Combo Fix log
My only concern with the MRU is that I don't understand why I used to be able to delete all MRUs before encountering the malware and now I can't...
Here is the ComboFix log. I started it and left the room for only a few minutes and it was already done. The computer did not seem to have restarted.
ComboFix doesn't seem to produce the log on my machine, I have to go find it in C:\ComboFix.
This is the file that I found there. The time says 13:47 so I'm guessing its from this last scan even though the scan was so quick
ComboFix 08-01-23.2 - Owner 2008-01-26 13:47:00.4 - NTFSx86
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\TEMP\cXzz9
C:\TEMP\gTiis19
C:\WINDOWS\system32\ctfmon.exe.tmp
C:\WINDOWS\system32\nGpxx01
C:\WINDOWS\system32\onnmp.ini
C:\WINDOWS\system32\onnmp.ini2
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\rtutv.ini
C:\WINDOWS\system32\rtutv.ini2
C:\WINDOWS\system32\ybeqcebg.ini
D:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_IPRIP
-------\Iprip
((((((((((((((((((((((((( Files Created from 2007-12-26 to 2008-01-26 )))))))))))))))))))))))))))))))
.
2008-01-26 13:47 . 2008-01-26 13:47 6,736 --a------ C:\WINDOWS\system32\drivers\PROCEXP90.SYS
2008-01-25 19:36 . 2008-01-25 19:44 <DIR> d-------- C:\Program Files\MessenPass
2008-01-25 19:33 . 2008-01-25 19:36 39,424 --a------ C:\WINDOWS\zipinst.exe
2008-01-25 16:30 . 2004-08-04 14:00 343,040 --a------ C:\WINDOWS\system32\mspaint.exe
2008-01-25 16:30 . 2004-08-04 14:00 343,040 --a--c--- C:\WINDOWS\system32\dllcache\mspaint.exe
2008-01-24 13:28 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\Nircmd.exe
2008-01-24 13:10 . 2008-01-24 13:10 <DIR> d-------- C:\Program Files\Trend Micro
2008-01-24 00:55 . 2004-08-04 14:00 35,328 --a------ C:\WINDOWS\system32\iprip.dll
2008-01-24 00:55 . 2004-08-04 14:00 35,328 --a--c--- C:\WINDOWS\system32\dllcache\iprip.dll
2008-01-24 00:55 . 2004-08-04 14:00 22,528 --a------ C:\WINDOWS\system32\lpdsvc.dll
2008-01-24 00:55 . 2004-08-04 14:00 22,528 --a--c--- C:\WINDOWS\system32\dllcache\lpdsvc.dll
2008-01-24 00:55 . 2004-08-04 14:00 18,944 --a------ C:\WINDOWS\system32\simptcp.dll
2008-01-24 00:55 . 2004-08-04 14:00 18,944 --a------ C:\WINDOWS\system32\lprmon.dll
2008-01-24 00:55 . 2004-08-04 14:00 18,944 --a--c--- C:\WINDOWS\system32\dllcache\simptcp.dll
2008-01-24 00:55 . 2004-08-04 14:00 18,944 --a--c--- C:\WINDOWS\system32\dllcache\lprmon.dll
2008-01-23 17:28 . 2008-01-23 17:28 <DIR> d-------- C:\Program Files\Microsoft Easy Assist
2008-01-23 12:44 . 2008-01-23 12:44 <DIR> d-------- C:\WINDOWS\system32\FxsTmp
2008-01-21 11:13 . 2008-01-25 01:05 <DIR> d-------- C:\Program Files\SpywareBlaster
2008-01-21 10:27 . 2008-01-21 10:27 <DIR> d-------- C:\Program Files\Lavasoft
2008-01-21 10:26 . 2008-01-21 10:26 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-01-21 01:55 . 2008-01-21 01:55 92 --a------ C:\WINDOWS\wininit.ini
2008-01-20 22:58 . 2008-01-22 00:45 <DIR> d-------- C:\VundoFix Backups
2008-01-20 19:35 . 2008-01-20 19:35 <DIR> d-------- C:\Program Files\Windows Sidebar
2008-01-20 19:32 . 2008-01-20 20:07 <DIR> d-------- C:\Program Files\Norton Internet Security
2008-01-20 19:29 . 2008-01-20 19:55 123,952 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-01-20 19:29 . 2008-01-20 19:55 60,800 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2008-01-20 19:29 . 2008-01-20 19:55 10,740 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-01-20 19:29 . 2008-01-20 19:55 805 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-01-20 19:28 . 2008-01-20 19:55 <DIR> d-------- C:\Program Files\Symantec
2008-01-20 19:26 . 2008-01-26 12:13 <DIR> d-------- C:\Program Files\Common Files\Symantec Shared
2008-01-15 17:58 . 2008-01-15 20:11 <DIR> d-------- C:\Program Files\Safer Networking
2008-01-14 11:51 . 2008-01-14 11:51 <DIR> d-------- C:\Program Files\Common Files\Scanner
2008-01-14 11:51 . 2008-01-14 11:53 <DIR> d-------- C:\Program Files\CA Yahoo! Anti-Spy
2008-01-14 11:49 . 2008-01-14 12:01 <DIR> d-------- C:\Program Files\Yahoo!
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-26 17:10 --------- d-----w C:\Program Files\QuickTime
2008-01-26 17:10 --------- d-----w C:\Program Files\iTunes
2008-01-21 01:10 499,200 ----a-w C:\WINDOWS\pchealth\helpctr\binaries\msconfig.exe.tmp
2008-01-16 01:10 --------- d-----w C:\Program Files\Google
2008-01-14 16:33 --------- d-----w C:\Program Files\BigFix
2008-01-14 16:25 --------- d-----w C:\Program Files\Viewpoint
2007-12-14 16:32 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2007-12-01 04:57 43,696 ----a-w C:\WINDOWS\system32\drivers\srtspx.sys
2007-12-01 04:57 317,616 ----a-w C:\WINDOWS\system32\drivers\srtspl.sys
2007-12-01 04:57 279,088 ----a-w C:\WINDOWS\system32\drivers\srtsp.sys
2007-12-01 04:57 10,549 ----a-w C:\WINDOWS\system32\drivers\srtspx.cat
2007-12-01 04:57 10,549 ----a-w C:\WINDOWS\system32\drivers\srtspl.cat
2007-12-01 04:57 10,545 ----a-w C:\WINDOWS\system32\drivers\srtsp.cat
2007-12-01 04:57 1,430 ----a-w C:\WINDOWS\system32\drivers\srtspl.inf
2007-12-01 04:57 1,421 ----a-w C:\WINDOWS\system32\drivers\srtspx.inf
2007-12-01 04:57 1,415 ----a-w C:\WINDOWS\system32\drivers\srtsp.inf
2007-11-07 09:26 721,920 ----a-w C:\WINDOWS\system32\lsasrv.dll
2007-10-29 22:43 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-27 22:40 227,328 ----a-w C:\WINDOWS\system32\wmasf.dll
.
((((((((((((((((((((((((((((( snapshot@2008-01-24_13.39.43.34 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-24 18:28:53 1,417,216 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
+ 2008-01-26 18:46:51 1,421,312 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
- 2008-01-24 18:28:53 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
+ 2008-01-26 18:46:51 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
- 2008-01-24 18:28:53 1,417,216 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\ntuser.dat
+ 2008-01-26 18:46:52 1,421,312 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\ntuser.dat
- 2008-01-24 18:28:53 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
+ 2008-01-26 18:46:52 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
- 2008-01-24 18:28:53 6,422,528 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\ntuser.dat
+ 2008-01-26 18:46:52 6,430,720 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\ntuser.dat
- 2008-01-24 18:28:54 12,288 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
+ 2008-01-26 18:46:52 12,288 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
- 2008-01-24 06:40:13 55,952 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-01-25 21:38:01 55,952 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2008-01-24 06:40:13 387,674 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-01-25 21:38:01 387,674 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2004-08-04 19:00:00 56,832 ----a-w C:\WINDOWS\system32\sol.exe
+ 2004-08-04 19:00:00 119,808 ----a-w C:\WINDOWS\system32\winmine.exe
+ 2008-01-26 17:52:47 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_808.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
2007-08-24 22:51 316784 --a------ C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
2008-01-20 19:34 116088 --a------ C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{BA52B914-B692-46C4-B683-905236F6F655}
{47833539-D0C5-4125-9FA8-0819E2EAAC93}
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}
[HKEY_CLASSES_ROOT\clsid\{7febefe3-6b19-4349-98d2-ffb09d4b49ca}]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}"= C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll [2007-08-24 22:51 316784]
[HKEY_CLASSES_ROOT\clsid\{7febefe3-6b19-4349-98d2-ffb09d4b49ca}]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 14:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2004-08-04 14:00 158208]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-08-25 00:07 51048]
"osCheck"="C:\Program Files\Norton Internet Security\osCheck.exe" [2007-08-24 23:53 714608]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-20 20:09 267064]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-05-13 03:30 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-05-13 03:29 126976]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acrobat Assistant.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk
backup=C:\WINDOWS\pss\Acrobat Assistant.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BigFix.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\BigFix.lnk
backup=C:\WINDOWS\pss\BigFix.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^j2 4.2.lnk.disabled]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\j2 4.2.lnk.disabled
backup=C:\WINDOWS\pss\j2 4.2.lnk.disabledCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^j2 DllCmd 4.0.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\j2 DllCmd 4.0.lnk
backup=C:\WINDOWS\pss\j2 DllCmd 4.0.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^j2 Tray Menu 4.0.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\j2 Tray Menu 4.0.lnk
backup=C:\WINDOWS\pss\j2 Tray Menu 4.0.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk.disabled]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk.disabled
backup=C:\WINDOWS\pss\Kodak EasyShare software.lnk.disabledCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Spyware Protection]
--a------ 2004-10-18 16:42 79448 C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]
-ra------ 2004-10-20 08:40 34904 C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Gateway Extended Warranty]
--a------ 2004-02-08 19:30 73728 C:\Program Files\Gateway\GWCares\GWCares.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
--a------ 2004-11-03 16:03 125528 C:\Program Files\Common Files\AOL\1154314233\EE\AOLHostManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-01-20 20:09 267064 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCAgentExe]
c:\PROGRA~1\mcafee.com\agent\McAgent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCUpdateExe]
C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MPFExe]
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MPSExe]
c:\PROGRA~1\mcafee.com\mps\mscifapp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSKAGENTEXE]
C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSKDetectorExe]
C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 14:50 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OASClnt]
C:\Program Files\McAfee.com\VSO\oasclnt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PlaxoUpdate]
C:\Program Files\Plaxo\2.11.1.5\PlaxoHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-01-19 21:27 286720 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
%WINDIR%\SMINST\RECGUARD.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Reminder]
%WINDIR%\Creator\Remind_XP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--a------ 2004-11-02 23:24 32768 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
--a------ 2004-11-04 19:47 688218 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPLpr]
--a------ 2004-11-04 19:47 98394 C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirusScan Online]
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VSOCheckTask]
C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{0228e555-4f9c-4e35-a3ec-b109a192b4c2}]
C:\Program Files\Google\Gmail Notifier\gnotify.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"PrismXL"=2 (0x2)
"MDM"=2 (0x2)
"mcupdmgr.exe"=3 (0x3)
"McTskshd.exe"=2 (0x2)
"McShield"=2 (0x2)
"McDetect.exe"=2 (0x2)
"MskService"=2 (0x2)
"iPod Service"=3 (0x3)
"IDriverT"=3 (0x3)
"Apple Mobile Device"=2 (0x2)
"BITS"=2 (0x2)
"MpfService"=2 (0x2)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"j2 4.2"="C:\Program Files\j2 Messenger 4.2\J2GDllCmd.exe" /R
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe"
"Ad-Watch"=C:\Program Files\Lavasoft\Ad-Aware 2007\Ad-Watch2007.exe
R2 LiveUpdate Notice;LiveUpdate Notice;"C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" [2007-08-25 00:07]
R3 NWADI;NWADI Bus Enumerator;C:\WINDOWS\system32\DRIVERS\NWADIenum.sys [2006-11-07 08:32]
R3 SymIMMP;SymIMMP;C:\WINDOWS\system32\DRIVERS\SymIM.sys [2007-08-09 19:27]
S3 COH_Mon;COH_Mon;C:\WINDOWS\system32\Drivers\COH_Mon.sys [2007-05-29 15:55]
S3 p2pgasvc;Peer Networking Group Authentication;C:\WINDOWS\system32\svchost.exe [2004-08-04 14:00]
S3 p2pimsvc;Peer Networking Identity Manager;C:\WINDOWS\system32\svchost.exe [2004-08-04 14:00]
S3 p2psvc;Peer Networking;C:\WINDOWS\system32\svchost.exe [2004-08-04 14:00]
S3 PNRPSvc;Peer Name Resolution Protocol;C:\WINDOWS\system32\svchost.exe [2004-08-04 14:00]
S3 SMNDIS5;SMNDIS5 NDIS Protocol Driver;C:\PROGRA~1\VERIZO~1\VZACCE~1\SMNDIS5.SYS [2002-11-26 13:54]
S3 SymIM;Symantec Network Security Intermediate Filter Service;C:\WINDOWS\system32\DRIVERS\SymIM.sys [2007-08-09 19:27]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2008-01-24 15:09:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-01-22 01:49:38 C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - Owner.job"
- C:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exeh/TASK:
"2008-01-26 16:58:29 C:\WINDOWS\Tasks\Spybot - Search & Destroy - Scheduled Task.job"
- C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-26 13:50:52
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.