flec006.exe appeared in the process list yesterday. Disappeared when i used Combofix the first time though.
Here's the combofix log:
ComboFix 08-01-18.5 - g3k0 2008-01-19 15:25:52.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1257.1.1033.18.660 [GMT 2:00]
Running from: C:\Documents and Settings\g3k0\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\g3k0\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE
C:\WINDOWS\system32\drivers\hldrrr.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\drivers\hldrrr.exe
C:\WINDOWS\system32\drivers\srosa.sys
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_SROSA
-------\srosa
((((((((((((((((((((((((( Files Created from 2007-12-19 to 2008-01-19 )))))))))))))))))))))))))))))))
.
2008-01-18 19:58 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-18 19:20 . 2008-01-18 19:20 250 --a------ C:\WINDOWS\gmer.ini
2008-01-18 19:08 . 2008-01-18 19:08 <DIR> d-------- C:\Program Files\OpenYahtzee
2008-01-17 17:45 . 2008-01-17 17:45 <DIR> d--h----- C:\Documents and Settings\g3k0\Application Data\m
2008-01-17 13:35 . 2008-01-17 13:35 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-01-17 13:35 . 2008-01-17 13:35 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-01-17 13:31 . 2008-01-17 13:31 <DIR> d-------- C:\Program Files\Trend Micro
2008-01-16 22:16 . 2008-01-16 22:14 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2008-01-16 22:14 . 2007-07-10 16:26 <DIR> d-------- C:\IceSword122en
2008-01-16 22:13 . 2008-01-16 22:17 <DIR> d-------- C:\Documents and Settings\g3k0\.housecall6.6
2008-01-16 22:06 . 2008-01-18 20:55 <DIR> d-------- C:\backupregistry
2008-01-16 20:32 . 2008-01-16 20:33 <DIR> d-------- C:\Documents and Settings\g3k0\Application Data\PrevxCSI
2008-01-16 20:32 . 2008-01-16 20:32 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Prevx
2008-01-16 20:27 . 2008-01-16 20:27 <DIR> d-------- C:\Program Files\EsetOnlineScanner
2008-01-16 17:13 . 2008-01-19 15:19 <DIR> d-------- C:\WINDOWS\system32\drivers\down
2008-01-15 21:11 . 2008-01-15 21:11 921,654 --a------ C:\BG12.bmp
2008-01-15 16:42 . 2008-01-15 16:42 <DIR> d-------- C:\Program Files\EA Sports
2008-01-14 16:55 . 2005-08-22 19:00 682,055,680 --a------ C:\sims2-cd1.ISO
2008-01-13 16:59 . 2008-01-13 16:59 921,654 --a------ C:\BG23.bmp
2008-01-12 23:13 . 2008-01-12 23:13 921,654 --a------ C:\BG44.bmp
2008-01-12 23:08 . 2008-01-12 23:08 3,817,014 --a------ C:\WINDOWS\Susie_g3k0_WP.BMP
2008-01-06 13:57 . 2008-01-13 19:57 <DIR> d-------- C:\Program Files\Lineage II
2008-01-04 02:34 . 2008-01-04 02:43 <DIR> d-------- C:\Program Files\Blaze Media Pro
2008-01-02 18:07 . 2008-01-02 18:07 <DIR> d-------- C:\Program Files\ZhyperMU
2008-01-02 03:32 . 2008-01-02 03:32 <DIR> d-------- C:\Program Files\CDex_150
2008-01-02 03:29 . 2008-01-19 03:09 <DIR> d-------- C:\Program Files\Tsukihime
2008-01-02 03:28 . 2008-01-02 03:28 <DIR> d-------- C:\TYPE-MOON
2007-12-31 17:45 . 2008-01-16 16:37 <DIR> d-------- C:\InfinityProject
2007-12-31 02:33 . 2007-12-31 03:15 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\FALCOM
2007-12-30 20:42 . 2007-12-30 20:42 <DIR> d-------- C:\Program Files\PROJECT YNP
2007-12-30 00:48 . 2007-12-30 01:26 <DIR> d-------- C:\Program Files\Pcsx2_0.9.4
2007-12-29 18:17 . 2007-12-29 18:17 <DIR> d-------- C:\Program Files\Puzzle Quest
2007-12-29 18:12 . 2007-12-29 18:12 <DIR> d-------- C:\WINDOWS\Puzzle Quest Challenge of the Warlords DeLEGiON
2007-12-29 18:12 . 2007-12-29 18:18 <DIR> d-------- C:\Program Files\Puzzle Quest Challenge of the Warlords DeLEGiON
2007-12-29 16:23 . 2007-12-29 16:23 27 --a------ C:\WINDOWS\MP32SWF.INI
2007-12-28 16:41 . 2007-12-28 16:41 <DIR> d-------- C:\Documents and Settings\g3k0\Application Data\Leadertech
2007-12-28 03:24 . 2007-12-28 03:24 <DIR> d-------- C:\Program Files\Flash Movie Player
2007-12-27 05:25 . 2007-12-27 05:25 <DIR> d-------- C:\Program Files\WinSWF Extractor
2007-12-27 05:09 . 2007-12-27 05:14 125 --a------ C:\WINDOWS\fd3.INI
2007-12-26 21:04 . 2007-12-26 21:04 <DIR> d-------- C:\Program Files\7-Zip
2007-12-25 14:27 . 2007-12-25 14:27 <DIR> d-------- C:\NVIDIA
2007-12-25 04:22 . 2007-12-25 04:22 <DIR> d-------- C:\Program Files\Oblivion Face Exchange Lite
2007-12-24 14:51 . 2007-12-24 14:51 <DIR> d-------- C:\Program Files\Bethesda Softworks
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-19 13:13 --------- d-----w C:\Program Files\Logitech
2008-01-19 01:22 --------- d-----w C:\Program Files\FlashGet
2008-01-18 22:12 --------- d-----w C:\Program Files\StepMania
2008-01-16 21:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-16 15:13 --------- d-----w C:\Program Files\eMule
2008-01-16 14:58 --------- d-----w C:\Program Files\NoteWorthy Composer
2008-01-13 19:24 --------- d-----w C:\Program Files\Electronic Arts
2008-01-12 19:42 --------- d-----w C:\Program Files\SuperCleaner
2008-01-12 19:36 --------- d-----w C:\Program Files\9Dragons
2008-01-06 11:57 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-04 00:43 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-31 01:15 --------- d-----w C:\Documents and Settings\g3k0\Application Data\FALCOM
2007-12-31 01:08 --------- d-----w C:\Program Files\QuickTime
2007-12-31 00:31 --------- d-----w C:\Program Files\Lilian
2007-12-30 18:45 --------- d-----w C:\Program Files\Debugging Tools for Windows
2007-12-28 14:44 --------- d-----w C:\Program Files\SpeedFan
2007-12-28 14:42 --------- d-----w C:\Program Files\DivX
2007-12-28 14:41 --------- d-----w C:\Documents and Settings\g3k0\Application Data\Desperate Housewives
2007-12-24 00:47 --------- d-----w C:\Program Files\Winamp
2007-12-23 00:55 --------- d-----w C:\Program Files\mIRC
2007-12-18 16:21 --------- d-----w C:\Program Files\Araneae 5
2007-12-17 17:26 --------- d-----w C:\Program Files\Microsoft Works
2007-12-17 17:26 --------- d-----w C:\Program Files\Microsoft ActiveSync
2007-12-17 17:26 --------- d-----w C:\Program Files\Common Files\L&H
2007-12-17 16:34 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2007-12-16 17:33 --------- d-----w C:\Program Files\DVDVIDEOSOFT
2007-12-16 17:32 --------- d-----w C:\Program Files\Free Music Zilla
2007-12-16 17:31 --------- d-----w C:\Documents and Settings\g3k0\Application Data\FMZilla
2007-12-16 03:13 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-12-15 21:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\nView_Profiles
2007-12-08 20:16 --------- d-----w C:\Program Files\NoteWorthy Player
2007-12-07 22:05 --------- d-----w C:\Program Files\Finale NotePad 2008
2007-12-05 11:45 104,064 ----a-w C:\WINDOWS\system32\drivers\Rtenicxp.sys
2007-12-04 23:41 7,435,392 ----a-w C:\WINDOWS\system32\drivers\nv4_mini.sys
2007-12-03 18:44 --------- d-----w C:\Program Files\AusLogics Disk Defrag
2007-12-01 02:48 --------- d-----w C:\Program Files\Elecard MPEG2 Decoder Package 2.0
2007-12-01 02:46 --------- d-----w C:\Program Files\Haali
2007-12-01 02:45 --------- d-----w C:\Program Files\Xvid
2007-11-29 12:41 --------- d-----w C:\Program Files\Eidos
2007-11-27 21:50 --------- d-----w C:\Documents and Settings\g3k0\Application Data\LimeWire
2007-11-26 20:04 --------- d-----w C:\Program Files\ffdshow
2007-11-25 21:09 --------- d-----w C:\Program Files\RegCure
2007-11-25 18:18 737,280 ----a-w C:\WINDOWS\iun6002.exe
2007-11-25 13:21 --------- d-----w C:\Program Files\VstPlugins
2007-11-25 13:21 --------- d-----w C:\Program Files\Image-Line
2007-11-25 12:18 --------- d-----w C:\Program Files\RivaTuner v2.06
2007-11-24 18:17 --------- d-----w C:\Program Files\MixMeister BPM Analyzer
2007-11-24 14:33 --------- d-----w C:\Program Files\IDT
2007-11-24 14:14 --------- d-----w C:\Program Files\SiSoftware
2007-11-22 14:48 --------- d-----w C:\Program Files\Your Company Name
2007-11-21 16:51 --------- d-----w C:\Documents and Settings\All Users\Application Data\Autodata Limited
2007-11-21 16:50 --------- d-----w C:\Program Files\Common Files\Autodata Limited Shared
2007-11-13 17:53 65,536 ----a-w C:\WINDOWS\IFinst27.exe
2007-10-28 14:11 769,536 ----a-w C:\Documents and Settings\g3k0\Application Data\sfdnwin.dll
2006-08-12 15:58 56 --sha-r C:\WINDOWS\system32\985915E552.sys
2006-08-12 15:58 2,516 -csha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((( snapshot_2008-01-19_15.08.00.26 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-19 12:54:54 1,417,216 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000001\NTUSER.DAT
+ 2008-01-19 13:25:35 1,417,216 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000001\NTUSER.DAT
- 2008-01-19 12:54:54 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000002\UsrClass.dat
+ 2008-01-19 13:25:35 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000002\UsrClass.dat
- 2008-01-19 12:54:55 20,500,480 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000003\NTUSER.DAT
+ 2008-01-19 13:25:36 20,508,672 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000003\NTUSER.DAT
- 2008-01-19 12:54:55 303,104 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000004\UsrClass.dat
+ 2008-01-19 13:25:36 303,104 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000004\UsrClass.dat
+ 2008-01-19 13:16:36 8,035 ----a-w C:\WINDOWS\system32\drivers\down\122812.exe
+ 2008-01-19 13:16:58 8,085 ----a-w C:\WINDOWS\system32\drivers\down\143984.exe
+ 2008-01-19 13:17:07 6,958 ----a-w C:\WINDOWS\system32\drivers\down\153203.exe
+ 2008-01-19 13:18:25 34,214 ----a-w C:\WINDOWS\system32\drivers\down\198578.exe
+ 2008-01-19 13:18:31 7,896 ----a-w C:\WINDOWS\system32\drivers\down\237468.exe
+ 2008-01-19 13:18:44 30,828 ----a-w C:\WINDOWS\system32\drivers\down\249234.exe
+ 2008-01-19 13:19:20 29,509 ----a-w C:\WINDOWS\system32\drivers\down\285781.exe
+ 2008-01-19 13:19:28 9,761 ----a-w C:\WINDOWS\system32\drivers\down\294015.exe
+ 2008-01-19 13:15:25 70,660 ----a-w C:\WINDOWS\system32\drivers\down\46703.exe
+ 2008-01-19 13:15:30 483,844 ----a-w C:\WINDOWS\system32\drivers\down\51968.exe
+ 2008-01-19 13:15:32 13,824 ----a-w C:\WINDOWS\system32\drivers\down\57671.exe
+ 2008-01-19 13:15:36 657,412 ----a-w C:\WINDOWS\system32\drivers\down\58796.exe
+ 2008-01-19 13:16:15 70,660 ----a-w C:\WINDOWS\system32\drivers\down\63843.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseSVN]
@={30351346-7B7D-4FCC-81B4-1E394CA267EB}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseSVN]
@={30351347-7B7D-4FCC-81B4-1E394CA267EB}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseSVN]
@={30351348-7B7D-4FCC-81B4-1E394CA267EB}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseSVN]
@={3035134B-7B7D-4FCC-81B4-1E394CA267EB}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseSVN]
@={3035134C-7B7D-4FCC-81B4-1E394CA267EB}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseSVN]
@={3035134D-7B7D-4FCC-81B4-1E394CA267EB}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseSVN]
@={3035134E-7B7D-4FCC-81B4-1E394CA267EB}
[HKEY_CLASSES_ROOT\CLSID\{30351346-7B7D-4FCC-81B4-1E394CA267EB}]
2007-08-26 10:40 536576 --a------ C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_CLASSES_ROOT\CLSID\{30351347-7B7D-4FCC-81B4-1E394CA267EB}]
2007-08-26 10:40 536576 --a------ C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_CLASSES_ROOT\CLSID\{30351348-7B7D-4FCC-81B4-1E394CA267EB}]
2007-08-26 10:40 536576 --a------ C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_CLASSES_ROOT\CLSID\{3035134B-7B7D-4FCC-81B4-1E394CA267EB}]
2007-08-26 10:40 536576 --a------ C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_CLASSES_ROOT\CLSID\{3035134C-7B7D-4FCC-81B4-1E394CA267EB}]
2007-08-26 10:40 536576 --a------ C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_CLASSES_ROOT\CLSID\{3035134D-7B7D-4FCC-81B4-1E394CA267EB}]
2007-08-26 10:40 536576 --a------ C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_CLASSES_ROOT\CLSID\{3035134E-7B7D-4FCC-81B4-1E394CA267EB}]
2007-08-26 10:40 536576 --a------ C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 14:00 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-11-16 19:04 139264]
"mule_st_key"="C:\Documents and Settings\g3k0\Application Data\m\flec006.exe" [2005-04-04 02:06 859580]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11 132496]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 19:42 32768]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2008-01-19 15:31 950664]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 00:47 31016]
"Samsung Common SM"="C:\WINDOWS\Samsung\ComSMMgr\ssmmgr.exe" [2005-07-03 09:20 372736]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
"amd_dc_opt"="C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2006-11-17 15:49 77824]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-03 21:32 208952]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 15:40 155648]
"Name of App"="C:\Program Files\SAMSUNG\FW LiveUpdate\FWManager.exe" [2007-04-05 15:29 684118]
"DAEMON Tools-1033"="C:\Program Files\D-Tools\daemon.exe" [2004-08-22 17:05 81920]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 01:41 8523776]
"nwiz"="nwiz.exe" [2007-12-05 01:41 1626112 C:\WINDOWS\system32\nwiz.exe]
"IMEKRMIG6.1"="C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE" [2002-09-02 02:00 44032]
"SysTrayApp"="C:\Program Files\IDT\WDM\sttray.exe" [2007-08-16 19:33 405504]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-12-05 01:41 81920]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 14:00 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AutorunsDisabled]
WgaLogon.dll 2007-03-15 18:17 183808 C:\WINDOWS\system32\WgaLogon.dll
SafeBoot registry key needs repairs. This machine cannot enter Safe Mode.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system]
@="Driver Group"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vgasave.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}]
@="DiskDrive"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
@="Hdc"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
@="Keyboard"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
@="Mouse"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
@="System"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
@="Volume"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeUpdater]
--a------ 2007-02-28 22:06 2321600 C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Creative Detector]
--a------ 2004-12-02 17:23 102400 C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM]
--a------ 2006-05-16 10:58 213936 C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
--a------ 2006-05-16 10:58 213936 C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
--a------ 2006-05-16 10:58 86960 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MessengerPlus3]
C:\Program Files\MessengerPlus! 3\MsgPlus.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SweetIM]
C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\zBrowser Launcher]
C:\Program Files\Logitech\iTouch\iTouch.exe
R2 GVCplDrv;GVCplDrv;C:\WINDOWS\system32\drivers\GVCplDrv.sys [2002-08-08 03:41]
S3 EMVSCARD;EMVSCARD;C:\WINDOWS\system32\Drivers\EMVSCARD.sys []
S3 FXDRV;FXDRV;D:\Fxdrv.sys []
S3 PPJoyBus;Parallel Port Joystick Bus device driver;C:\WINDOWS\system32\drivers\PPJoyBus.sys [2004-10-24 08:11]
S3 SndTDriverV32;SndTDriverV32;C:\WINDOWS\system32\drivers\SndTDriverV32.sys [2006-12-13 18:02]
S3 SQLWriter;SQL Server VSS Writer;"c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" [2005-10-14 02:53]
S3 XDva039;XDva039;C:\WINDOWS\system32\XDva039.sys []
.
Contents of the 'Scheduled Tasks' folder
"2008-01-19 13:34:38 C:\WINDOWS\Tasks\RegCure Program Check.job"
- C:\Program Files\RegCure\RegCure.exe
"2008-01-03 01:00:00 C:\WINDOWS\Tasks\RegCure.job"
- C:\Program Files\RegCure\RegCure.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-19 15:34:54
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-19 15:40:24 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-19 13:40:22
ComboFix2.txt 2008-01-19 13:08:14
ComboFix3.txt 2008-01-18 18:14:29
.
2008-01-12 11:10:59 --- E O F ---