combofix log 2 parts
ComboFix 08-03-05.3 - John 2008-03-06 10:33:58.1 - NTFSx86
Running from: C:\Documents and Settings\John\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\BM971c222e.xml
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\awtqr.dll
C:\WINDOWS\SYSTEM32\axmeepue.ini
C:\WINDOWS\system32\brgvpyhx.dll
C:\WINDOWS\system32\eupeemxa.dll
C:\WINDOWS\system32\fkdgoate.dll
C:\WINDOWS\system32\fxdaxlur.dll
C:\WINDOWS\system32\gljjexnu.dll
C:\WINDOWS\system32\gscwmskm.dll
C:\WINDOWS\system32\iifefcb.dll
C:\WINDOWS\system32\kvukhust.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\SYSTEM32\mksmwcsg.ini
C:\WINDOWS\system32\ncehksre.dll
C:\WINDOWS\system32\plnjbfex.dll
C:\WINDOWS\system32\qctffgxf.dll
C:\WINDOWS\SYSTEM32\qqxgpmrv.ini
C:\WINDOWS\system32\rfducang.dll
C:\WINDOWS\SYSTEM32\rqtwa.ini
C:\WINDOWS\SYSTEM32\rqtwa.ini2
C:\WINDOWS\SYSTEM32\rulxadxf.ini
C:\WINDOWS\system32\saybhaev.dll
C:\WINDOWS\system32\tggaoohq.dll
C:\WINDOWS\SYSTEM32\veahbyas.ini
C:\WINDOWS\system32\vrmpgxqq.dll
C:\WINDOWS\SYSTEM32\xhypvgrb.ini
C:\WINDOWS\system32\xsdvonre.dll
C:\WINDOWS\system32\yhkpmoaw.dll
C:\WINDOWS\system32\ymydvhoe.dll
.
((((((((((((((((((((((((( Files Created from 2008-02-06 to 2008-03-06 )))))))))))))))))))))))))))))))
.
2008-03-06 10:14 . 2008-03-06 10:26 <DIR> d-------- C:\VundoFix Backups
2008-03-05 22:41 . 2008-03-05 22:41 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-03-05 22:41 . 2008-03-05 22:41 1,409 --a------ C:\WINDOWS\QTFont.for
2008-03-05 14:04 . 2008-03-05 14:04 <DIR> d-------- C:\Documents and Settings\NetworkService\Application Data\McAfee.com Personal Firewall
2008-03-05 14:03 . 2008-03-05 14:03 <DIR> d-------- C:\Documents and Settings\John\Application Data\PC Tools
2008-03-05 13:50 . 2008-03-05 13:50 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\PC Tools
2008-03-05 13:46 . 2008-03-05 12:23 218,504 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\pctfw2.sys
2008-03-05 12:23 . 2008-03-05 14:28 <DIR> d-------- C:\Program Files\Common Files\PC Tools
2008-03-05 01:04 . 2007-10-17 13:53 43,816 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\fssfltr.sys
2008-03-05 00:59 . 2008-03-05 00:59 <DIR> d-------- C:\Program Files\Microsoft SQL Server Compact Edition
2008-03-05 00:52 . 2008-03-05 14:04 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2008-03-05 00:51 . 2008-03-06 09:22 <DIR> d-------- C:\Program Files\Windows Live
2008-03-05 00:51 . 2008-03-05 00:51 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-03-03 22:44 . 2008-03-06 09:19 <DIR> d-------- C:\Program Files\Spyware Doctor
2008-03-03 22:44 . 2007-12-10 14:53 81,288 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\iksyssec.sys
2008-03-03 22:44 . 2007-12-10 14:53 66,952 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\iksysflt.sys
2008-03-03 22:44 . 2008-02-01 12:55 42,376 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\ikfilesec.sys
2008-03-03 22:44 . 2007-12-10 14:53 29,576 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\kcom.sys
2008-03-03 11:10 . 2008-03-03 11:10 <DIR> d-------- C:\WINDOWS\SYSTEM32\Kaspersky Lab
2008-03-03 11:10 . 2008-03-03 11:10 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-03-02 13:35 . 2003-10-31 15:21 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Sonic
2008-03-02 13:35 . 2005-05-26 16:47 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Gtek
2008-02-29 23:10 . 2008-02-29 23:10 <DIR> d-------- C:\Program Files\Trend Micro
2008-02-27 23:37 . 2008-02-27 23:37 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-02-27 22:24 . 2008-02-27 22:25 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-27 00:33 . 2008-02-27 01:30 32,394 ---hs---- C:\WINDOWS\SYSTEM32\dafspjkd.dllbox
2008-02-26 19:54 . 2008-02-27 01:31 <DIR> d-------- C:\Program Files\AquaMark3
2008-02-26 10:51 . 2008-02-26 10:51 8,704 --ahs---- C:\WINDOWS\Thumbs.db
2008-02-25 14:25 . 2008-02-25 14:26 <DIR> d-------- C:\Program Files\vghd
2008-02-25 14:25 . 2008-02-25 14:25 <DIR> d-------- C:\Documents and Settings\John\Application Data\vghd
2008-02-23 11:14 . 2008-02-23 11:14 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
2008-02-22 21:09 . 2008-02-22 21:09 25 --a------ C:\WINDOWS\mixerdef.ini
2008-02-20 20:57 . 2008-02-20 20:57 54,608 --a------ C:\WINDOWS\SYSTEM32\xfcodec.dll
2008-02-18 10:23 . 2008-02-18 10:23 268 --ah----- C:\sqmdata03.sqm
2008-02-18 10:23 . 2008-02-18 10:23 244 --ah----- C:\sqmnoopt03.sqm
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-06 15:42 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-04 23:46 --------- d-----w C:\Program Files\CleanUp!
2008-03-02 17:57 --------- d-----w C:\Program Files\McAfee
2008-02-29 04:52 --------- d-----w C:\Program Files\Xfire
2008-02-29 01:53 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-02-28 04:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-28 03:24 --------- d-----w C:\Program Files\Lavasoft
2008-02-28 03:23 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-02-27 06:31 --------- d-----w C:\Documents and Settings\John\Application Data\Xfire
2008-02-27 06:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\nHancer
2008-02-26 23:14 --------- d-----w C:\Documents and Settings\John\Application Data\teamspeak2
2008-02-23 16:23 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-13 16:25 --------- d-----w C:\Program Files\Common Files\Adobe
2008-02-02 04:29 --------- d-----w C:\Program Files\America's Army Server Manager
2008-02-02 04:29 --------- d-----w C:\Program Files\America's Army
2008-02-02 03:46 --------- d-----w C:\Program Files\Dynamic Toolbar
2008-02-02 03:46 --------- d-----w C:\Program Files\Dell Computer
2008-02-02 03:46 --------- d-----w C:\Program Files\Common Files\Real
2008-02-02 03:44 --------- d--ha-w C:\Documents and Settings\All Users\Application Data\GTek
2008-02-02 03:44 --------- d--h--w C:\Documents and Settings\Theresa\Application Data\GTek
2008-02-02 03:44 --------- d--h--w C:\Documents and Settings\John\Application Data\GTek
2008-02-01 21:19 --------- d-----w C:\Documents and Settings\John\Application Data\BitTorrent
2008-02-01 20:23 --------- d-----w C:\Program Files\RivaTuner v2.06
2008-02-01 20:02 22,328 ----a-w C:\Documents and Settings\John\Application Data\PnkBstrK.sys
2008-02-01 16:11 586,240 ----a-w C:\WINDOWS\WLXPGSS.SCR
2008-01-27 15:54 --------- d-----w C:\Documents and Settings\John\Application Data\GSC
2008-01-24 19:23 --------- d-----w C:\Program Files\teamspeak2_RC2
2008-01-23 22:32 --------- d-----w C:\Program Files\DivX
2008-01-21 22:20 --------- d-----w C:\Program Files\GSC
2008-01-06 16:06 --------- d-----w C:\Program Files\Software602
2005-01-21 00:53 45,056 -c----r C:\Program Files\SetAttrib.exe
2004-11-30 07:23 40,960 -c----r C:\Program Files\delete.exe
2003-12-03 20:55 2,352 -c--a-w C:\Documents and Settings\John\Application Data\mpauth.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{15FD53F3-89D6-437A-B810-3DA9606DFF91}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2B07C93B-274B-4B4F-BA6F-8AB0975F7F12}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{32E09C0B-951D-451C-8CBF-80B33EA5A017}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3982DF72-66B1-49E3-B21D-B0DE93D37665}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{45C2A50F-8F4A-496E-AF02-D0207525BF5A}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4f3ed5cd-0726-42a9-87f5-d13f3d2976ac}]
2007-12-17 11:12 56360 --a------ C:\Program Files\Windows Live\Family Safety\fssbho.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53AFAF4B-0062-4046-9C2C-76C0F0CEBC06}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D7E9654-1C1E-4DA5-8AC9-3997EBF83953}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7bff7d64-2160-4bcc-b1c4-7403239ccc45}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8130A05C-1C14-4C26-AC28-7E3C4C6C70CE}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8D9BE2DB-4A79-4206-87DF-96E1F411B5B2}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8EE559E2-4475-4AC9-B94D-796FBA2EE820}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9e44e01c-6535-4868-a6aa-77df6d6f059f}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AD61B098-A7D0-41E8-A7CB-86117E340A51}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B186F284-3849-4A10-B116-B0DB4CA6D028}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F7FF7EAB-0C06-4B33-8FC1-153AF0E0FDCF}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56 15360]
"CUCore Agent"="C:\PROGRA~1\COMMON~1\FIRSTV~1\ConfAgent.exe" [ ]
"NVIDIA nTune"="C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-07-03 12:32 81920]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MPFEXE"="C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe" [2005-11-11 17:00 1005096]
"VSOCheckTask"="C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" [2005-07-08 18:18 151552]
"VirusScan Online"="C:\Program Files\McAfee.com\VSO\mcvsshld.exe" [2005-08-10 12:49 163840]
"OASClnt"="C:\Program Files\McAfee.com\VSO\oasclnt.exe" [2005-08-11 22:02 53248]
"tgcmd"="C:\Program Files\Support.com\bin\tgcmd.exe" [2007-03-07 09:58 1773568]
"RivaTunerStartupDaemon"="C:\Program Files\RivaTuner v2.06\RivaTuner.exe" [2007-10-30 13:05 2650112]
"C-Media Mixer"="Mixer.exe" [2002-10-15 18:00 1818624 C:\WINDOWS\mixer.exe]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 23:46 57344]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-10-04 17:14 8491008]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-12-11 10:56 286720]
"BM971c222e"="C:\WINDOWS\system32\odoshgmm.dll" [ ]
"ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [2008-02-01 12:55 1103240]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-12-07 02:33 8720384]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
"ZboardTray"= "C:\Program Files\Ideazon\Zboard Software\Driver\ZboardTray.exe" /autolaunch
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\iifefcb]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Zboard]
Winlognotif.dll 2003-09-03 07:14 49152 C:\WINDOWS\SYSTEM32\Winlognotif.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk
backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=C:\WINDOWS\pss\Digital Line Detect.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=C:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=C:\WINDOWS\pss\Logitech Desktop Messenger.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Monitor.lnk
backup=C:\WINDOWS\pss\Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^John^Start Menu^Programs^Startup^VirtuaGirl HD.LNK]
path=C:\Documents and Settings\John\Start Menu\Programs\Startup\VirtuaGirl HD.LNK
backup=C:\WINDOWS\pss\VirtuaGirl HD.LNKStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
--a------ 2005-06-06 23:46 57344 C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 22:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BM971c222e]
C:\WINDOWS\system32\ypjrxesp.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a--c--- 2004-08-04 02:56 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\diagent]
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
--a--c--- 2003-08-06 02:04 114741 C:\WINDOWS\system32\dla\tfswctrl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDSentry]
--a--c--- 2003-08-13 11:27 28672 C:\WINDOWS\System32\DSentry.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM]
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LaunchPDeviceConn]
--a------ 2005-07-05 19:41 299008 C:\Program Files\Philips\Philips Device Transfer Pop-up\PDeviceConn.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Utility]
-----c--- 2003-03-04 04:50 19968 C:\WINDOWS\LOGI_MWX.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-10-13 11:24 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MySpaceIM]
--a------ 2007-12-07 02:33 8720384 C:\Program Files\MySpace\IM\MySpaceIM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
-----c--- 2001-07-09 03:50 155648 C:\WINDOWS\System32\\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nHancer]
C:\Program Files\nHancer\nHancer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2007-10-04 17:14 8491008 C:\WINDOWS\system32\NvCpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2007-10-04 17:14 81920 C:\WINDOWS\SYSTEM32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2007-10-04 17:14 1626112 C:\WINDOWS\SYSTEM32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Pitstop Optimize2 Reminder]
C:\Program Files\PCPitstop\Optimize2\Reminder.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
C:\Program Files\Dell\Media Experience\PCMService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-12-11 10:56 286720 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sonic RecordNow!]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-09-25 01:11 132496 C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
C:\WINDOWS\UpdReg.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\America's Army\\System\\ArmyOps.exe"=
"C:\\WINDOWS\\SYSTEM32\\mmc.exe"=
"C:\\Program Files\\Xfire\\xfire.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"=
R2 fssfltr;FssFltr;C:\WINDOWS\system32\DRIVERS\fssfltr.sys [2007-10-17 13:53]
R2 fsssvc;Windows Live OneCare Family Safety;"C:\Program Files\Windows Live\Family Safety\fsssvc.exe" [2007-12-17 11:13]
R2 IOPort;IOPort;C:\WINDOWS\system32\IOPORT.SYS [1998-11-27 18:57]
S0 NVStrap;NVStrap;C:\WINDOWS\system32\drivers\NVStrap.sys [2007-10-30 13:05]
S2 0203011204480698mcinstcleanup;McAfee Application Installer Cleanup (0203011204480698);C:\WINDOWS\TEMP\
020301~1.EXE C:\PROGRA~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini []
S3 ICAM3NT5;Intel(r) PC Camera CS331;C:\WINDOWS\system32\Drivers\ICAM3D2.SYS [2001-12-03 11:57]
S3 LCcfltr;Logitech USB Filter Driver;C:\WINDOWS\system32\Drivers\LCcFltr.Sys [2003-03-04 04:50]
.
Contents of the 'Scheduled Tasks' folder
"2003-11-06 04:00:00 C:\WINDOWS\Tasks\ISP signup reminder 1.job"
- C:\WINDOWS\System32\OOBE\OOBEBALN.EXE
"2008-02-16 01:00:00 C:\WINDOWS\Tasks\McAfee.com Scan for Viruses - My Computer (DB2PBQ31-John).job"
- c:\program files\mcafee.com\vso\mcmnhdlr.exe
"2008-02-15 06:14:00 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe'
"2008-02-01 06:00:11 C:\WINDOWS\Tasks\McQcTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-03-06 10:43:05
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0