exe"=
"C:\\Program Files\\Morpheus\\Morpheus.exe"=
"C:\\Program Files\\BearShare Applications\\BearShare\\BearShare.exe"=
"C:\\Program Files\\BearFlix\\bearflix.exe"=
"C:\\Program Files\\FilePipe P2P\\giFT\\giFTl.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\WINDOWS\\system32\\rtcshare.exe"=
"C:\\Program Files\\BitTorrent\\bittorrent.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\AIM\\AIM95_c0\\aim.exe"=
"C:\\Program Files\\BitZip\\bitzip.exe"=
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\backWeb-8876480.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=
"C:\\Program Files\\Paltalk Messenger\\paltalk.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"C:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr .exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\GameTap\\bin\\Release\\gametap.exe"=
"C:\\Program Files\\Starcraft\\StarCraft.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
"C:\\Program Files\\Cain\\Cain.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\AIM\\aim.exe"=
"C:\\Program Files\\eMule\\emule.exe"=
"C:\\WINDOWS\\Temp\\~os43.tmp\\ossproxy.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\GloballyOpenPorts\List]
"14101:TCP"= 14101:TCP:BitComet 14101 TCP
"14101:UDP"= 14101:UDP:BitComet 14101 UDP
R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 17:38]
S0 oxfjcp;oxfjcp;C:\WINDOWS\system32\drivers\kifeacu. sys []
S3 gel90xne;gel90xne;C:\DOCUME~1\IRENEH~1\LOCALS~1\Te mp\gel90xne.sys []
S3 hamachi_oem;PlayLinc Adapter;C:\WINDOWS\system32\DRIVERS\gan_adapter.sy s [2006-09-27 16:12]
S3 NPF;NetGroup Packet Filter Driver;C:\WINDOWS\system32\drivers\npf.sys [2007-06-28 20:01]
.
Contents of the 'Scheduled Tasks' folder
"2008-05-31 13:20:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
************************************************** ************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-06-03 20:24:26
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\c lbdriver]
"imagepath"="\??\globalroot\systemroot\system32\dr ivers\clbdriver.sys"
.
------------------------ Other Running Processes ------------------------
.
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\taskmgr.exe
.
************************************************** ************************
.
Completion time: 2008-06-03 20:31:21 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-04 00:31:16
Pre-Run: 78,382,731,264 bytes free
Post-Run: 78,462,418,944 bytes free
234 --- E O F --- 2008-05-28 04:56:10