fsbl-20070329002742:
03/28/07 20:27:42 [Info]: BlackLight Engine 1.0.55 initialized
03/28/07 20:27:42 [Info]: OS: 5.1 build 2600 (Service Pack 2)
03/28/07 20:27:42 [Note]: 7019 4
03/28/07 20:27:42 [Note]: 7005 0
03/28/07 20:27:44 [Note]: 7006 0
03/28/07 20:27:44 [Note]: 7011 636
03/28/07 20:27:44 [Note]: 7026 0
03/28/07 20:27:45 [Note]: 7026 0
03/28/07 20:27:48 [Note]: FSRAW library version 1.7.1021
03/28/07 20:33:44 [Note]: 2000 1012
03/28/07 20:34:08 [Note]: 7007 0
ComboFix:
"Andy" - 07-03-28 20:20:09 Service Pack 2
ComboFix 07-03-27.4.2 - Running from: "C:\Documents and Settings\Andy\Desktop"
((((((((((((((((((((((((((((((( Files Created from 2007-02-28 to 2007-03-28 ))))))))))))))))))))))))))))))))))
2007-03-24 22:50 79,360 --a------ C:\WINDOWS\system32\swxcacls.exe
2007-03-24 22:50 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-03-24 22:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-03-24 22:50 40,960 --a------ C:\WINDOWS\system32\swsc.exe
2007-03-24 22:50 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2007-03-24 22:50 135,168 --a------ C:\WINDOWS\system32\swreg.exe
2007-03-24 22:40 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-03-20 19:42 4,076 --a------ C:\WINDOWS\system32\tmp.reg
2007-03-20 19:37 <DIR> d-------- C:\VundoFix Backups
2007-03-19 20:12 <DIR> d-------- C:\DOCUME~1\Andy\APPLIC~1\Pixela
2007-03-19 19:56 <DIR> d-------- C:\Program Files\PIXELA
2007-03-19 18:49 2,560 --------- C:\WINDOWS\system32\drivers\cdralw2k.sys
2007-03-19 18:49 2,432 --------- C:\WINDOWS\system32\drivers\cdr4_xp.sys
2007-03-19 18:49 129,784 --------- C:\WINDOWS\system32\pxafs.dll
2007-03-11 09:25 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2007-03-04 20:11 <DIR> d-------- C:\Program Files\Sunbelt Software
2007-03-04 20:08 <DIR> d-------- C:\agnis-sites
2007-03-04 20:05 <DIR> d-------- C:\Program Files\SpywareGuard
2007-03-04 19:47 <DIR> d-------- C:\Program Files\Windows Defender
2007-03-04 19:42 <DIR> d-------- C:\WINDOWS\network diagnostic
2007-03-04 19:33 <DIR> d-------- C:\Program Files\SpywareBlaster
2007-03-04 18:59 <DIR> d-------- C:\Program Files\Common Files\Adobe
2007-03-04 18:59 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
2007-03-04 18:56 <DIR> d-------- C:\DOCUME~1\LOCALS~1\APPLIC~1\pdf995
2007-03-04 18:56 <DIR> d-------- C:\DOCUME~1\Andy\APPLIC~1\pdf995
2007-03-04 17:23 <DIR> d-------- C:\Program Files\MSXML 4.0
2007-03-04 16:24 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2007-03-04 16:12 49,152 --a------ C:\WINDOWS\system32\ugorahl.dll
2007-03-04 11:30 51,716 --a------ C:\WINDOWS\system32\pdf995mon.dll
2007-03-04 11:30 118,784 --a------ C:\WINDOWS\system32\pdfmona.dll
2007-03-04 11:30 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\pdf995
2007-03-04 11:29 54,272 --a------ C:\WINDOWS\system32\tmpwisc1.exe
2007-03-04 11:28 <DIR> d-------- C:\Program Files\TaxCut06
2007-03-04 11:25 48,640 --a------ C:\WINDOWS\system32\qwrmvrj.dll
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-03-28 20:16 384 --a------ C:\WINDOWS\system32\dvcstatebkp-{00000001-00000000-00000007-00001102-00000004-20021102}.dat
2007-03-28 20:16 384 --a------ C:\WINDOWS\system32\dvcstate-{00000001-00000000-00000007-00001102-00000004-20021102}.dat
2007-03-28 20:15 -------- d-------- C:\Program Files\Common Files\symantec shared
2007-03-19 19:56 -------- d--h----- C:\Program Files\installshield installation information
2007-03-19 18:49 -------- d-------- C:\Program Files\divx
2007-03-18 11:58 -------- d-------- C:\Program Files\java
2007-03-04 16:54 -------- d-------- C:\Program Files\quicktime
2007-03-04 11:16 4212 ---h----- C:\WINDOWS\system32\zllictbl.dat
2007-02-23 00:29 524288 --a------ C:\WINDOWS\system32\divxsm.exe
2007-02-23 00:29 36624 --------- C:\WINDOWS\system32\drivers\PxHelp20.sys
2007-02-23 00:29 3596288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2007-02-23 00:29 200704 --a------ C:\WINDOWS\system32\ssldivx.dll
2007-02-23 00:29 118520 --------- C:\WINDOWS\system32\pxinsi64.exe
2007-02-23 00:29 116472 --------- C:\WINDOWS\system32\pxcpyi64.exe
2007-02-23 00:29 1044480 --a------ C:\WINDOWS\system32\libdivx.dll
2007-02-23 00:25 823296 --a------ C:\WINDOWS\system32\divx_xx0c.dll
2007-02-23 00:25 823296 --a------ C:\WINDOWS\system32\divx_xx07.dll
2007-02-23 00:25 802816 --a------ C:\WINDOWS\system32\divx_xx11.dll
2007-02-23 00:25 73728 --a------ C:\WINDOWS\system32\dpl100.dll
2007-02-23 00:25 639066 --a------ C:\WINDOWS\system32\divx.dll
2007-02-23 00:25 593920 --a------ C:\WINDOWS\system32\dpugui11.dll
2007-02-23 00:25 57344 --a------ C:\WINDOWS\system32\dpv11.dll
2007-02-23 00:25 53248 --a------ C:\WINDOWS\system32\dpugui10.dll
2007-02-23 00:25 344064 --a------ C:\WINDOWS\system32\dpus11.dll
2007-02-23 00:25 294912 --a------ C:\WINDOWS\system32\dpu11.dll
2007-02-23 00:25 294912 --a------ C:\WINDOWS\system32\dpu10.dll
2007-02-23 00:25 196608 --a------ C:\WINDOWS\system32\dtu100.dll
2007-02-20 14:34 71088 --a------ C:\WINDOWS\system32\drivers\khips.sys
2007-02-20 14:34 302000 --a------ C:\WINDOWS\system32\drivers\fwdrv.sys
2007-02-15 21:40 124472 --a------ C:\WINDOWS\system32\divxcodecupdatechecker.exe
2007-02-01 20:16 -------- d-------- C:\DOCUME~1\Andy\APPLIC~1\ultra
2007-01-08 20:01 17408 --a------ C:\WINDOWS\system32\corpol.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"RemoteCenter"="C:\\Program Files\\Creative\\MediaSource\\RemoteControl\\RCMan.EXE"
"updateMgr"="C:\\Program Files\\Adobe\\Acrobat 7.0\\Reader\\AdobeUpdateManager.exe AcRdB7_0_9"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"USIUDF_Eject_Monitor"="C:\\Program Files\\Common Files\\Ulead Systems\\DVD\\USISrv.exe"
"UpdReg"="C:\\WINDOWS\\UpdReg.EXE"
"Ulead Quick-Drop"="\"C:\\Program Files\\Ulead Systems\\Ulead DVD MovieFactory 4.0 Suite\\Ulead Quick-Drop 1.0\\Quick-Drop.exe\" WINDOWCALL"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_10\\bin\\jusched.exe\""
"SBDrvDet"="C:\\Program Files\\Creative\\SB Drive Det\\SBDrvDet.exe /r"
"nwiz"="nwiz.exe /install"
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"nTrayFw"="C:\\Program Files\\NVIDIA Corporation\\NetworkAccessManager\\bin\\nTrayFw.exe"
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"HP Software Update"="C:\\Program Files\\HP\\HP Software Update\\HPWuSchd2.exe"
"CTSysVol"="C:\\Program Files\\Creative\\SBAudigy2ZS\\Surround Mixer\\CTSysVol.exe /r"
"CTHelper"="CTHELPER.EXE"
"CTDVDDET"="C:\\Program Files\\Creative\\SBAudigy2ZS\\DVDAudio\\CTDVDDet.EXE"
"AGRSMMSG"="AGRSMMSG.exe"
"NWEReboot"=""
"DAEMON Tools"="\"C:\\Program Files\\DAEMON Tools\\daemon.exe\" -lang 1033"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"SNM"="C:\\Program Files\\SpyNoMore\\SNM.exe /startup"
"Windows Defender"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide"
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgcc.exe /STARTUP"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"="Microsoft AntiMalware ShellExecuteHook"
"{81559C35-8464-49F7-BB0E-07A383BEF910}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, ntoskrnl.dll, xlibgfl254.dll"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\D]
Shell\AutoRun\command D:\stub.exe
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b0b48b29-8fe9-11da-88eb-806d6172696f}]
Shell\AutoRun\command D:\Setup.EXE
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Backup060714.job
C:\WINDOWS\tasks\MP Scheduled Scan.job
********************************************************************
catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
********************************************************************
Completion time: 07-03-28 20:24:59
03/28/07 20:27:42 [Info]: BlackLight Engine 1.0.55 initialized
03/28/07 20:27:42 [Info]: OS: 5.1 build 2600 (Service Pack 2)
03/28/07 20:27:42 [Note]: 7019 4
03/28/07 20:27:42 [Note]: 7005 0
03/28/07 20:27:44 [Note]: 7006 0
03/28/07 20:27:44 [Note]: 7011 636
03/28/07 20:27:44 [Note]: 7026 0
03/28/07 20:27:45 [Note]: 7026 0
03/28/07 20:27:48 [Note]: FSRAW library version 1.7.1021
03/28/07 20:33:44 [Note]: 2000 1012
03/28/07 20:34:08 [Note]: 7007 0
ComboFix:
"Andy" - 07-03-28 20:20:09 Service Pack 2
ComboFix 07-03-27.4.2 - Running from: "C:\Documents and Settings\Andy\Desktop"
((((((((((((((((((((((((((((((( Files Created from 2007-02-28 to 2007-03-28 ))))))))))))))))))))))))))))))))))
2007-03-24 22:50 79,360 --a------ C:\WINDOWS\system32\swxcacls.exe
2007-03-24 22:50 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-03-24 22:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-03-24 22:50 40,960 --a------ C:\WINDOWS\system32\swsc.exe
2007-03-24 22:50 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2007-03-24 22:50 135,168 --a------ C:\WINDOWS\system32\swreg.exe
2007-03-24 22:40 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-03-20 19:42 4,076 --a------ C:\WINDOWS\system32\tmp.reg
2007-03-20 19:37 <DIR> d-------- C:\VundoFix Backups
2007-03-19 20:12 <DIR> d-------- C:\DOCUME~1\Andy\APPLIC~1\Pixela
2007-03-19 19:56 <DIR> d-------- C:\Program Files\PIXELA
2007-03-19 18:49 2,560 --------- C:\WINDOWS\system32\drivers\cdralw2k.sys
2007-03-19 18:49 2,432 --------- C:\WINDOWS\system32\drivers\cdr4_xp.sys
2007-03-19 18:49 129,784 --------- C:\WINDOWS\system32\pxafs.dll
2007-03-11 09:25 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2007-03-04 20:11 <DIR> d-------- C:\Program Files\Sunbelt Software
2007-03-04 20:08 <DIR> d-------- C:\agnis-sites
2007-03-04 20:05 <DIR> d-------- C:\Program Files\SpywareGuard
2007-03-04 19:47 <DIR> d-------- C:\Program Files\Windows Defender
2007-03-04 19:42 <DIR> d-------- C:\WINDOWS\network diagnostic
2007-03-04 19:33 <DIR> d-------- C:\Program Files\SpywareBlaster
2007-03-04 18:59 <DIR> d-------- C:\Program Files\Common Files\Adobe
2007-03-04 18:59 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
2007-03-04 18:56 <DIR> d-------- C:\DOCUME~1\LOCALS~1\APPLIC~1\pdf995
2007-03-04 18:56 <DIR> d-------- C:\DOCUME~1\Andy\APPLIC~1\pdf995
2007-03-04 17:23 <DIR> d-------- C:\Program Files\MSXML 4.0
2007-03-04 16:24 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2007-03-04 16:12 49,152 --a------ C:\WINDOWS\system32\ugorahl.dll
2007-03-04 11:30 51,716 --a------ C:\WINDOWS\system32\pdf995mon.dll
2007-03-04 11:30 118,784 --a------ C:\WINDOWS\system32\pdfmona.dll
2007-03-04 11:30 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\pdf995
2007-03-04 11:29 54,272 --a------ C:\WINDOWS\system32\tmpwisc1.exe
2007-03-04 11:28 <DIR> d-------- C:\Program Files\TaxCut06
2007-03-04 11:25 48,640 --a------ C:\WINDOWS\system32\qwrmvrj.dll
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-03-28 20:16 384 --a------ C:\WINDOWS\system32\dvcstatebkp-{00000001-00000000-00000007-00001102-00000004-20021102}.dat
2007-03-28 20:16 384 --a------ C:\WINDOWS\system32\dvcstate-{00000001-00000000-00000007-00001102-00000004-20021102}.dat
2007-03-28 20:15 -------- d-------- C:\Program Files\Common Files\symantec shared
2007-03-19 19:56 -------- d--h----- C:\Program Files\installshield installation information
2007-03-19 18:49 -------- d-------- C:\Program Files\divx
2007-03-18 11:58 -------- d-------- C:\Program Files\java
2007-03-04 16:54 -------- d-------- C:\Program Files\quicktime
2007-03-04 11:16 4212 ---h----- C:\WINDOWS\system32\zllictbl.dat
2007-02-23 00:29 524288 --a------ C:\WINDOWS\system32\divxsm.exe
2007-02-23 00:29 36624 --------- C:\WINDOWS\system32\drivers\PxHelp20.sys
2007-02-23 00:29 3596288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2007-02-23 00:29 200704 --a------ C:\WINDOWS\system32\ssldivx.dll
2007-02-23 00:29 118520 --------- C:\WINDOWS\system32\pxinsi64.exe
2007-02-23 00:29 116472 --------- C:\WINDOWS\system32\pxcpyi64.exe
2007-02-23 00:29 1044480 --a------ C:\WINDOWS\system32\libdivx.dll
2007-02-23 00:25 823296 --a------ C:\WINDOWS\system32\divx_xx0c.dll
2007-02-23 00:25 823296 --a------ C:\WINDOWS\system32\divx_xx07.dll
2007-02-23 00:25 802816 --a------ C:\WINDOWS\system32\divx_xx11.dll
2007-02-23 00:25 73728 --a------ C:\WINDOWS\system32\dpl100.dll
2007-02-23 00:25 639066 --a------ C:\WINDOWS\system32\divx.dll
2007-02-23 00:25 593920 --a------ C:\WINDOWS\system32\dpugui11.dll
2007-02-23 00:25 57344 --a------ C:\WINDOWS\system32\dpv11.dll
2007-02-23 00:25 53248 --a------ C:\WINDOWS\system32\dpugui10.dll
2007-02-23 00:25 344064 --a------ C:\WINDOWS\system32\dpus11.dll
2007-02-23 00:25 294912 --a------ C:\WINDOWS\system32\dpu11.dll
2007-02-23 00:25 294912 --a------ C:\WINDOWS\system32\dpu10.dll
2007-02-23 00:25 196608 --a------ C:\WINDOWS\system32\dtu100.dll
2007-02-20 14:34 71088 --a------ C:\WINDOWS\system32\drivers\khips.sys
2007-02-20 14:34 302000 --a------ C:\WINDOWS\system32\drivers\fwdrv.sys
2007-02-15 21:40 124472 --a------ C:\WINDOWS\system32\divxcodecupdatechecker.exe
2007-02-01 20:16 -------- d-------- C:\DOCUME~1\Andy\APPLIC~1\ultra
2007-01-08 20:01 17408 --a------ C:\WINDOWS\system32\corpol.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"RemoteCenter"="C:\\Program Files\\Creative\\MediaSource\\RemoteControl\\RCMan.EXE"
"updateMgr"="C:\\Program Files\\Adobe\\Acrobat 7.0\\Reader\\AdobeUpdateManager.exe AcRdB7_0_9"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"USIUDF_Eject_Monitor"="C:\\Program Files\\Common Files\\Ulead Systems\\DVD\\USISrv.exe"
"UpdReg"="C:\\WINDOWS\\UpdReg.EXE"
"Ulead Quick-Drop"="\"C:\\Program Files\\Ulead Systems\\Ulead DVD MovieFactory 4.0 Suite\\Ulead Quick-Drop 1.0\\Quick-Drop.exe\" WINDOWCALL"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_10\\bin\\jusched.exe\""
"SBDrvDet"="C:\\Program Files\\Creative\\SB Drive Det\\SBDrvDet.exe /r"
"nwiz"="nwiz.exe /install"
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"nTrayFw"="C:\\Program Files\\NVIDIA Corporation\\NetworkAccessManager\\bin\\nTrayFw.exe"
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"HP Software Update"="C:\\Program Files\\HP\\HP Software Update\\HPWuSchd2.exe"
"CTSysVol"="C:\\Program Files\\Creative\\SBAudigy2ZS\\Surround Mixer\\CTSysVol.exe /r"
"CTHelper"="CTHELPER.EXE"
"CTDVDDET"="C:\\Program Files\\Creative\\SBAudigy2ZS\\DVDAudio\\CTDVDDet.EXE"
"AGRSMMSG"="AGRSMMSG.exe"
"NWEReboot"=""
"DAEMON Tools"="\"C:\\Program Files\\DAEMON Tools\\daemon.exe\" -lang 1033"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"SNM"="C:\\Program Files\\SpyNoMore\\SNM.exe /startup"
"Windows Defender"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide"
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgcc.exe /STARTUP"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"="Microsoft AntiMalware ShellExecuteHook"
"{81559C35-8464-49F7-BB0E-07A383BEF910}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, ntoskrnl.dll, xlibgfl254.dll"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\D]
Shell\AutoRun\command D:\stub.exe
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b0b48b29-8fe9-11da-88eb-806d6172696f}]
Shell\AutoRun\command D:\Setup.EXE
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Backup060714.job
C:\WINDOWS\tasks\MP Scheduled Scan.job
********************************************************************
catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
********************************************************************
Completion time: 07-03-28 20:24:59