ComboFix
ok. I manage to run ComboFix once after repeated Panda active online scan. It doesn't help much as the Mdelk.exe comes back again and ComboFix is again not a valid Win32 application (as I can see the icon is "blinking", if you knwo what I mean)
The following is the ComboFix.txt
ComboFix 08-02.03.1 - ycchen100 2008-02-03 15:07:45.1 -
FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.2.950.1.1028.18.414 [GMT 8:00]
執行位置?: D:\ycchen\downloads\ComboFix.exe
* 已建立新的還原點
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
/wow section - STAGE 4
/wow section unfinished
(((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\boot.ini
C:\WINDOWS\system32\drivers\down
C:\WINDOWS\system32\drivers\down\1000819.exe
C:\WINDOWS\system32\drivers\down\1011364.exe
C:\WINDOWS\system32\drivers\down\1020847.exe
C:\WINDOWS\system32\drivers\down\11456263.exe
C:\WINDOWS\system32\drivers\down\11458446.exe
C:\WINDOWS\system32\drivers\down\11466127.exe
C:\WINDOWS\system32\drivers\down\11471124.exe
C:\WINDOWS\system32\drivers\down\11477874.exe
C:\WINDOWS\system32\drivers\down\11480938.exe
C:\WINDOWS\system32\drivers\down\11516359.exe
C:\WINDOWS\system32\drivers\down\11527615.exe
C:\WINDOWS\system32\drivers\down\11538060.exe
C:\WINDOWS\system32\drivers\down\121334.exe
C:\WINDOWS\system32\drivers\down\14913744.exe
C:\WINDOWS\system32\drivers\down\14955464.exe
C:\WINDOWS\system32\drivers\down\15033236.exe
C:\WINDOWS\system32\drivers\down\15033917.exe
C:\WINDOWS\system32\drivers\down\15049950.exe
C:\WINDOWS\system32\drivers\down\15059744.exe
C:\WINDOWS\system32\drivers\down\15067996.exe
C:\WINDOWS\system32\drivers\down\15071291.exe
C:\WINDOWS\system32\drivers\down\15093863.exe
C:\WINDOWS\system32\drivers\down\15111939.exe
C:\WINDOWS\system32\drivers\down\15120912.exe
C:\WINDOWS\system32\drivers\down\15123085.exe
C:\WINDOWS\system32\drivers\down\15125599.exe
C:\WINDOWS\system32\drivers\down\15132118.exe
C:\WINDOWS\system32\drivers\down\15149674.exe
C:\WINDOWS\system32\drivers\down\15152548.exe
C:\WINDOWS\system32\drivers\down\15201328.exe
C:\WINDOWS\system32\drivers\down\15222909.exe
C:\WINDOWS\system32\drivers\down\15231381.exe
C:\WINDOWS\system32\drivers\down\157676.exe
C:\WINDOWS\system32\drivers\down\170234.exe
C:\WINDOWS\system32\drivers\down\204874.exe
C:\WINDOWS\system32\drivers\down\210202.exe
C:\WINDOWS\system32\drivers\down\259713.exe
C:\WINDOWS\system32\drivers\down\273122.exe
C:\WINDOWS\system32\drivers\down\280433.exe
C:\WINDOWS\system32\drivers\down\281314.exe
C:\WINDOWS\system32\drivers\down\313881.exe
C:\WINDOWS\system32\drivers\down\318427.exe
C:\WINDOWS\system32\drivers\down\325848.exe
C:\WINDOWS\system32\drivers\down\327020.exe
C:\WINDOWS\system32\drivers\down\334060.exe
C:\WINDOWS\system32\drivers\down\336854.exe
C:\WINDOWS\system32\drivers\down\345366.exe
C:\WINDOWS\system32\drivers\down\366677.exe
C:\WINDOWS\system32\drivers\down\378824.exe
C:\WINDOWS\system32\drivers\down\381879.exe
C:\WINDOWS\system32\drivers\down\382790.exe
C:\WINDOWS\system32\drivers\down\384953.exe
C:\WINDOWS\system32\drivers\down\390511.exe
C:\WINDOWS\system32\drivers\down\392394.exe
C:\WINDOWS\system32\drivers\down\393455.exe
C:\WINDOWS\system32\drivers\down\400676.exe
C:\WINDOWS\system32\drivers\down\402719.exe
C:\WINDOWS\system32\drivers\down\403249.exe
C:\WINDOWS\system32\drivers\down\407075.exe
C:\WINDOWS\system32\drivers\down\407325.exe
C:\WINDOWS\system32\drivers\down\409468.exe
C:\WINDOWS\system32\drivers\down\423559.exe
C:\WINDOWS\system32\drivers\down\427705.exe
C:\WINDOWS\system32\drivers\down\432291.exe
C:\WINDOWS\system32\drivers\down\436016.exe
C:\WINDOWS\system32\drivers\down\436117.exe
C:\WINDOWS\system32\drivers\down\441665.exe
C:\WINDOWS\system32\drivers\down\443667.exe
C:\WINDOWS\system32\drivers\down\445510.exe
C:\WINDOWS\system32\drivers\down\447533.exe
C:\WINDOWS\system32\drivers\down\454273.exe
C:\WINDOWS\system32\drivers\down\456456.exe
C:\WINDOWS\system32\drivers\down\458749.exe
C:\WINDOWS\system32\drivers\down\461854.exe
C:\WINDOWS\system32\drivers\down\467612.exe
C:\WINDOWS\system32\drivers\down\476094.exe
C:\WINDOWS\system32\drivers\down\483014.exe
C:\WINDOWS\system32\drivers\down\487330.exe
C:\WINDOWS\system32\drivers\down\500339.exe
C:\WINDOWS\system32\drivers\down\507389.exe
C:\WINDOWS\system32\drivers\down\515030.exe
C:\WINDOWS\system32\drivers\down\517434.exe
C:\WINDOWS\system32\drivers\down\525285.exe
C:\WINDOWS\system32\drivers\down\543301.exe
C:\WINDOWS\system32\drivers\down\551342.exe
C:\WINDOWS\system32\drivers\down\553355.exe
C:\WINDOWS\system32\drivers\down\563340.exe
C:\WINDOWS\system32\drivers\down\574786.exe
C:\WINDOWS\system32\drivers\down\589948.exe
C:\WINDOWS\system32\drivers\down\597138.exe
C:\WINDOWS\system32\drivers\down\600173.exe
C:\WINDOWS\system32\drivers\down\602135.exe
C:\WINDOWS\system32\drivers\down\608194.exe
C:\WINDOWS\system32\drivers\down\608334.exe
C:\WINDOWS\system32\drivers\down\608875.exe
C:\WINDOWS\system32\drivers\down\624157.exe
C:\WINDOWS\system32\drivers\down\624998.exe
C:\WINDOWS\system32\drivers\down\628133.exe
C:\WINDOWS\system32\drivers\down\633090.exe
C:\WINDOWS\system32\drivers\down\644136.exe
C:\WINDOWS\system32\drivers\down\662813.exe
C:\WINDOWS\system32\drivers\down\673458.exe
C:\WINDOWS\system32\drivers\down\680909.exe
C:\WINDOWS\system32\drivers\down\729228.exe
C:\WINDOWS\system32\drivers\down\739673.exe
C:\WINDOWS\system32\drivers\down\747755.exe
C:\WINDOWS\system32\drivers\down\749677.exe
C:\WINDOWS\system32\drivers\down\7728783.exe
C:\WINDOWS\system32\drivers\down\7730165.exe
C:\WINDOWS\system32\drivers\down\7744866.exe
C:\WINDOWS\system32\drivers\down\7755551.exe
C:\WINDOWS\system32\drivers\down\7761780.exe
C:\WINDOWS\system32\drivers\down\7765195.exe
C:\WINDOWS\system32\drivers\down\7796851.exe
C:\WINDOWS\system32\drivers\down\7846102.exe
C:\WINDOWS\system32\drivers\down\799048.exe
C:\WINDOWS\system32\drivers\down\799770.exe
C:\WINDOWS\system32\drivers\down\802073.exe
C:\WINDOWS\system32\drivers\down\802934.exe
C:\WINDOWS\system32\drivers\down\812948.exe
C:\WINDOWS\system32\drivers\down\818647.exe
C:\WINDOWS\system32\drivers\down\821801.exe
C:\WINDOWS\system32\drivers\down\826668.exe
C:\WINDOWS\system32\drivers\down\827069.exe
C:\WINDOWS\system32\drivers\down\829652.exe
C:\WINDOWS\system32\drivers\down\836713.exe
C:\WINDOWS\system32\drivers\down\837324.exe
C:\WINDOWS\system32\drivers\down\839587.exe
C:\WINDOWS\system32\drivers\down\852776.exe
C:\WINDOWS\system32\drivers\down\861689.exe
C:\WINDOWS\system32\drivers\down\863752.exe
C:\WINDOWS\system32\drivers\down\865865.exe
C:\WINDOWS\system32\drivers\down\867727.exe
C:\WINDOWS\system32\drivers\down\878182.exe
C:\WINDOWS\system32\drivers\down\881337.exe
C:\WINDOWS\system32\drivers\down\909748.exe
C:\WINDOWS\system32\drivers\down\915846.exe
C:\WINDOWS\system32\drivers\down\923417.exe
C:\WINDOWS\system32\drivers\down\927523.exe
C:\WINDOWS\system32\drivers\down\931479.exe
C:\WINDOWS\system32\drivers\down\939671.exe
C:\WINDOWS\system32\drivers\down\941623.exe
C:\WINDOWS\system32\drivers\down\943446.exe
C:\WINDOWS\system32\drivers\down\948563.exe
C:\WINDOWS\system32\drivers\down\956094.exe
C:\WINDOWS\system32\drivers\down\959960.exe
C:\WINDOWS\system32\drivers\down\a.bat
.
(((((((((((((((((((((((((((( Files Created from 2008-01-03 - 2008-02-03 )))))))))))))))))))))))))))))))))
.
2008-02-03 13:15 . 2006-06-30 14:13 8,704 --a------ C:\WINDOWS\system32\pfdnnt.exe
2008-02-03 11:44 . 2008-02-03 11:44 <DIR> d-------- C:\Deckard
2008-02-03 11:41 . 2008-02-03 11:41 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-02-03 11:41 . 2008-02-03 11:41 <DIR> d-------- C:\WINDOWS\LastGood
2008-02-03 11:41 . 2008-02-03 11:41 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-02-03 10:33 . 2008-02-03 10:33 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Prevx
2008-02-03 10:32 . 2008-02-03 10:33 <DIR> d-------- C:\Documents and Settings\ycchen100\Application Data\PrevxCSI
2008-02-03 10:17 . 2008-02-03 10:17 <DIR> d--hs---- C:\FOUND.003
2008-02-02 21:33 . 2008-02-02 21:33 <DIR> d-------- C:\Program Files\Unlocker
2008-02-02 20:29 . 2008-02-02 20:29 <DIR> d--h----- C:\WINDOWS\PIF
2008-02-02 20:09 . 2008-02-02 20:08 512,096 --a------ C:\WINDOWS\system32\drivers\amon.sys
2008-02-02 20:09 . 2008-02-02 20:08 298,104 --a------ C:\WINDOWS\system32\imon.dll
2008-02-02 20:09 . 2008-02-02 20:07 15,424 --a------ C:\WINDOWS\system32\drivers\nod32drv.sys
2008-02-02 19:49 . 2008-02-03 13:32 0 --------- C:\WINDOWS\system32\mdelk.exe
2008-02-02 16:42 . 2007-06-05 10:56 44,928 --a------ C:\WINDOWS\system32\drivers\SDTHOOK.SYS
2008-02-02 15:29 . 2006-09-06 00:03 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-02-02 15:25 . 2008-02-02 15:25 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avg7
2008-02-02 15:16 . 2008-02-02 15:16 <DIR> d--hs---- C:\FOUND.002
2008-01-29 15:59 . 2004-12-24 11:15 225,357 -ra------ C:\WINDOWS\system32\VM31bPrp.Ax
2008-01-29 15:59 . 2006-05-24 13:39 195,299 -ra------ C:\WINDOWS\system32\drivers\usbVM31b.sys
2008-01-29 15:59 . 2006-04-11 13:25 176,128 -ra------ C:\WINDOWS\amcap.exe
2008-01-29 15:59 . 2006-05-24 13:39 94,208 -ra------ C:\WINDOWS\VMCap.exe
2008-01-29 15:59 . 2006-05-24 13:39 61,440 -ra------ C:\WINDOWS\system32\VM31bSTI.dll
2008-01-29 15:59 . 2006-07-17 11:27 49,152 -ra------ C:\WINDOWS\VMSnap1.exe
2008-01-29 15:59 . 2006-07-04 14:16 49,152 -ra------ C:\WINDOWS\domino.exe
2008-01-11 21:37 . 2008-01-11 21:37 <DIR> d-------- C:\Program Files\Taobao
2008-01-09 22:06 . 2008-01-09 22:07 <DIR> d-------- C:\Program Files\TransMac
2008-01-09 21:59 . 2006-10-04 22:06 1,197,294 --------- C:\WINDOWS\system32\dllcache\sysmain.sdb
2008-01-09 21:59 . 2006-10-04 22:06 764,868 --------- C:\WINDOWS\system32\dllcache\apph_sp.sdb
2008-01-09 21:59 . 2006-10-04 22:06 217,118 --------- C:\WINDOWS\system32\dllcache\apphelp.sdb
2008-01-09 21:56 . 2008-01-09 21:56 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2008-01-09 21:46 . 2008-01-09 21:46 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2008-01-09 20:05 . 2008-01-09 20:05 <DIR> d-------- C:\Documents and Settings\ycchen100\Application Data\Synergy Software
2008-01-09 20:05 . 2008-01-09 20:05 0 --a------ C:\WINDOWS\KGOleSrv.INI
2008-01-09 20:04 . 2008-01-09 20:04 <DIR> d-------- C:\Program Files\KaleidaGraph 4.0
2008-01-09 20:04 . 2008-01-09 20:04 <DIR> d-------- C:\Documents and Settings\All Users\「開始」
2008-01-09 20:04 . 2004-03-29 15:23 90,112 --a------ C:\WINDOWS\unvise32.exe
2008-01-06 16:28 . 2008-01-06 16:29 <DIR> d-------- C:\WINDOWS\system32\aliedit
2008-01-06 00:20 . 2008-01-06 00:20 <DIR> d-------- C:\Documents and Settings\ycchen100\Application Data\Media Player Classic
2008-01-06 00:18 . 2008-01-06 00:18 <DIR> d-------- C:\Program Files\K-Lite Codec Pack
2008-01-06 00:18 . 2007-09-04 17:56 164,352 --a------ C:\WINDOWS\system32\unrar.dll
2008-01-06 00:18 . 2007-12-24 13:49 7,680 --a------ C:\WINDOWS\system32\ff_vfw.dll
2008-01-06 00:18 . 2007-07-10 17:10 547 --a------ C:\WINDOWS\system32\ff_vfw.dll.manifest
2008-01-06 00:05 . 2008-01-06 00:05 <DIR> d-------- C:\Documents and Settings\ycchen100\Application Data\skypePM
2008-01-06 00:05 . 2008-01-06 00:05 32 --a------ C:\Documents and Settings\All Users\Application Data\ezsid.dat
2008-01-06 00:03 . 2008-01-06 00:03 <DIR> d-------- C:\Program Files\Common Files\Skype
2008-01-05 22:50 . 2008-01-05 22:50 <DIR> d-------- C:\Program Files\Glary Utilities
.
(((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-03 07:07 6,815,744 ---ha-w C:\Documents and Settings\ycchen100\NTUSER.DAT
2008-02-03 07:07 6,815,744 ---ha-w C:\Documents and Settings\ycchen100\NTUSER.DAT
2008-02-03 02:33 --------- d-----w C:\Documents and Settings\ycchen100\Application Data\PrevxCSI
2008-01-11 13:37 --------- d-----w C:\Program Files\Taobao
2008-01-09 12:05 --------- d-----w C:\Documents and Settings\ycchen100\Application Data\Synergy Software
2008-01-05 16:20 --------- d-----w C:\Documents and Settings\ycchen100\Application Data\Media Player Classic
2008-01-05 16:05 --------- d-----w C:\Documents and Settings\ycchen100\Application Data\skypePM
2007-11-14 07:27 450,560 ------w C:\WINDOWS\system32\dllcache\jscript.dll
2007-11-07 09:26 699,904 ----a-w C:\WINDOWS\system32\lsasrv.dll
2007-11-07 09:26 699,904 ------w C:\WINDOWS\system32\dllcache\lsasrv.dll
.
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*注意* 空白或合法的登錄值將不會顯示
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\{A08FB30D-51C4-4E54-AA5E-FF18739802EA}]
@=Mediafour Mac Volume Icons
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 20:00 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2006-02-20 10:10 678769]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2007-12-07 15:11 21777704]
"SpybotSD TeaTimer"="D:\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-04 20:00 208952]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 20:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 20:00 455168]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2004-02-10 10:55 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2004-02-10 10:51 118784]
"SoundMan"="SOUNDMAN.EXE" [2003-12-19 17:53 65024 C:\WINDOWS\SOUNDMAN.EXE]
"AGRSMMSG"="AGRSMMSG.exe" [2003-11-19 15:41 88363 C:\WINDOWS\AGRSMMSG.exe]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2003-09-26 11:01 98304]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2003-09-26 11:01 503808]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 19:42 32768]
"Ulead AutoDetector"="C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe" [2008-02-03 11:15 45056]
"IMEKRMIG6.1"="C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE" [2004-08-04 20:00 44032]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 20:00 59392]
"PRONoMgr.exe"="c:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe" [2004-02-05 16:33 86016]
"MDDiskProtect.exe"="C:\Program Files\Mediafour\MacDrive\MDDiskProtect.exe" [2005-04-15 15:54 106496]
"MediafourGettingStartedWithMacDrive6"="C:\Program Files\Mediafour\MacDrive\MacDrive.exe" [2004-08-26 14:12 86016]
"Mediafour Mac Volume Notifications"="C:\Program Files\Common Files\Mediafour\MACVNTFY.exe" [2002-12-17 16:43 61440]
"SNPSTD2"="C:\WINDOWS\vsnpstd2.exe" [2004-08-30 16:37 286720]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20 866584]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"domino"="C:\WINDOWS\domino.exe" [2006-07-04 14:16 49152]
"VMSnap1"="C:\WINDOWS\VMSnap1.exe" [2006-07-17 11:27 49152]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2008-02-03 13:10 949376]
"UnlockerAssistant"="C:\Program Files\Unlocker\UnlockerAssistant.exe" [2006-09-08 01:19 15872]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2008-02-02 23:52 6731312]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Panda_cleaner"="C:\WINDOWS\system32\ACTIVE~1\pavdr.exe" [2006-07-14 13:04 45056]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 20:00 15360]
C:\Documents and Settings\ycchen100\「開始」功能表\程式集\啟動\
Internet Explorer.lnk - C:\Program Files\Internet Explorer\IEXPLORE.EXE [2005-05-31 12:23:18 93184]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Sebring]
c:\WINDOWS\system32\LgNotify.dll 2004-03-03 16:48 110592 c:\WINDOWS\system32\LgNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PPENSB\win32\PPINKDLL.DLL
R0 MDPMGRNT;MDPMGRNT;C:\WINDOWS\system32\drivers\MDPMGRNT.sys [2006-04-30 22:57]
R1 MDFSYSNT;MDFSYSNT;C:\WINDOWS\system32\drivers\MDFSYSNT.sys [2006-09-14 02:53]
R1 srosa;Megadrv3;C:\WINDOWS\system32\drivers\srosa.sys [2008-02-03 11:15]
R3 EMCR;EMCR;C:\WINDOWS\system32\DRIVERS\EMCR7SK.sys [2004-05-03 14:12]
S2 VCapture;DC3410 Video Camera Device;C:\WINDOWS\system32\Drivers\VCapture.sys [2002-10-21 11:37]
S3 MD1000;GSL MD1000 Electronic Dictionary;C:\WINDOWS\system32\Drivers\MD1000.sys [2004-10-08 16:39]
S3 PAC7311;VGA USB Camera;C:\WINDOWS\system32\DRIVERS\PA707UCM.SYS [2005-10-18 11:48]
S3 snpstd2;USB PC Camera (SN9C103);C:\WINDOWS\system32\DRIVERS\snpstd2.sys [2004-10-14 17:12]
S3 USBCamera;DC3410 Still Camera Device;C:\WINDOWS\system32\Drivers\CamBulk.sys [2002-12-04 14:38]
.
Contents of the 'Scheduled Tasks' folder
"2008-02-02 17:37:04 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-02-03 15:09:49
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
? [1956]
? [3968]
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files?: 0
**************************************************************************
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"drvsyskit"="C:\\WINDOWS\\system32\\drivers\\hldrrr.exe"
"german.exe"="C:\\WINDOWS\\system32\\wintems.exe"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\lsass.exe [5.01.2600.2180]
-> C:\Program Files\Eset\pr_imon.dll
.
Completion time?: 2008-02-03 15:11:06
ComboFix-quarantined-files.txt 2008-02-03 07:11:04
.
2008-02-01 01:38:53 --- E O F ---