combofix:
ComboFix 07-11-08.1 - silver01 2007-11-09 11:00:40.1 - NTFSx86
Running from: C:\Documents and Settings\silver01\Local Settings\Temporary Internet Files\Content.IE5\8F77MKPX\ComboFix[1].exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data.\salesmonitor
C:\Documents and Settings\All Users\Start Menu\Programs\DriveCleaner Freeware
C:\Documents and Settings\All Users\Start Menu\Programs\DriveCleaner Freeware\DriveCleaner Freeware.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\DriveCleaner Freeware\DriveCleaner HomePage.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\DriveCleaner Freeware\DriveCleaner Online Manual.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\DriveCleaner Freeware\DriveCleaner Online Support.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\DriveCleaner Freeware\Uninstall DriveCleaner.lnk
C:\Documents and Settings\silver01\Application Data\DriveCleaner Freeware
C:\Documents and Settings\silver01\Application Data\DriveCleaner Freeware\Logs\update.log
C:\Documents and Settings\silver01\Application Data\macromedia\Flash Player\#SharedObjects\9HA2BSKW\
www.broadcaster.com
C:\Documents and Settings\silver01\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#
www.broadcaster.com
C:\Documents and Settings\silver01\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#
www.broadcaster.com\settings.sol
C:\Documents and Settings\silver01\Application Data\microsoft\internet explorer\quick launch\AntiVirGear 3.8.lnk
C:\Documents and Settings\silver01\Application Data\setup_en[1].exe
C:\Documents and Settings\silver01\Desktop\AntiVirGear 3.8.lnk
C:\Documents and Settings\silver01\err.log
C:\Documents and Settings\silver01\Start Menu\AntiVirGear 3.8.lnk
C:\Documents and Settings\silver01\Start Menu\Programs\AntiVirGear 3.8
C:\Documents and Settings\silver01\Start Menu\Programs\AntiVirGear 3.8\AntiVirGear 3.8 Website.lnk
C:\Documents and Settings\silver01\Start Menu\Programs\AntiVirGear 3.8\AntiVirGear 3.8.lnk
C:\Documents and Settings\silver01\Start Menu\Programs\AntiVirGear 3.8\Uninstall AntiVirGear 3.8.lnk
C:\Program Files\AntiVirGear 3.8
C:\Program Files\AntiVirGear 3.8\AntiVirGear 3.8.exe
C:\Program Files\AntiVirGear 3.8\AntiVirGear 3.8.url
C:\Program Files\AntiVirGear 3.8\avrg.dat
C:\Program Files\AntiVirGear 3.8\blacklist.txt
C:\Program Files\AntiVirGear 3.8\Lang\English.ini
C:\Program Files\AntiVirGear 3.8\msvcp71.dll
C:\Program Files\AntiVirGear 3.8\msvcr71.dll
C:\Program Files\AntiVirGear 3.8\uninst.exe
C:\WINDOWS\system32\__c001EC42.exe
C:\WINDOWS\system32\ugbtna.dll
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2007-10-09 to 2007-11-09 )))))))))))))))))))))))))))))))
.
2007-11-09 10:59 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-10-28 22:23 <DIR> d-------- C:\Program Files\Video Add-on
2007-10-09 20:18 584,192 -----c--- C:\WINDOWS\system32\dllcache\rpcrt4.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-05 11:02 --------- d-----w C:\Program Files\Coupons
2007-10-30 22:59 --------- d-----w C:\Program Files\Lavasoft
2007-10-29 03:24 --------- dc--a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-10-28 17:59 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2007-10-28 02:00 --------- d-----w C:\Program Files\AIM
2007-10-28 01:55 --------- d-----w C:\Program Files\WarRock
2007-10-28 01:05 --------- dc----w C:\Documents and Settings\All Users\Application Data\AOL Downloads
2007-10-05 14:28 --------- d-----w C:\Program Files\Opera
2007-10-05 13:15 --------- d-----w C:\Program Files\Java
2007-09-22 07:47 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-09-22 07:44 --------- d-----w C:\Documents and Settings\silver01\Application Data\InstallShield
2007-09-16 01:09 --------- d-----w C:\Program Files\DivX
2007-09-14 02:18 --------- dc----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-09-10 02:57 --------- d-----w C:\Program Files\Viewpoint
2007-09-10 02:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B499D34E-58EF-4927-AB9F-7AF52B2C4C82}]
2007-11-09 08:42 13312 --a------ C:\Program Files\Video Add-on\isfmdl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 18:04]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2004-08-20 15:51]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 17:38]
"HPHUPD05"="c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe" [2003-08-21 05:23]
"HPHmon05"="C:\WINDOWS\System32\hphmon05.exe" [2003-08-21 05:15]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2004-04-14 15:43]
"VTTimer"="VTTimer.exe" []
"AGRSMMSG"="AGRSMMSG.exe" [2004-06-29 09:06 C:\WINDOWS\AGRSMMSG.exe]
"SoundMan"="SOUNDMAN.EXE" [2004-05-03 13:21 C:\WINDOWS\SOUNDMAN.EXE]
"AlcWzrd"="ALCWZRD.EXE" [2004-05-03 15:23 C:\WINDOWS\ALCWZRD.EXE]
"PS2"="C:\WINDOWS\system32\ps2.exe" []
"UpdateManager"="c:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 00:01]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2004-05-12 06:26]
"hjhq3a23"="C:\WINDOWS\System32\hjhq3a23.exe" [2007-04-26 15:06]
"Rndwyhd"="C:\Program Files\Exqmm\Nlnbaff.exe" [2005-09-19 05:45]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2004-08-20 15:55]
"SNM"="C:\Program Files\SpyNoMore\SNM.exe" []
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-08-18 07:38]
"ProSiteFinder"="C:\Program Files\ProSiteFinder\prositefinder.exe" []
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" []
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 03:00]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BackupNotify"="c:\Program Files\HP\Digital Imaging\bin\backupnotify.exe" [2004-01-09 03:34]
"MSMSGS"="C:\Program Files\Messenger\MSMSGS.exe" [2004-10-13 11:24]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 15:46]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-24 01:05:26]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2003-09-16 14:19:24]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - D:\Info.exe folder.htt 480 480
.
Contents of the 'Scheduled Tasks' folder
"2004-05-13 05:58:38 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************
catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-11-09 11:11:31
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-09 11:12:15 - machine was rebooted
.
--- E O F ---