Combo Fix
Combo fix Log
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.303 [GMT 5.5:30]
Running from: C:\Documents and Settings\Amit Verma\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\RECYCLER\Desktop__.ini
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\b1
C:\WINDOWS\system32\c1
C:\WINDOWS\system32\Cache
C:\WINDOWS\system32\csdgvurs.dll
C:\WINDOWS\system32\d1
C:\WINDOWS\system32\FrmInst.exe.exe
C:\WINDOWS\system32\g2
C:\WINDOWS\system32\i2
C:\WINDOWS\system32\m8
C:\WINDOWS\system32\n8
D:\RECYCLER\Desktop__.ini
E:\RECYCLER\Desktop__.ini
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_CORE
((((((((((((((((((((((((( Files Created from 2007-11-08 to 2007-12-08 )))))))))))))))))))))))))))))))
.
2007-12-08 20:44 . 2007-12-08 20:44 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-12-08 20:43 . 2007-12-08 20:43 <DIR> d-------- C:\Documents and Settings\Amit Verma\Application Data\SUPERAntiSpyware.com
2007-12-08 12:48 . 2007-12-08 19:55 <DIR> d-------- C:\VundoFix Backups
2007-12-08 00:45 . 2007-12-08 00:45 <DIR> d-------- C:\Documents and Settings\Amit Verma\Application Data\IsolatedStorage
2007-12-07 18:44 . 2007-12-07 18:44 834,100 --ahs---- C:\WINDOWS\system32\srmiftby.ini
2007-12-06 10:43 . 2007-12-06 10:43 807,468 --ahs---- C:\WINDOWS\system32\mfaidktg.ini
2007-12-06 08:42 . 2007-12-06 08:42 <DIR> d-------- C:\Program Files\Common Files\Blizzard Entertainment
2007-12-05 10:42 . 2007-12-05 10:42 805,321 --ahs---- C:\WINDOWS\system32\qphlvahl.ini
2007-12-05 08:41 . 2007-12-05 08:41 159 --a------ C:\WINDOWS\wininit.ini
2007-12-05 08:09 . 2007-12-05 08:10 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-04 10:41 . 2007-12-04 10:41 788,468 --ahs---- C:\WINDOWS\system32\evbengsv.ini
2007-12-03 10:39 . 2007-12-03 10:39 793,664 --ahs---- C:\WINDOWS\system32\yalqodxb.ini
2007-12-01 07:53 . 2007-12-01 07:53 140 --a------ C:\WINDOWS\system32\spupdsvc.inf
2007-12-01 02:21 . 2007-12-01 02:23 793,776 --ahs---- C:\WINDOWS\system32\vcvgmcwa.ini
2007-11-30 19:10 . 2006-05-05 15:11 453,120 -----c--- C:\WINDOWS\system32\dllcache\mrxsmb.sys
2007-11-30 18:54 . 2007-11-30 19:07 793,673 --ahs---- C:\WINDOWS\system32\jiblaslu.ini
2007-11-29 18:51 . 2007-11-29 18:51 789,924 --ahs---- C:\WINDOWS\system32\ctlgyelq.ini
2007-11-28 11:30 . 2007-11-28 11:30 778,054 --ahs---- C:\WINDOWS\system32\xtdwjsbu.ini
2007-11-28 07:44 . 2007-02-28 14:40 2,180,352 -----c--- C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2007-11-28 07:44 . 2007-02-28 14:38 2,136,064 -----c--- C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2007-11-28 07:44 . 2007-02-28 14:08 2,057,600 -----c--- C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2007-11-28 07:44 . 2007-02-28 14:08 2,015,744 -----c--- C:\WINDOWS\system32\dllcache\ntkrpamp.exe
2007-11-27 21:21 . 2007-11-27 21:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-11-27 21:20 . 2007-12-08 20:42 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-11-27 10:20 . 2007-11-27 10:30 780,814 --ahs---- C:\WINDOWS\system32\imexavcy.ini
2007-11-26 19:58 . 2007-11-27 04:36 <DIR> d--hs---- C:\WINDOWS\Q1M
2007-11-26 08:15 . 2007-11-26 20:52 776,210 --ahs---- C:\WINDOWS\system32\ibvybxby.ini
2007-11-25 05:26 . 2007-11-26 07:36 775,970 --ahs---- C:\WINDOWS\system32\dnhwfotv.ini
2007-11-24 20:45 . 2007-11-24 20:45 <DIR> d-------- C:\Program Files\Windows Defender
2007-11-24 05:24 . 2007-11-24 20:39 775,946 --ahs---- C:\WINDOWS\system32\fbxvhafb.ini
2007-11-22 10:54 . 2007-11-27 22:42 321 --ahs---- C:\WINDOWS\system32\xbeeg.ini
2007-11-14 04:04 . 2007-11-14 04:04 <DIR> d-------- C:\Documents and Settings\Amit Verma\Application Data\Scooter Software
2007-11-10 20:44 . 2007-12-08 13:46 <DIR> d-------- C:\quarantine
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-08 17:58 --------- d-----w C:\Documents and Settings\Amit Verma\Application Data\Skype
2007-11-26 03:11 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-11-23 02:24 --------- d-----w C:\Program Files\Common Files\InstallShield
2007-11-07 06:12 --------- d-----w C:\Program Files\ZohoMeeting
2007-11-06 14:54 --------- d-----w C:\Program Files\JETSTAT.COM
2007-11-05 14:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\Red Gate
2007-11-02 16:53 --------- d-----w C:\Documents and Settings\Amit Verma\Application Data\Microsoft FxCop
2007-11-02 16:48 --------- d-----w C:\Program Files\Microsoft FxCop 1.35
2007-11-02 16:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-10-28 14:02 --------- d-----w C:\Documents and Settings\Amit Verma\Application Data\Media Player Classic
2007-10-28 14:01 --------- d-----w C:\Program Files\K-Lite Codec Pack
2007-10-23 07:19 --------- d-----w C:\Documents and Settings\Amit Verma\Application Data\Etasoft Inc
2007-10-15 16:48 --------- d-----w C:\Program Files\Citrix
2007-09-27 10:18 6,133,312 ----a-w C:\Documents and Settings\Amit Verma\POWERPNT.EXE.exe
2007-09-27 10:10 9 --sha-r C:\Program Files\Desktop__.ini
2007-09-26 09:25 196,152 ----a-w C:\Documents and Settings\Amit Verma\OUTLOOK.EXE.exe
2007-09-25 07:38 157,696 ----a-w C:\ipmsg.exe
2007-09-24 07:43 1,564,672 ----a-w C:\Documents and Settings\Amit Verma\TortoiseAct.exe.exe
2007-09-22 09:37 734,872 ----a-w C:\Documents and Settings\Amit Verma\AdobeCollabSync.exe.exe
2007-09-22 06:36 204,845 ----a-w C:\Documents and Settings\Amit Verma\realplay.exe.exe
2007-09-22 05:58 53,248 ----a-w C:\Documents and Settings\Amit Verma\AzMixerSel.exe.exe
2007-09-22 05:58 286,720 ----a-w C:\Documents and Settings\Amit Verma\QTTask.exe.exe
2007-09-22 05:42 7,671,876 ----a-w C:\Documents and Settings\Amit Verma\AcroRd32.exe.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{977ED744-96FE-44F1-B015-BED5591B82B0}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E30EE3B9-A23F-421D-838E-94800D092249}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseSVN]
@={30351346-7B7D-4FCC-81B4-1E394CA267EB}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseSVN]
@={30351347-7B7D-4FCC-81B4-1E394CA267EB}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseSVN]
@={30351348-7B7D-4FCC-81B4-1E394CA267EB}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseSVN]
@={3035134B-7B7D-4FCC-81B4-1E394CA267EB}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseSVN]
@={3035134C-7B7D-4FCC-81B4-1E394CA267EB}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseSVN]
@={3035134D-7B7D-4FCC-81B4-1E394CA267EB}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseSVN]
@={3035134E-7B7D-4FCC-81B4-1E394CA267EB}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Offline Files]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\TortoiseCVS0]
@={5d1cb710-1c4b-11d4-bed5-005004b1f42f}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\TortoiseCVS1]
@={5d1cb711-1c4b-11d4-bed5-005004b1f42f}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\TortoiseCVS2]
@={5d1cb712-1c4b-11d4-bed5-005004b1f42f}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\TortoiseCVS3]
@={5d1cb713-1c4b-11d4-bed5-005004b1f42f}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\TortoiseCVS4]
@={5d1cb714-1c4b-11d4-bed5-005004b1f42f}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\TortoiseCVS5]
@={5d1cb715-1c4b-11d4-bed5-005004b1f42f}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\TortoiseCVS6]
@={5d1cb716-1c4b-11d4-bed5-005004b1f42f}
[HKEY_CLASSES_ROOT\CLSID\{30351346-7B7D-4FCC-81B4-1E394CA267EB}]
2007-06-09 13:42 536576 --a------ D:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_CLASSES_ROOT\CLSID\{30351347-7B7D-4FCC-81B4-1E394CA267EB}]
2007-06-09 13:42 536576 --a------ D:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_CLASSES_ROOT\CLSID\{30351348-7B7D-4FCC-81B4-1E394CA267EB}]
2007-06-09 13:42 536576 --a------ D:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_CLASSES_ROOT\CLSID\{3035134B-7B7D-4FCC-81B4-1E394CA267EB}]
2007-06-09 13:42 536576 --a------ D:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_CLASSES_ROOT\CLSID\{3035134C-7B7D-4FCC-81B4-1E394CA267EB}]
2007-06-09 13:42 536576 --a------ D:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_CLASSES_ROOT\CLSID\{3035134D-7B7D-4FCC-81B4-1E394CA267EB}]
2007-06-09 13:42 536576 --a------ D:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_CLASSES_ROOT\CLSID\{3035134E-7B7D-4FCC-81B4-1E394CA267EB}]
2007-06-09 13:42 536576 --a------ D:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_CLASSES_ROOT\CLSID\{5d1cb710-1c4b-11d4-bed5-005004b1f42f}]
2007-03-15 21:50 1073152 --a------ E:\Program Files\TortoiseCVS\TrtseShl.dll
[HKEY_CLASSES_ROOT\CLSID\{5d1cb711-1c4b-11d4-bed5-005004b1f42f}]
2007-03-15 21:50 1073152 --a------ E:\Program Files\TortoiseCVS\TrtseShl.dll
[HKEY_CLASSES_ROOT\CLSID\{5d1cb712-1c4b-11d4-bed5-005004b1f42f}]
2007-03-15 21:50 1073152 --a------ E:\Program Files\TortoiseCVS\TrtseShl.dll
[HKEY_CLASSES_ROOT\CLSID\{5d1cb713-1c4b-11d4-bed5-005004b1f42f}]
2007-03-15 21:50 1073152 --a------ E:\Program Files\TortoiseCVS\TrtseShl.dll
[HKEY_CLASSES_ROOT\CLSID\{5d1cb714-1c4b-11d4-bed5-005004b1f42f}]
2007-03-15 21:50 1073152 --a------ E:\Program Files\TortoiseCVS\TrtseShl.dll
[HKEY_CLASSES_ROOT\CLSID\{5d1cb715-1c4b-11d4-bed5-005004b1f42f}]
2007-03-15 21:50 1073152 --a------ E:\Program Files\TortoiseCVS\TrtseShl.dll
[HKEY_CLASSES_ROOT\CLSID\{5d1cb716-1c4b-11d4-bed5-005004b1f42f}]
2007-03-15 21:50 1073152 --a------ E:\Program Files\TortoiseCVS\TrtseShl.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SybaseCentral43"="D:\Program Files\Sybase\Shared\Sybase Central 4.3\win32\scjview.exe" [2004-01-14 14:30]
"DBISQL9"="D:\Program Files\Sybase\SQL Anywhere 9\win32\dbisqlg.exe" [2004-01-26 18:09]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 17:30]
"SpybotSD TeaTimer"="D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46]
"SUPERAntiSpyware"="D:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ShStatEXE"="D:\Program Files\Network Associates\VirusScan\SHSTAT.exe" [2004-08-18 08:00]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2006-06-13 07:27]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2006-06-13 07:27]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2006-06-13 07:27]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-04-29 06:13]
"RTHDCPL"="RTHDCPL.EXE" [2006-07-19 07:12 C:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-07-19 07:12 C:\WINDOWS\SkyTel.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 17:30 C:\WINDOWS\system32\bthprops.cpl]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-09-05 23:29]
"McAfeeUpdaterUI"="C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" [2004-08-25 03:50]
"QuickTime Task"="D:\Program Files\QuickTime\qttask.exe" [2007-06-29 06:24]
"Acrobat Assistant 8.0"="D:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2007-05-10 22:46]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"nvscv32"="C:\WINDOWS\system32\drivers\ncscv32.exe" []
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 16:38]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= D:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
D:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 D:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tuvsrsp]
tuvsrsp.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
backup=C:\WINDOWS\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Synchronizer.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Synchronizer.lnk
backup=C:\WINDOWS\pss\Adobe Acrobat Synchronizer.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
backup=C:\WINDOWS\pss\Bluetooth.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ipmsg.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ipmsg.lnk
backup=C:\WINDOWS\pss\ipmsg.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Service Manager.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Service Manager.lnk
backup=C:\WINDOWS\pss\Service Manager.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0]
2007-05-10 22:46 624248 --a------ D:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
ALCMTR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AzMixerSel]
C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BroadcomWireless]
C:\Program Files\Broadcom\Wireless\Utility\WlanUtil.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DBISQL9]
D:\Program Files\Sybase\SQL Anywhere 9\win32\dbisqlg.exe -preload
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\googletalk]
C:\Program Files\Google\Google Talk\googletalk.exe /autostart
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
2006-06-13 07:27 77824 -ra------ C:\WINDOWS\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
2006-06-13 07:27 118784 -ra------ C:\WINDOWS\system32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]
2006-06-13 07:27 94208 -ra------ C:\WINDOWS\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
C:\Program Files\MSN Messenger\MsnMsgr.Exe /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nvscv32]
C:\WINDOWS\system32\drivers\ncscv32.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
D:\Program Files\QuickTime\qttask.exe -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
RTHDCPL.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
SkyTel.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SybaseCentral43]
D:\Program Files\Sybase\Shared\Sybase Central 4.3\win32\scjview.exe -preload
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
2006-04-29 06:13 766041 --a------ C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot
R1 NaiAvTdi1;NaiAvTdi1;C:\WINDOWS\system32\drivers\mvstdi5x.sys
R2 SMTPSVC;Simple Mail Transfer Protocol (SMTP);C:\WINDOWS\system32\inetsrv\inetinfo.exe
S3 ANTS Profiler 3 Service;ANTS Profiler 3 Service;"D:\Program Files\Red Gate\ANTS Profiler 3\RedGate.Profiler.IISProfileHost.exe"
S3 btwaudio;Bluetooth Audio Device Service;C:\WINDOWS\system32\drivers\btwaudio.sys
S3 btwavdt;Bluetooth AVDT;C:\WINDOWS\system32\drivers\btwavdt.sys
S3 SQLWriter;SQL Server VSS Writer;"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
S4 msvsmon80;Visual Studio 2005 Remote Debugger;"D:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe" /service msvsmon80
*Newly Created Service* - ENTDRV51
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{43564368-4375-8601-4371-458454791235]
C:\WINDOWS\system32\tcpconn.exe /r
.
Contents of the 'Scheduled Tasks' folder
"2007-12-08 18:28:26 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************
catchme 0.3.1331 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-12-08 23:57:08
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-08 23:59:49 - machine was rebooted
.
--- E O F ---