ComboFix 08-02.03.1 - James 2008-02-04 9:35:38.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.499 [GMT 0:00]
Running from: D:\Documents and Settings\James\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
/wow section - STAGE 7
((((((((((((((((((((((((( Files Created from 2008-01-04 to 2008-02-04 )))))))))))))))))))))))))))))))
.
2008-02-04 09:22 . 2008-02-04 09:25 <DIR> d-------- D:\MGtools
2008-02-04 09:18 . 2008-02-04 09:18 1,556 --a------ D:\WINDOWS\system32\tmp.reg
2008-02-04 08:44 . 2008-02-04 08:44 <DIR> d-------- D:\Documents and Settings\All Users\Application Data\Avg7
2008-02-04 08:20 . 2008-02-04 08:19 1,238,736 --a------ D:\MGtools.exe
2008-02-04 08:20 . 2008-02-04 09:25 59,230 --a------ D:\MGlogs.zip
2008-02-04 08:16 . 2008-02-04 08:16 <DIR> d-------- D:\Program Files\Avira
2008-02-04 08:07 . 2008-02-04 08:08 <DIR> d-------- D:\Program Files\Unlocker
2008-02-03 18:02 . 2008-02-03 23:25 357 --a------ D:\WINDOWS\wininit.ini
2008-02-03 17:26 . 2008-02-03 17:27 <DIR> d-------- D:\Program Files\Spybot - Search & Destroy
2008-02-03 17:26 . 2008-02-03 21:13 <DIR> d-------- D:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-03 16:30 . 2008-02-03 21:10 <DIR> d-------- D:\Documents and Settings\James\Downloads
2008-02-03 14:30 . 2008-02-04 08:55 <DIR> d-------- D:\Documents and Settings\James\Application Data\CheckPoint
2008-02-03 14:29 . 2008-02-03 14:29 <DIR> d-------- D:\Program Files\CheckPoint
2008-02-02 23:36 . 2008-02-02 23:36 <DIR> d-------- D:\Program Files\Audacity
2008-02-02 21:29 . 2008-02-02 21:29 86,144 --a------ D:\WINDOWS\system32\drivers\ndiswann.sys
2008-02-02 20:28 . 2008-02-02 20:28 <DIR> d-------- D:\Program Files\ESET
2008-02-02 18:34 . 2008-02-02 18:34 <DIR> d-------- D:\Program Files\Common Files\Softwin
2008-02-02 17:26 . 2008-02-02 17:26 <DIR> d-------- D:\Program Files\Microsoft IntelliType Pro
2008-02-02 17:23 . 2007-08-31 12:01 1,421,736 --a------ D:\WINDOWS\system32\wdfcoinstaller01005.dll
2008-02-02 17:23 . 2004-08-04 00:56 21,504 --a------ D:\WINDOWS\system32\drivers\hidserv.dll
2008-02-02 17:23 . 2007-08-31 11:58 18,856 --a------ D:\WINDOWS\system32\drivers\nuidfltr.sys
2008-02-02 17:23 . 2008-02-02 17:23 0 --ah----- D:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-02-02 17:23 . 2008-02-02 17:23 0 --ah----- D:\WINDOWS\system32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
2008-02-02 17:22 . 2008-02-02 17:22 <DIR> d-------- D:\Program Files\Microsoft IntelliPoint
2008-02-02 17:22 . 2007-08-21 01:13 21,760 --a------ D:\WINDOWS\system32\drivers\point32.sys
2008-02-02 17:06 . 2008-02-02 17:06 139,008 --a------ D:\WINDOWS\system32\guard32.dll
2008-02-02 17:06 . 2008-02-02 17:06 81,272 --a------ D:\WINDOWS\system32\drivers\cmdGuard.sys
2008-02-02 17:06 . 2008-02-02 17:06 23,672 --a------ D:\WINDOWS\system32\drivers\cmdhlp.sys
2008-02-01 19:01 . 2008-02-01 19:01 <DIR> d-------- D:\Documents and Settings\James\Application Data\ieSpell
2008-01-27 12:47 . 2008-01-27 12:47 268 --ah----- D:\sqmdata09.sqm
2008-01-27 12:47 . 2008-01-27 12:47 244 --ah----- D:\sqmnoopt09.sqm
2008-01-27 11:52 . 2008-01-27 11:52 <DIR> d-------- D:\WINDOWS\system32\NtmsData
2008-01-27 11:38 . 2008-01-27 11:38 <DIR> d-------- D:\Program Files\MSXML 6.0
2008-01-27 08:53 . 2008-01-27 08:53 <DIR> d-------- D:\WINDOWS\1st JavaScript Editor
2008-01-26 23:53 . 2008-01-26 23:54 <DIR> d-------- D:\Program Files\uTorrent
2008-01-26 21:39 . 2008-02-03 21:49 54,156 --ah----- D:\WINDOWS\QTFont.qfn
2008-01-26 21:39 . 2008-01-26 21:39 1,409 --a------ D:\WINDOWS\QTFont.for
2008-01-26 16:20 . 2008-01-26 16:20 <DIR> d-------- D:\Program Files\proDAD
2008-01-26 16:20 . 2007-01-27 09:28 <DIR> d-------- D:\Documents and Settings\James\Application Data\proDAD
2008-01-26 15:34 . 2008-01-26 15:34 <DIR> d-------- D:\Documents and Settings\James\Application Data\Publish Providers
2008-01-26 15:33 . 2008-01-26 17:04 <DIR> d-------- D:\Documents and Settings\James\Application Data\Sony
2008-01-26 15:30 . 2008-01-26 15:30 <DIR> d-------- D:\Documents and Settings\All Users\Application Data\Sony
2008-01-26 15:24 . 2008-01-26 15:24 <DIR> d-------- D:\WINDOWS\system32\XPSViewer
2008-01-26 15:23 . 2008-01-26 15:23 <DIR> d-------- D:\Program Files\Reference Assemblies
2008-01-26 15:22 . 2006-06-29 13:07 14,048 --------- D:\WINDOWS\system32\spmsg2.dll
2008-01-26 15:20 . 2008-01-26 15:20 <DIR> d-------- D:\Documents and Settings\James\Application Data\Sony Setup
2008-01-26 13:25 . 2008-02-02 21:32 <DIR> d-------- D:\Documents and Settings\James\Application Data\uTorrent
2008-01-20 23:21 . 2008-01-26 15:30 <DIR> d-------- D:\Program Files\Sony
2008-01-20 23:20 . 2008-01-26 16:06 <DIR> d-------- D:\Program Files\Sony Setup
2008-01-15 22:02 . 2008-01-15 22:02 <DIR> d-------- D:\Program Files\ImTOO
2008-01-11 23:01 . 2008-01-11 23:01 <DIR> d-------- D:\Program Files\AviSynth 2.5
2008-01-11 23:00 . 2008-01-11 23:00 <DIR> d-------- D:\Program Files\Red Kawa
2008-01-11 19:40 . 2008-01-11 19:43 <DIR> d-------- D:\Documents and Settings\James\Shared
2008-01-11 18:05 . 2007-12-17 13:53 159,458 --a------ D:\WINDOWS\system32\nvapps.nvb
2008-01-11 17:57 . 2008-01-11 17:57 <DIR> d-------- D:\Documents and Settings\Administrator\Application Data\Talkback
2008-01-07 18:45 . 2004-08-04 12:00 96,768 --a------ D:\WINDOWS\system32\dllcache\dpcdll.dll
2008-01-07 18:44 . 2008-01-08 18:11 <DIR> d-------- D:\WINDOWS\system32\en
2008-01-07 18:44 . 2008-01-08 18:11 <DIR> d-------- D:\WINDOWS\system32\bits
2008-01-07 18:44 . 2008-01-08 18:09 <DIR> d-------- D:\WINDOWS\l2schemas
2008-01-07 18:32 . 2007-10-26 03:34 8,460,288 --a------ D:\WINDOWS\system32\dllcache\shell32.dll
2008-01-07 15:55 . 2008-01-07 15:55 <DIR> d-------- D:\Program Files\HiFi
2008-01-07 15:55 . 2008-01-07 22:09 <DIR> d-------- D:\Documents and Settings\James\Application Data\HiFi
2008-01-07 15:11 . 2008-01-07 15:11 <DIR> d-------- D:\Program Files\Nibitor
2008-01-06 23:29 . 2008-01-12 00:10 23,392 --a------ D:\WINDOWS\system32\nscompat.tlb
2008-01-06 23:29 . 2008-01-12 00:10 16,832 --a------ D:\WINDOWS\system32\amcompat.tlb
2008-01-06 22:48 . 2008-01-06 22:48 <DIR> d-------- D:\Program Files\IObit
2008-01-06 18:14 . 2008-01-06 18:14 <DIR> d-------- D:\Program Files\Winamp Toolbar
2008-01-06 18:14 . 2008-01-06 18:14 <DIR> d-------- D:\Documents and Settings\All Users\Application Data\Winamp Toolbar
2008-01-06 12:01 . 2008-01-06 12:01 <DIR> d-------- D:\Program Files\DivX
2008-01-05 15:39 . 2008-01-05 15:39 <DIR> d-------- D:\Documents and Settings\All Users\Application Data\BitDefender
2008-01-05 14:46 . 2008-01-05 14:46 <DIR> d-------- D:\Program Files\iPod
2008-01-05 14:45 . 2008-01-05 14:46 <DIR> d-------- D:\Program Files\iTunes
2008-01-05 14:44 . 2008-01-05 14:44 <DIR> d-------- D:\Program Files\QuickTime
2008-01-05 12:43 . 2008-01-05 12:43 268 --ah----- D:\sqmdata08.sqm
2008-01-05 12:43 . 2008-01-05 12:43 244 --ah----- D:\sqmnoopt08.sqm
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-04 09:13 --------- d---a-w D:\Documents and Settings\All Users\Application Data\TEMP
2008-02-04 08:43 --------- d-----w D:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-04 08:16 --------- d-----w D:\Documents and Settings\All Users\Application Data\Avira
2008-02-03 20:33 --------- d-----w D:\Program Files\Winamp Remote
2008-02-03 20:24 --------- d-----w D:\Program Files\Mozilla Thunderbird
2008-02-03 17:44 --------- d-----w D:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-03 14:21 --------- d-----w D:\Program Files\ASRC
2008-02-03 00:47 --------- d-----w D:\Program Files\mIRC
2008-02-03 00:45 --------- d-----w D:\Program Files\GameSpy Arcade
2008-02-02 17:41 --------- d-----w D:\Documents and Settings\All Users\Application Data\Comodo
2008-02-02 17:06 --------- d-----w D:\Program Files\Comodo
2008-02-02 17:06 --------- d-----w D:\Program Files\Common Files\Agnitum Shared
2008-02-02 17:06 --------- d-----w D:\Documents and Settings\James\Application Data\Comodo
2008-02-02 14:29 --------- d-----w D:\Program Files\Windows Live
2008-02-02 13:36 --------- d-----w D:\Program Files\Yahoo!
2008-02-02 13:36 --------- d-----w D:\Documents and Settings\James\Application Data\FrostWire
2008-02-02 13:26 --------- d-----w D:\Program Files\Winamp
2008-02-02 13:13 --------- d-----w D:\Program Files\Valve
2008-02-02 13:12 --------- d-----w D:\Program Files\AAS
2008-02-02 13:12 --------- d-----w D:\Program Files\3D Mailbox
2008-01-26 15:30 --------- d-----w D:\Program Files\VstPlugins
2008-01-26 15:26 --------- d-----w D:\Program Files\MSBuild
2008-01-26 15:17 --------- d-----w D:\Program Files\MagicISO
2008-01-10 20:59 --------- d-----w D:\Program Files\xchat
2008-01-07 14:14 --------- d-----w D:\Documents and Settings\All Users\Application Data\nHancer
2008-01-06 23:28 --------- d-----w D:\Program Files\Windows Desktop Search
2008-01-06 16:00 --------- d-----w D:\Program Files\Microsoft Games
2008-01-06 15:37 --------- d-----w D:\Documents and Settings\All Users\Application Data\Microsoft Corporation
2008-01-06 15:20 --------- d-----w D:\Program Files\Windows Media Connect 2
2008-01-06 14:13 --------- d-----w D:\Program Files\FrostWire
2008-01-05 16:27 --------- d-----w D:\Program Files\Windows Live Safety Center
2008-01-05 15:41 --------- d-----w D:\Documents and Settings\All Users\Application Data\OrbNetworks
2008-01-05 15:09 --------- d-----w D:\Documents and Settings\James\Application Data\Apple Computer
2008-01-05 12:43 --------- d-----w D:\Program Files\Messenger Plus! Live
2007-12-16 14:52 --------- d-----w D:\Documents and Settings\All Users\Application Data\GRETECH
2007-12-16 14:50 --------- d-----w D:\Documents and Settings\James\Application Data\GRETECH
2007-12-16 14:49 --------- d-----w D:\Program Files\GRETECH
2007-12-15 14:08 --------- d-----w D:\Documents and Settings\James\Application Data\Microsoft Games
2007-12-15 14:08 --------- d-----w D:\Documents and Settings\All Users\Application Data\Microsoft Games
2007-12-15 13:16 --------- d-----w D:\Program Files\Image-Line
2007-12-14 17:58 --------- d-----w D:\Program Files\ATCA
2007-12-12 18:28 --------- d-----w D:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-12-11 17:37 --------- d-----w D:\Program Files\VRC Runways
2007-12-11 12:56 --------- d-----w D:\Program Files\EuroScope
2007-12-10 16:31 --------- d-----w D:\Program Files\VRC
2007-12-10 11:43 --------- d-----w D:\Program Files\RivaTuner v2.06
2007-12-09 19:02 685,816 ----a-w D:\WINDOWS\system32\drivers\sptd.sys
2007-12-09 14:47 --------- d-----w D:\Program Files\Unreal3.2
2007-12-08 19:56 --------- d-----w D:\Program Files\Java
2007-12-08 16:44 --------- d-----w D:\Program Files\Lavasoft
2007-12-08 16:41 --------- d-----w D:\Program Files\Common Files\Wise Installation Wizard
2007-12-05 01:41 7,435,392 ----a-w D:\WINDOWS\system32\drivers\nv4_mini.sys
2007-09-29 08:58 96,374 ----a-w D:\Documents and Settings\All Users\Application Data\firstlsp.reg.dat
2007-08-02 23:43 90 --sh--w D:\WINDOWS\cnerolf.dat
.
Code:
<pre>
----a-w 35,842,012 2007-08-04 13:24:20 D:\Documents and Settings\James\My Documents\BitTorrent Downloads\OTHER DOWNLOADS\FlyTampa - St. Maarten for FS9 - .exe
</pre>
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}]
2007-12-13 16:49 1185120 --a------ D:\Program Files\Winamp Toolbar\winamptb.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{47833539-D0C5-4125-9FA8-0819E2EAAC93}
{381FFDE8-2394-4F90-B10D-FC6124A40F8C}
{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}
[HKEY_CLASSES_ROOT\clsid\{ebf2ba02-9094-4c5a-858b-bb198f3d8de2}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}"= D:\Program Files\Winamp Toolbar\winamptb.dll [2007-12-13 16:49 1185120]
[HKEY_CLASSES_ROOT\clsid\{ebf2ba02-9094-4c5a-858b-bb198f3d8de2}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVIDIA nTune"="D:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-07-03 11:32 81920]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="D:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 18:03 152872]
"msnmsgr"="D:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-08-16 15:19 5728112]
"Orb"="D:\Program Files\Winamp Remote\bin\OrbTray.exe" [2008-01-07 20:02 495616]
"nHancer"="D:\Program Files\nHancer\nHancer.exe" [2007-10-31 10:43 1519616]
"ctfmon.exe"="D:\WINDOWS\system32\ctfmon.exe" [2004-08-04 12:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SmartDefrag"="D:\Program Files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe" [2007-12-05 20:49 2895600]
"NvCplDaemon"="D:\WINDOWS\system32\NvCpl.dll" [2007-12-05 01:41 8523776]
"nwiz"="nwiz.exe" [2007-12-05 01:41 1626112 D:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="D:\WINDOWS\system32\NvMcTray.dll" [2007-12-05 01:41 81920]
"COMODO Firewall Pro"="D:\Program Files\Comodo\Firewall\cfp.exe" [2008-02-02 17:06 1481472]
"IntelliPoint"="d:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2007-08-31 12:01 1037736]
"itype"="d:\Program Files\Microsoft IntelliType Pro\itype.exe" [2006-11-21 17:08 813912]
"UnlockerAssistant"="D:\Program Files\Unlocker\UnlockerAssistant.exe" [2006-09-07 17:19 15872]
"avgnt"="D:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-02-04 08:23 249896]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="D:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 12:00 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"= D:\WINDOWS\system32\guard32.dll
[HKLM\~\startupfolder\D:^Documents and Settings^James^Start Menu^Programs^Startup^IMVU.lnk]
path=D:\Documents and Settings\James\Start Menu\Programs\Startup\IMVU.lnk
backup=D:\WINDOWS\pss\IMVU.lnkStartup
[HKLM\~\startupfolder\D:^Documents and Settings^James^Start Menu^Programs^Startup^OpenOffice.org 2.3.lnk]
path=D:\Documents and Settings\James\Start Menu\Programs\Startup\OpenOffice.org 2.3.lnk
backup=D:\WINDOWS\pss\OpenOffice.org 2.3.lnkStartup
[HKLM\~\startupfolder\D:^Documents and Settings^James^Start Menu^Programs^Startup^RemindMe.lnk]
path=D:\Documents and Settings\James\Start Menu\Programs\Startup\RemindMe.lnk
backup=D:\WINDOWS\pss\RemindMe.lnkStartup
[HKLM\~\startupfolder\D:^Documents and Settings^James^Start Menu^Programs^Startup^Xfire.lnk]
path=D:\Documents and Settings\James\Start Menu\Programs\Startup\Xfire.lnk
backup=D:\WINDOWS\pss\Xfire.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG7_CC]
D:\PROGRA~1\Grisoft\AVG7\avgcc.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVP]
D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
D:\Program Files\BitTorrent\bittorrent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DownloadAccelerator]
--a------ 2007-08-02 17:00 4376328 D:\Program Files\DAP\DAP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Fraps]
--a------ 2007-07-12 07:24 2928296 D:\FRAPS\FRAPS.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2004-10-13 16:24 1694208 D:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
--a------ 2007-04-09 12:23 200704 D:\Program Files\PowerISO\PWRISOVM.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-12-11 10:56 286720 D:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
-ra------ 2007-05-10 15:09 23395880 D:\Program Files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
--a------ 2007-11-16 23:42 1271032 d:\program files\steam\steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
--a------ 2008-01-26 13:22 219952 D:\Program Files\uTorrent\uTorrent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
S1 cmdGuard;COMODO Firewall Pro Sandbox Driver;D:\WINDOWS\system32\DRIVERS\cmdguard.sys [2008-02-02 17:06]
S1 cmdHlp;COMODO Firewall Pro Helper Driver;D:\WINDOWS\system32\DRIVERS\cmdhlp.sys [2008-02-02 17:06]
S1 ndiswann;ndiswann;D:\WINDOWS\system32\drivers\ndiswann.sys [2008-02-02 21:29]
S3 avfwim;AvFw Packet Filter Miniport;D:\WINDOWS\system32\DRIVERS\avfwim.sys []
S3 USB_RNDIS_XP;Linksys Wireless-G USB Network Adapter with SpeedBooster Driver;D:\WINDOWS\system32\DRIVERS\usb8023.sys [2004-08-04 12:00]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5d360e3a-6602-11dc-8b23-00179a80aac4}]
\Shell\AutoRun\command - E:\setupSNK.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-02-02 19:35:00 D:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- D:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-02-03 22:00:00 D:\WINDOWS\Tasks\SmartDefrag.job"
- D:\Program Files\IObit\IObit SmartDefrag\schedule.exe
"2008-02-03 16:53:14 D:\WINDOWS\Tasks\ZoneAlarm Security.job"
- D:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-02-04 10:10:03
Windows 5.1.2600 Service Pack 2 NTFS
detected NTDLL code modification:
ZwClose
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: D:\WINDOWS\system32\winlogon.exe
-> D:\WINDOWS\system32\guard32.dll
PROCESS: D:\WINDOWS\system32\lsass.exe [5.01.2600.2180]
-> D:\WINDOWS\system32\guard32.dll
PROCESS: D:\WINDOWS\Explorer.EXE [6.00.2900.3156]
-> D:\WINDOWS\system32\guard32.dll
-> D:\Program Files\WinRAR\rarext.dll
.
------------------------ Other Running Processes ------------------------
.
D:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
.
**************************************************************************
.
Completion time: 2008-02-04 10:15:49 - machine was rebooted
.
2008-02-02 18:22:22 --- E O F ---
------------------------------------------