virus and trojans
ComboFix 07-12-19.2 - Joey 2007-12-18 15:37:05.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.329 [GMT -6:00]
Running from: C:\Documents and Settings\Joey\Local Settings\Temporary Internet Files\Content.IE5\1GBE7RLB\ComboFix[1].exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Joey\Application Data\inst.exe
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\Temp\bkR11
C:\Temp\bkR11\ftCa.log
C:\temp\tn3
C:\WINDOWS\Fonts\a.zip
C:\WINDOWS\mrofinu1000140.exe
C:\WINDOWS\system32\pac.txt
C:\winlogon.exe
C:\WINDOWS\Fonts\'
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_CMDSERVICE
-------\LEGACY_CORE
-------\LEGACY_NETWORK_MONITOR
((((((((((((((((((((((((( Files Created from 2007-11-19 to 2007-12-19 )))))))))))))))))))))))))))))))
.
2007-12-19 15:39 . 2007-12-19 15:39 4,958,588 --------- C:\WINDOWS\{00000002-00000000-00000005-00001102-00000004-00531102}.BAK
2007-12-17 15:07 . 2007-12-17 15:07 <DIR> d-------- C:\WINDOWS\Cache
2007-12-17 15:07 . 2007-12-17 15:07 <DIR> d-------- C:\Program Files\Coupons
2007-12-17 15:07 . 2007-12-17 15:07 189,784 --------- C:\WINDOWS\system32\cpnprt2.cid
2007-12-17 15:07 . 2007-12-17 15:07 189,784 -rah----- C:\WINDOWS\cpnprt2.cid
2007-12-17 15:07 . 2007-12-17 15:07 82 --ah----- C:\WINDOWS\WindowsShellOld.Manifest.1
2007-12-17 15:07 . 2007-12-17 15:07 31 --ah----- C:\WINDOWS\uccspecc.sys
2007-12-16 20:49 . 2007-12-16 21:41 354 ---hs---- C:\WINDOWS\system32\cbspxtpd.ini
2007-12-16 20:46 . 2007-12-16 21:41 <DIR> d-------- C:\VundoFix Backups
2007-12-16 19:46 . 2007-12-16 19:46 2,274 ---hs---- C:\WINDOWS\system32\gaunbahe.ini
2007-12-16 18:46 . 2007-12-16 18:46 2,214 ---hs---- C:\WINDOWS\system32\pfgvvqdh.ini
2007-12-16 17:46 . 2007-12-16 17:46 2,154 ---hs---- C:\WINDOWS\system32\fkykgsqf.ini
2007-12-16 16:43 . 2007-12-16 16:43 2,034 ---hs---- C:\WINDOWS\system32\crrvmvlf.ini
2007-12-16 15:43 . 2007-12-16 15:43 1,974 ---hs---- C:\WINDOWS\system32\vfgymsql.ini
2007-12-16 14:43 . 2007-12-16 14:43 1,914 ---hs---- C:\WINDOWS\system32\aiopsdjp.ini
2007-12-16 14:40 . 2007-12-16 14:40 1,854 ---hs---- C:\WINDOWS\system32\wblkotcq.ini
2007-12-16 13:40 . 2007-12-16 13:40 1,794 ---hs---- C:\WINDOWS\system32\tskovaur.ini
2007-12-16 11:40 . 2007-12-16 11:40 1,674 ---hs---- C:\WINDOWS\system32\abfkuvuw.ini
2007-12-16 11:37 . 2007-12-16 11:37 1,614 ---hs---- C:\WINDOWS\system32\xsmcscwp.ini
2007-12-16 10:37 . 2007-12-16 10:37 1,554 ---hs---- C:\WINDOWS\system32\apepgenk.ini
2007-12-16 10:36 . 2007-12-16 10:36 1,494 ---hs---- C:\WINDOWS\system32\ptwylotr.ini
2007-12-16 09:34 . 2007-12-16 09:34 1,434 ---hs---- C:\WINDOWS\system32\eaidxuiu.ini
2007-12-16 08:34 . 2007-12-16 08:34 1,374 ---hs---- C:\WINDOWS\system32\kxkjeklm.ini
2007-12-16 07:34 . 2007-12-16 07:34 1,314 ---hs---- C:\WINDOWS\system32\tvapagdd.ini
2007-12-16 07:31 . 2007-12-16 07:31 1,254 ---hs---- C:\WINDOWS\system32\qvcfjhuq.ini
2007-12-16 06:31 . 2007-12-16 06:31 1,194 ---hs---- C:\WINDOWS\system32\lmjjyfcm.ini
2007-12-16 05:31 . 2007-12-16 05:31 1,134 ---hs---- C:\WINDOWS\system32\iadwerph.ini
2007-12-16 04:31 . 2007-12-16 04:31 1,074 ---hs---- C:\WINDOWS\system32\mvpsldvi.ini
2007-12-16 03:28 . 2007-12-16 03:28 954 ---hs---- C:\WINDOWS\system32\yshwkouv.ini
2007-12-16 02:26 . 2007-12-16 02:26 894 ---hs---- C:\WINDOWS\system32\fioiucfv.ini
2007-12-16 01:25 . 2007-12-16 01:25 834 ---hs---- C:\WINDOWS\system32\vqvficst.ini
2007-12-16 01:22 . 2007-12-16 01:22 774 ---hs---- C:\WINDOWS\system32\onimintj.ini
2007-12-16 00:22 . 2007-12-16 00:22 714 ---hs---- C:\WINDOWS\system32\sclkxshs.ini
2007-12-15 23:22 . 2007-12-15 23:22 654 ---hs---- C:\WINDOWS\system32\kwbbenom.ini
2007-12-15 22:22 . 2007-12-15 22:22 594 ---hs---- C:\WINDOWS\system32\sublgmtj.ini
2007-12-15 22:19 . 2007-12-15 22:19 534 ---hs---- C:\WINDOWS\system32\iffwfubt.ini
2007-12-15 21:19 . 2007-12-15 21:19 474 ---hs---- C:\WINDOWS\system32\dstehfil.ini
2007-12-15 20:19 . 2007-12-15 20:19 414 ---hs---- C:\WINDOWS\system32\snnlwaej.ini
2007-12-15 19:19 . 2007-12-15 19:19 354 ---hs---- C:\WINDOWS\system32\cggsfygh.ini
2007-12-15 19:16 . 2007-12-15 19:16 294 ---hs---- C:\WINDOWS\system32\rxtpctoe.ini
2007-12-14 11:26 . 2007-12-14 11:26 594 ---hs---- C:\WINDOWS\system32\slipsrke.ini
2007-12-14 11:23 . 2007-12-14 11:23 534 ---hs---- C:\WINDOWS\system32\tisjuxqu.ini
2007-12-14 10:23 . 2007-12-14 10:23 474 ---hs---- C:\WINDOWS\system32\kkjrwmfw.ini
2007-12-14 09:21 . 2007-12-14 09:21 414 ---hs---- C:\WINDOWS\system32\hfumcisx.ini
2007-12-14 09:18 . 2007-12-14 09:18 294 ---hs---- C:\WINDOWS\system32\oyrqxpgv.ini
2007-12-14 03:01 . 2007-12-14 09:18 354 ---hs---- C:\WINDOWS\system32\inpjilde.ini
2007-12-14 01:58 . 2007-12-14 01:58 1,494 ---hs---- C:\WINDOWS\system32\admhtchn.ini
2007-12-14 00:58 . 2007-12-14 00:58 1,434 ---hs---- C:\WINDOWS\system32\bglvoyki.ini
2007-12-13 23:58 . 2007-12-13 23:58 1,374 ---hs---- C:\WINDOWS\system32\roqsyqji.ini
2007-12-13 23:55 . 2007-12-13 23:55 1,314 ---hs---- C:\WINDOWS\system32\faqyuavo.ini
2007-12-13 23:07 . 2007-12-13 23:29 1,254 ---hs---- C:\WINDOWS\system32\tfrerltc.ini
2007-12-13 22:03 . 2007-12-13 22:10 1,194 ---hs---- C:\WINDOWS\system32\ooefwnid.ini
2007-12-13 20:52 . 2007-12-13 20:52 1,134 ---hs---- C:\WINDOWS\system32\uncxsiuj.ini
2007-12-13 20:49 . 2007-12-13 20:49 1,074 ---hs---- C:\WINDOWS\system32\hiniicga.ini
2007-12-13 19:49 . 2007-12-13 19:49 1,014 ---hs---- C:\WINDOWS\system32\fjqkwpxg.ini
2007-12-13 18:49 . 2007-12-13 18:49 954 ---hs---- C:\WINDOWS\system32\melntsfu.ini
2007-12-13 18:48 . 2007-12-13 18:48 894 ---hs---- C:\WINDOWS\system32\iusjwnmy.ini
2007-12-13 17:49 . 2007-12-13 17:50 834 ---hs---- C:\WINDOWS\system32\owhaqdyg.ini
2007-12-13 16:46 . 2007-12-13 16:46 774 ---hs---- C:\WINDOWS\system32\kdchtfhi.ini
2007-12-13 15:46 . 2007-12-13 15:46 714 ---hs---- C:\WINDOWS\system32\glknuhkk.ini
2007-12-13 15:43 . 2007-12-13 15:43 654 ---hs---- C:\WINDOWS\system32\bdkdprix.ini
2007-12-13 14:43 . 2007-12-13 14:43 594 ---hs---- C:\WINDOWS\system32\mqsklrut.ini
2007-12-13 13:43 . 2007-12-13 13:43 534 ---hs---- C:\WINDOWS\system32\wemyskfm.ini
2007-12-13 13:40 . 2007-12-13 13:40 474 ---hs---- C:\WINDOWS\system32\upexkcap.ini
2007-12-13 12:40 . 2007-12-13 12:40 414 ---hs---- C:\WINDOWS\system32\rbhaubxl.ini
2007-12-13 11:40 . 2007-12-13 11:40 354 ---hs---- C:\WINDOWS\system32\ghbijblk.ini
2007-12-13 11:37 . 2007-12-13 11:37 294 ---hs---- C:\WINDOWS\system32\ccdjiivk.ini
2007-12-13 10:37 . 2007-12-13 10:37 354 ---hs---- C:\WINDOWS\system32\egxdwnrq.ini
2007-12-13 10:34 . 2007-12-13 10:34 294 ---hs---- C:\WINDOWS\system32\gbdrvnoj.ini
2007-12-13 03:10 . 2007-12-13 03:07 1,314 --ahs---- C:\WINDOWS\system32\qrtnayfy.ini
2007-12-13 02:07 . 2007-12-13 02:07 1,254 ---hs---- C:\WINDOWS\system32\bmkwujso.ini
2007-12-13 01:07 . 2007-12-13 01:07 1,194 ---hs---- C:\WINDOWS\system32\sujeofip.ini
2007-12-13 00:07 . 2007-12-13 00:07 1,134 ---hs---- C:\WINDOWS\system32\brqtvxku.ini
2007-12-13 00:04 . 2007-12-13 00:04 1,074 ---hs---- C:\WINDOWS\system32\fmlhfpki.ini
2007-12-12 23:04 . 2007-12-12 23:04 1,014 ---hs---- C:\WINDOWS\system32\yglvbgje.ini
2007-12-12 22:04 . 2007-12-12 22:04 954 ---hs---- C:\WINDOWS\system32\nrmfdxey.ini
2007-12-12 21:04 . 2007-12-12 21:04 894 ---hs---- C:\WINDOWS\system32\erxgkxem.ini
2007-12-12 21:01 . 2007-12-12 21:01 834 ---hs---- C:\WINDOWS\system32\sdhhsqvo.ini
2007-12-12 20:00 . 2007-12-12 20:00 774 ---hs---- C:\WINDOWS\system32\ensstmhd.ini
2007-12-12 18:58 . 2007-12-12 18:58 714 ---hs---- C:\WINDOWS\system32\thgbbgek.ini
2007-12-12 17:58 . 2007-12-12 17:58 654 ---hs---- C:\WINDOWS\system32\gdrkqnsw.ini
2007-12-12 17:55 . 2007-12-12 17:55 594 ---hs---- C:\WINDOWS\system32\kpipywuk.ini
2007-12-12 16:55 . 2007-12-12 16:55 534 ---hs---- C:\WINDOWS\system32\ulcselfj.ini
2007-12-12 15:55 . 2007-12-12 15:55 474 ---hs---- C:\WINDOWS\system32\ygyfajhy.ini
2007-12-12 14:55 . 2007-12-12 14:55 414 ---hs---- C:\WINDOWS\system32\lmsrecai.ini
2007-12-12 14:52 . 2007-12-12 14:52 354 ---hs---- C:\WINDOWS\system32\iymhvrrv.ini
2007-12-12 13:52 . 2007-12-12 13:52 294 ---hs---- C:\WINDOWS\system32\mjkrabtg.ini
2007-12-12 12:50 . 2007-12-12 12:50 534 ---hs---- C:\WINDOWS\system32\upghmhem.ini
2007-12-12 11:45 . 2007-12-12 11:46 474 ---hs---- C:\WINDOWS\system32\xhohegnn.ini
2007-12-12 10:44 . 2007-12-12 10:44 414 ---hs---- C:\WINDOWS\system32\csaqkurm.ini
2007-12-12 10:41 . 2007-12-12 10:44 354 ---hs---- C:\WINDOWS\system32\qlqhpkpg.ini
2007-12-12 10:38 . 2007-12-12 10:38 294 ---hs---- C:\WINDOWS\system32\huyxlkst.ini
2007-12-07 16:17 . 2007-12-07 16:17 294 ---hs---- C:\WINDOWS\system32\omwxjrwr.ini
2007-12-06 16:14 . 2007-12-06 16:14 774 ---hs---- C:\WINDOWS\system32\huflsxcs.ini
2007-12-05 16:07 . 2007-12-05 16:07 294 ---hs---- C:\WINDOWS\system32\qxhdxexq.ini
2007-12-04 18:43 . 2007-12-04 18:43 <DIR> d-------- C:\Documents and Settings\Joey\LimeWire Store Purchased
2007-12-04 18:34 . 2007-12-04 18:58 <DIR> d-------- C:\Program Files\DVDFab Platinum 4
2007-12-04 16:05 . 2007-12-04 16:37 414 ---hs---- C:\WINDOWS\system32\rbaeesgm.ini
2007-12-04 15:58 . 2007-12-04 15:58 <DIR> d-------- C:\Program Files\Trend Micro
2007-12-04 10:02 . 2007-12-04 10:02 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-18 21:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\DVD Shrink
2007-12-07 06:51 --------- d-----w C:\Program Files\LimeWire
2007-12-07 06:51 --------- d-----w C:\Documents and Settings\Joey\Application Data\uTorrent
2007-12-07 06:51 --------- d-----w C:\Documents and Settings\Joey\Application Data\LimeWire
2007-12-05 01:27 --------- d-----w C:\Documents and Settings\Joey\Application Data\Vso
2007-12-05 01:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\SlySoft
2007-12-05 01:25 --------- d-----w C:\Program Files\SlySoft
2007-12-05 00:34 47,360 ----a-w C:\WINDOWS\system32\drivers\pcouffin.sys
2007-12-05 00:34 47,360 ----a-w C:\Documents and Settings\Joey\Application Data\pcouffin.sys
2007-12-03 15:23 --------- d-----w C:\Program Files\Common Files\LightScribe
2007-12-03 15:22 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-12-01 06:13 --------- d-----w C:\Program Files\uTorrent
2007-11-30 21:37 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-11-30 21:21 --------- d-----w C:\Program Files\Viewpoint
2007-11-30 21:21 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-12 23:05 --------- d-----w C:\Program Files\ZipForm Desktop
2007-11-09 18:25 --------- d-----w C:\Program Files\Nick Jr. Arcade
2007-11-08 01:43 --------- d-----w C:\Program Files\Common Files\Viewpoint
2007-11-07 23:19 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-11-07 05:07 --------- d-----w C:\Program Files\DVDFab Gold 4
2007-11-07 03:06 --------- d-----w C:\Program Files\DVDFab Platinum 3
2007-11-07 03:04 --------- d-----w C:\Program Files\DVD Region+CSS Free
2007-10-30 17:35 --------- d-----w C:\Program Files\HP
2007-10-29 22:43 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-27 23:39 230,912 ----a-w C:\WINDOWS\system32\wmasf.dll
2007-10-26 03:36 8,454,656 ----a-w C:\WINDOWS\system32\shell32(2).dll
2007-08-02 13:43 282,624 ----a-w C:\Program Files\TTC.dll
2007-07-01 14:26 21,848 ----a-w C:\Documents and Settings\Joey\Application Data\GDIPFONTCACHEV1.DAT
2006-02-19 08:28 12,288 ----a-w C:\WINDOWS\Fonts\RandFont.dll
2005-08-02 22:46 187,904 --sha-r C:\WINDOWS\Sm9zZSBMdW5h\asappsrv.dll
2005-08-02 22:58 293,888 --sha-r C:\WINDOWS\Sm9zZSBMdW5h\command.exe
2005-07-29 22:24 472 --sha-r C:\WINDOWS\Sm9zZSBMdW5h\mA6Wtm1gxqc1.vbs
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{18188503-F6A9-41C7-9FF2-9FE4A24C82DC}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{196328db-2270-44a6-985a-39cbcf35beda}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{36C3A207-3203-4670-BF2E-0C124A3D218B}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3DBB0EA0-EAB0-4DF3-AA70-239C1414A37E}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7C280CF0-2F02-4E6B-8815-CCFAC2BC6260}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{81DC16D1-A1F5-42DB-968E-70EA63FB61FE}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9CA7C156-EC64-4B12-BF92-F2650B1AB768}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B6BBC013-3647-4F3F-9DE8-C6136261A2F1}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{CEEA11ED-F489-475C-9600-69014E387E0F}]
C:\WINDOWS\system32\ddccd.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E20723B0-7483-4585-88B5-E0BE9220CC2E}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E3E7DB98-132A-424D-B8FF-C244FAC9024E}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 10:24]
"SMSystemAnalyzer"="C:\Program Files\iolo\System Mechanic Professional 6\SMSystemAnalyzer.exe" [2006-12-20 17:47]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ALi5289"="C:\Program Files\ULI5289\ALi5289.exe" [2004-09-16 16:49]
"CTHelper"="CTHELPER.EXE" [2007-04-09 11:32 C:\WINDOWS\system32\CtHelper.exe]
"CTxfiHlp"="CTXFIHLP.EXE" [2007-04-09 11:32 C:\WINDOWS\system32\Ctxfihlp.exe]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 09:50]
"NvCplDaemon"="RUNDLL32.exe" [2006-02-28 06:00 C:\WINDOWS\system32\rundll32.exe]
"nwiz"="nwiz.exe" [2006-10-22 11:22 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="RUNDLL32.exe" [2006-02-28 06:00 C:\WINDOWS\system32\rundll32.exe]
"itype"="C:\Program Files\Microsoft IntelliType Pro\itype.exe" [2006-11-21 16:08]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2007-02-05 14:52]
"Acronis Scheduler2 Service"="C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe" [2007-04-19 20:29]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-09-26 13:42]
"KAVPersonal50"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" [2006-07-19 08:27]
"184ef8d6"="C:\WINDOWS\system32\dptxpsbc.dll" []
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 05:24]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-06-07 16:39:30]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 03:21:22]
HP Photosmart Premier Fast Start.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2006-02-10 06:56:20]
Kaspersky Anti-Hacker.lnk - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Hacker\KAVPF.exe [2006-07-19 07:51:57]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{93994DE8-8239-4655-B1D1-5F4E91300429}"= C:\PROGRA~1\DVDREG~1\DVDShell.dll [2004-10-09 15:18 49152]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 relog_ap
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"WebBuying"=C:\Program Files\Web Buying\v1.8.6\webbuying.exe
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
R0 aliidex;aliidex;C:\WINDOWS\system32\drivers\aliidex.sys [2003-03-06 10:26]
R0 aliperf;aliperf;C:\WINDOWS\system32\drivers\aliperf.sys [2003-01-16 15:47]
R0 Klpf;Klpf;C:\WINDOWS\system32\drivers\Klpf.sys [2006-05-11 08:05]
R0 Klpid;Klpid;C:\WINDOWS\system32\drivers\Klpid.sys [2006-05-11 08:06]
R0 m5289;m5289;C:\WINDOWS\system32\DRIVERS\m5289.sys [2004-12-01 09:49]
R0 snapman;Acronis Snapshots Manager;C:\WINDOWS\system32\DRIVERS\snapman.sys [2007-07-22 13:26]
R0 timounter;Acronis True Image Backup Archive Explorer;C:\WINDOWS\system32\DRIVERS\timntr.sys [2007-07-22 13:26]
R0 uliagpkx;ULi AGP Bus Filter Driver;C:\WINDOWS\system32\DRIVERS\agpkx.sys [2004-07-08 14:58]
R1 Klmc;Klmc;C:\WINDOWS\system32\drivers\klmc.sys [2006-05-18 11:38]
R2 tifsfilter;Acronis True Image FS Filter;C:\WINDOWS\system32\DRIVERS\tifsfilt.sys [2007-07-22 13:26]
R3 ULI5261;ULi Based Ethernet NT Driver;C:\WINDOWS\system32\DRIVERS\ULILAN.SYS [2004-07-26 20:19]
S3 BVRPMPR5;BVRPMPR5 NDIS Protocol Driver;E:\INSTAL~E\Core\BVRPMPR5.SYS []
.
Contents of the 'Scheduled Tasks' folder
"2007-12-13 22:57:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-12-19 21:41:21 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-12-19 15:41:30
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
Completion time: 2007-12-19 15:43:56 - machine was rebooted
.
2007-12-14 09:01:04 --- E O F ---