Hi, need help to remove virtumonde trojan from my system. I've read through a couple of previous threads on this trojan and executed vundofix (scanned and removed), combofix, and hijackthis in that order. Below are the log files...
VUNDOFIX LOG =================
VundoFix V6.6.2
Checking Java version...
Java version is 1.5.0.9
Old versions of java are exploitable and should be removed.
Scan started at 11:15:41 PM 11/17/2007
Listing files found while scanning....
C:\windows\system32\dccdd.ini
C:\windows\system32\dccdd.ini2
C:\windows\system32\ddccd.dll
Beginning removal...
Attempting to delete C:\windows\system32\dccdd.ini
C:\windows\system32\dccdd.ini Has been deleted!
Attempting to delete C:\windows\system32\dccdd.ini2
C:\windows\system32\dccdd.ini2 Has been deleted!
Attempting to delete C:\windows\system32\ddccd.dll
C:\windows\system32\ddccd.dll Could not be deleted.
Performing Repairs to the registry.
Done!
Beginning removal...
Attempting to delete C:\windows\system32\dccdd.ini
C:\windows\system32\dccdd.ini Has been deleted!
Attempting to delete C:\windows\system32\dccdd.ini2
C:\windows\system32\dccdd.ini2 Has been deleted!
Attempting to delete C:\windows\system32\ddccd.dll
C:\windows\system32\ddccd.dll Has been deleted!
Performing Repairs to the registry.
Done!
COMBOFIX LOG =================
ComboFix 07-11-08.1 - mufti 2007-11-17 23:39:45.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1561 [GMT 7:00]
Running from: D:\Documents and Settings\mufti\Desktop\ComboFix.exe
.
Unable to gain System Privileges
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\kjkmp.ini
C:\WINDOWS\system32\kjkmp.ini2
C:\WINDOWS\system32\pmkjk.dll
.
((((((((((((((((((((((((( Files Created from 2007-10-17 to 2007-11-17 )))))))))))))))))))))))))))))))
.
2007-11-17 23:15 <DIR> d-------- C:\VundoFix Backups
2007-11-17 23:05 52,072 --a------ C:\WINDOWS\system32\pmnlm.dll
2007-11-17 22:57 <DIR> d-------- C:\Program Files\Trend Micro
2007-11-17 22:06 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-11-17 20:41 85,056 --a------ C:\WINDOWS\system32\uwrnukni.dll
2007-11-17 20:41 82,496 --a------ C:\WINDOWS\system32\fsrvoodx.dll
2007-11-17 20:38 71,232 --a------ C:\WINDOWS\system32\tsujtqos.exe
2007-11-17 12:02 <DIR> d-------- D:\Documents and Settings\mufti\Application Data\JPEGsnoop
2007-11-16 16:56 85,056 --a------ C:\WINDOWS\system32\tvwbvnut.dll
2007-11-16 16:53 81,984 --a------ C:\WINDOWS\system32\sklyhbbg.dll
2007-11-15 23:13 <DIR> d-------- C:\Program Files\DOSBox-0.63
2007-11-15 07:47 37,376 --a------ C:\WINDOWS\system32\yayxxxy.dll
2007-11-15 07:47 37,376 --a------ C:\WINDOWS\system32\efcayaw.dll
2007-11-15 07:26 <DIR> d-a------ D:\Documents and Settings\All Users\Application Data\TEMP
2007-11-15 07:25 <DIR> d-------- C:\Program Files\DAP
2007-11-15 05:59 <DIR> d-------- C:\Program Files\Second Sight Software
2007-10-30 01:06 413,760 --a------ C:\WINDOWS\system32\MPG4C32.DLL
2007-10-24 20:37 <DIR> d-------- C:\Program Files\Monte Cristo
2007-10-21 18:43 <DIR> d-------- D:\Documents and Settings\mufti\Application Data\Command & Conquer 3 Tiberium Wars
2007-10-21 18:17 <DIR> d-------- C:\Program Files\DAEMON Tools
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-17 04:59 --------- d-----w D:\Documents and Settings\mufti\Application Data\Printer Info Cache
2007-11-17 04:59 --------- d-----w D:\Documents and Settings\mufti\Application Data\Image Zone Express
2007-11-17 02:35 --------- d-----w D:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-11-17 01:31 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-11-16 10:17 --------- d-----w C:\Program Files\Microsoft ActiveSync
2007-10-21 11:41 --------- d-----w C:\Program Files\Electronic Arts
2007-10-20 03:24 --------- d-----w C:\Program Files\HP
2007-10-12 17:40 --------- d-----w C:\Program Files\Google
2007-10-12 16:28 --------- d-----w D:\Documents and Settings\mufti\Application Data\Command & Conquer 3 Tiberium Wars Demo
2007-10-11 03:22 --------- d-----w C:\Program Files\Java
2007-10-10 12:50 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-10-10 11:39 --------- d-----w D:\Documents and Settings\All Users\Application Data\Firefly Studios
2007-10-10 11:35 --------- d-----w D:\Documents and Settings\All Users\Application Data\SecTaskMan
2007-10-08 13:13 --------- d-----w C:\Program Files\Winamp
2007-10-08 05:33 --------- d-----w C:\Program Files\Yahoo!
2007-10-06 10:23 --------- d-----w C:\Program Files\CCP
2007-10-05 19:17 --------- d-----w C:\Program Files\Security Task Manager
2007-10-04 19:26 --------- d-----w C:\Program Files\Alcohol Soft
2007-10-04 19:12 --------- d--h--r D:\Documents and Settings\mufti\Application Data\SecuROM
2007-10-03 05:53 --------- d-----w D:\Documents and Settings\mufti\Application Data\Gamelab
2007-10-02 20:47 --------- d-----w D:\Documents and Settings\All Users\Application Data\Apple Computer
2007-10-02 20:46 --------- d-----w C:\Program Files\K-Lite Codec Pack
2007-09-30 04:34 --------- d-----w D:\Documents and Settings\mika\Application Data\HP
2007-09-29 03:06 --------- d-----w D:\Documents and Settings\dana\Application Data\HP
2007-09-28 15:46 --------- d-----w C:\Program Files\QuickPar
2007-09-27 09:01 --------- d-----w C:\Program Files\Common Files\HP
2007-09-27 08:45 --------- d-----w D:\Documents and Settings\mufti\Application Data\HP
2007-09-27 08:29 --------- d-----w D:\Documents and Settings\All Users\Application Data\HP
2007-09-27 08:25 --------- d-----w C:\Program Files\Hewlett-Packard
2007-09-27 08:25 --------- d-----w C:\Program Files\Common Files\Hewlett-Packard
2007-09-26 03:44 --------- d-----w C:\Program Files\MatrixEngine 1.0
2007-09-24 04:45 --------- d-----w C:\Program Files\Camfrog
2007-09-22 12:17 --------- d-----w C:\Program Files\Astraware
2007-08-21 06:25 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{549B5CA7-4A86-11D7-A4DF-000874180BB3}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{761BCB47-850E-4893-BDA7-4952EF459F14}]
C:\WINDOWS\system32\pmnno.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{89F3D70D-7643-4C33-90F0-991EA6024B26}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{91A20DDB-5032-429E-95A1-37D824CAE14C}]
C:\WINDOWS\system32\geeby.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A923799F-552B-429D-8327-FECA1E0D65E0}]
C:\WINDOWS\system32\ddccd.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E0B54BEC-9209-4B5D-94E5-A8906DE18FFB}]
2007-11-15 07:47 37376 --a------ C:\WINDOWS\system32\efcayaw.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2006-08-14 13:00 C:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-16 17:04 C:\WINDOWS\SkyTel.exe]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 17:32]
"DU Meter"="C:\Program Files\DU Meter\DUMeter.exe" [2002-06-23 21:19]
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2007-04-08 02:56]
"Tweak UI"="TWEAKUI.CPL" [2000-06-18 14:03 C:\WINDOWS\system32\TWEAKUI.CPL]
"PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2006-11-08 13:27]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-06-29 00:43]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 16:24]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-06-29 00:43]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:56]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-06-20 22:36]
"CTSyncU.exe"="C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe" [2006-09-13 11:00]
"MtdAcqu"="C:\Program Files\Creative\MediaSource5\MtdAcqu.exe" [2006-03-08 08:56]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2006-11-12 17:48]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"PcSync"=C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{E0B54BEC-9209-4B5D-94E5-A8906DE18FFB}"= C:\WINDOWS\system32\efcayaw.dll [2007-11-15 07:47 37376]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\efcayaw]
efcayaw.dll 2007-11-15 07:47 37376 C:\WINDOWS\system32\efcayaw.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\pmkjk.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
"Phase One Media Reader"=C:\PROGRA~1\PHASEO~1\CAPTUR~1\DCIMImp.exe /noscan /CheckAutoStart
"WinampAgent"=C:\Program Files\Winamp\winampa.exe
"Acrobat Assistant 7.0"="C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
"JMB36X Configure"=C:\WINDOWS\system32\JMRaidTool.exe boot
"nwiz"=nwiz.exe /install
R0 videX32;videX32;C:\WINDOWS\system32\DRIVERS\videX32.sys
R0 xfilt;VIA SATA IDE Hot-plug Driver;C:\WINDOWS\system32\DRIVERS\xfilt.sys
R2 NPF;NetGroup Packet Filter Driver;C:\WINDOWS\system32\drivers\npf.sys
R2 nvcap;nVidia WDM Video Capture (universal);C:\WINDOWS\system32\DRIVERS\nvcap.sys
R2 NVXBAR;nVidia WDM A/V Crossbar;C:\WINDOWS\system32\DRIVERS\NVxbar.sys
.
Contents of the 'Scheduled Tasks' folder
"2007-11-16 10:15:00 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2006\SystemOptimizer.exe
"2007-11-16 13:00:00 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer - Administrator.job"
- C:\PROGRA~1\NORTON~1\Navw32.exe
.
**************************************************************************
catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-17 23:51:08
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-17 23:56:40 - machine was rebooted
.
--- E O F ---
VUNDOFIX LOG =================
VundoFix V6.6.2
Checking Java version...
Java version is 1.5.0.9
Old versions of java are exploitable and should be removed.
Scan started at 11:15:41 PM 11/17/2007
Listing files found while scanning....
C:\windows\system32\dccdd.ini
C:\windows\system32\dccdd.ini2
C:\windows\system32\ddccd.dll
Beginning removal...
Attempting to delete C:\windows\system32\dccdd.ini
C:\windows\system32\dccdd.ini Has been deleted!
Attempting to delete C:\windows\system32\dccdd.ini2
C:\windows\system32\dccdd.ini2 Has been deleted!
Attempting to delete C:\windows\system32\ddccd.dll
C:\windows\system32\ddccd.dll Could not be deleted.
Performing Repairs to the registry.
Done!
Beginning removal...
Attempting to delete C:\windows\system32\dccdd.ini
C:\windows\system32\dccdd.ini Has been deleted!
Attempting to delete C:\windows\system32\dccdd.ini2
C:\windows\system32\dccdd.ini2 Has been deleted!
Attempting to delete C:\windows\system32\ddccd.dll
C:\windows\system32\ddccd.dll Has been deleted!
Performing Repairs to the registry.
Done!
COMBOFIX LOG =================
ComboFix 07-11-08.1 - mufti 2007-11-17 23:39:45.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1561 [GMT 7:00]
Running from: D:\Documents and Settings\mufti\Desktop\ComboFix.exe
.
Unable to gain System Privileges
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\kjkmp.ini
C:\WINDOWS\system32\kjkmp.ini2
C:\WINDOWS\system32\pmkjk.dll
.
((((((((((((((((((((((((( Files Created from 2007-10-17 to 2007-11-17 )))))))))))))))))))))))))))))))
.
2007-11-17 23:15 <DIR> d-------- C:\VundoFix Backups
2007-11-17 23:05 52,072 --a------ C:\WINDOWS\system32\pmnlm.dll
2007-11-17 22:57 <DIR> d-------- C:\Program Files\Trend Micro
2007-11-17 22:06 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-11-17 20:41 85,056 --a------ C:\WINDOWS\system32\uwrnukni.dll
2007-11-17 20:41 82,496 --a------ C:\WINDOWS\system32\fsrvoodx.dll
2007-11-17 20:38 71,232 --a------ C:\WINDOWS\system32\tsujtqos.exe
2007-11-17 12:02 <DIR> d-------- D:\Documents and Settings\mufti\Application Data\JPEGsnoop
2007-11-16 16:56 85,056 --a------ C:\WINDOWS\system32\tvwbvnut.dll
2007-11-16 16:53 81,984 --a------ C:\WINDOWS\system32\sklyhbbg.dll
2007-11-15 23:13 <DIR> d-------- C:\Program Files\DOSBox-0.63
2007-11-15 07:47 37,376 --a------ C:\WINDOWS\system32\yayxxxy.dll
2007-11-15 07:47 37,376 --a------ C:\WINDOWS\system32\efcayaw.dll
2007-11-15 07:26 <DIR> d-a------ D:\Documents and Settings\All Users\Application Data\TEMP
2007-11-15 07:25 <DIR> d-------- C:\Program Files\DAP
2007-11-15 05:59 <DIR> d-------- C:\Program Files\Second Sight Software
2007-10-30 01:06 413,760 --a------ C:\WINDOWS\system32\MPG4C32.DLL
2007-10-24 20:37 <DIR> d-------- C:\Program Files\Monte Cristo
2007-10-21 18:43 <DIR> d-------- D:\Documents and Settings\mufti\Application Data\Command & Conquer 3 Tiberium Wars
2007-10-21 18:17 <DIR> d-------- C:\Program Files\DAEMON Tools
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-17 04:59 --------- d-----w D:\Documents and Settings\mufti\Application Data\Printer Info Cache
2007-11-17 04:59 --------- d-----w D:\Documents and Settings\mufti\Application Data\Image Zone Express
2007-11-17 02:35 --------- d-----w D:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-11-17 01:31 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-11-16 10:17 --------- d-----w C:\Program Files\Microsoft ActiveSync
2007-10-21 11:41 --------- d-----w C:\Program Files\Electronic Arts
2007-10-20 03:24 --------- d-----w C:\Program Files\HP
2007-10-12 17:40 --------- d-----w C:\Program Files\Google
2007-10-12 16:28 --------- d-----w D:\Documents and Settings\mufti\Application Data\Command & Conquer 3 Tiberium Wars Demo
2007-10-11 03:22 --------- d-----w C:\Program Files\Java
2007-10-10 12:50 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-10-10 11:39 --------- d-----w D:\Documents and Settings\All Users\Application Data\Firefly Studios
2007-10-10 11:35 --------- d-----w D:\Documents and Settings\All Users\Application Data\SecTaskMan
2007-10-08 13:13 --------- d-----w C:\Program Files\Winamp
2007-10-08 05:33 --------- d-----w C:\Program Files\Yahoo!
2007-10-06 10:23 --------- d-----w C:\Program Files\CCP
2007-10-05 19:17 --------- d-----w C:\Program Files\Security Task Manager
2007-10-04 19:26 --------- d-----w C:\Program Files\Alcohol Soft
2007-10-04 19:12 --------- d--h--r D:\Documents and Settings\mufti\Application Data\SecuROM
2007-10-03 05:53 --------- d-----w D:\Documents and Settings\mufti\Application Data\Gamelab
2007-10-02 20:47 --------- d-----w D:\Documents and Settings\All Users\Application Data\Apple Computer
2007-10-02 20:46 --------- d-----w C:\Program Files\K-Lite Codec Pack
2007-09-30 04:34 --------- d-----w D:\Documents and Settings\mika\Application Data\HP
2007-09-29 03:06 --------- d-----w D:\Documents and Settings\dana\Application Data\HP
2007-09-28 15:46 --------- d-----w C:\Program Files\QuickPar
2007-09-27 09:01 --------- d-----w C:\Program Files\Common Files\HP
2007-09-27 08:45 --------- d-----w D:\Documents and Settings\mufti\Application Data\HP
2007-09-27 08:29 --------- d-----w D:\Documents and Settings\All Users\Application Data\HP
2007-09-27 08:25 --------- d-----w C:\Program Files\Hewlett-Packard
2007-09-27 08:25 --------- d-----w C:\Program Files\Common Files\Hewlett-Packard
2007-09-26 03:44 --------- d-----w C:\Program Files\MatrixEngine 1.0
2007-09-24 04:45 --------- d-----w C:\Program Files\Camfrog
2007-09-22 12:17 --------- d-----w C:\Program Files\Astraware
2007-08-21 06:25 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{549B5CA7-4A86-11D7-A4DF-000874180BB3}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{761BCB47-850E-4893-BDA7-4952EF459F14}]
C:\WINDOWS\system32\pmnno.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{89F3D70D-7643-4C33-90F0-991EA6024B26}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{91A20DDB-5032-429E-95A1-37D824CAE14C}]
C:\WINDOWS\system32\geeby.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A923799F-552B-429D-8327-FECA1E0D65E0}]
C:\WINDOWS\system32\ddccd.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E0B54BEC-9209-4B5D-94E5-A8906DE18FFB}]
2007-11-15 07:47 37376 --a------ C:\WINDOWS\system32\efcayaw.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2006-08-14 13:00 C:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-16 17:04 C:\WINDOWS\SkyTel.exe]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 17:32]
"DU Meter"="C:\Program Files\DU Meter\DUMeter.exe" [2002-06-23 21:19]
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2007-04-08 02:56]
"Tweak UI"="TWEAKUI.CPL" [2000-06-18 14:03 C:\WINDOWS\system32\TWEAKUI.CPL]
"PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2006-11-08 13:27]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-06-29 00:43]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 16:24]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-06-29 00:43]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:56]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-06-20 22:36]
"CTSyncU.exe"="C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe" [2006-09-13 11:00]
"MtdAcqu"="C:\Program Files\Creative\MediaSource5\MtdAcqu.exe" [2006-03-08 08:56]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2006-11-12 17:48]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"PcSync"=C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{E0B54BEC-9209-4B5D-94E5-A8906DE18FFB}"= C:\WINDOWS\system32\efcayaw.dll [2007-11-15 07:47 37376]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\efcayaw]
efcayaw.dll 2007-11-15 07:47 37376 C:\WINDOWS\system32\efcayaw.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\pmkjk.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
"Phase One Media Reader"=C:\PROGRA~1\PHASEO~1\CAPTUR~1\DCIMImp.exe /noscan /CheckAutoStart
"WinampAgent"=C:\Program Files\Winamp\winampa.exe
"Acrobat Assistant 7.0"="C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
"JMB36X Configure"=C:\WINDOWS\system32\JMRaidTool.exe boot
"nwiz"=nwiz.exe /install
R0 videX32;videX32;C:\WINDOWS\system32\DRIVERS\videX32.sys
R0 xfilt;VIA SATA IDE Hot-plug Driver;C:\WINDOWS\system32\DRIVERS\xfilt.sys
R2 NPF;NetGroup Packet Filter Driver;C:\WINDOWS\system32\drivers\npf.sys
R2 nvcap;nVidia WDM Video Capture (universal);C:\WINDOWS\system32\DRIVERS\nvcap.sys
R2 NVXBAR;nVidia WDM A/V Crossbar;C:\WINDOWS\system32\DRIVERS\NVxbar.sys
.
Contents of the 'Scheduled Tasks' folder
"2007-11-16 10:15:00 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2006\SystemOptimizer.exe
"2007-11-16 13:00:00 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer - Administrator.job"
- C:\PROGRA~1\NORTON~1\Navw32.exe
.
**************************************************************************
catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-17 23:51:08
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-17 23:56:40 - machine was rebooted
.
--- E O F ---