combofix loggen:
ComboFix 07-11-19.3 - Martin Thorstein 2007-11-21 20:43:37.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1030.18.854 [GMT 1:00]
Running from: C:\Users\Martin Thorstein\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2007-10-21 to 2007-11-21 )))))))))))))))))))))))))))))))
.
2007-11-21 20:35 <DIR> d-------- C:\Users\All Users\Yahoo! Companion
2007-11-21 20:35 <DIR> d-------- C:\ProgramData\Yahoo! Companion
2007-11-21 20:25 <DIR> d-------- C:\Program Files\Yahoo!
2007-11-21 20:25 <DIR> d-------- C:\Program Files\CCleaner
2007-11-20 17:37 <DIR> d-------- C:\Users\Martin Thorstein\AppData\Roaming\SUPERAntiSpyware.com
2007-11-20 17:37 <DIR> d-------- C:\Users\All Users\SUPERAntiSpyware.com
2007-11-20 17:37 <DIR> d-------- C:\ProgramData\SUPERAntiSpyware.com
2007-11-20 17:37 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2007-11-20 17:17 <DIR> d-------- C:\Users\Martin Thorstein\DoctorWeb
2007-11-20 16:56 <DIR> d-------- C:\Program Files\SPYWAREfighter
2007-11-20 16:56 <DIR> d-------- C:\Program Files\Common Files\Application
2007-11-20 15:51 <DIR> d-------- C:\Users\All Users\Spybot - Search & Destroy
2007-11-20 15:51 <DIR> d-------- C:\ProgramData\Spybot - Search & Destroy
2007-11-20 15:13 <DIR> d-------- C:\Program Files\SpywareBlaster
2007-11-20 15:13 115,920 --a------ C:\Windows\System32\MSINET.OCX
2007-11-20 13:25 <DIR> d-------- C:\Users\Martin Thorstein\AppData\Roaming\PC Tools
2007-11-20 13:25 <DIR> d-------- C:\Program Files\Spyware Doctor
2007-11-20 13:06 29,696 --a------ C:\Users\Martin Thorstein\serial.exe
2007-11-20 13:06 9,728 --a------ C:\Users\Martin Thorstein\install.exe
2007-11-20 13:06 48 --a------ C:\Users\Martin Thorstein\readme.bat
2007-11-20 12:42 100 --a------ C:\Windows\System32\ikhcore.cfg
2007-11-20 12:36 626,688 --a------ C:\Windows\System32\msvcr80.dll
2007-11-20 12:01 <DIR> d-------- C:\Users\All Users\Lavasoft
2007-11-20 12:01 <DIR> d-------- C:\ProgramData\Lavasoft
2007-11-20 12:01 <DIR> d-------- C:\Program Files\Lavasoft
2007-11-20 12:01 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-11-10 10:58 <DIR> d-------- C:\Program Files\Ubisoft
2007-11-10 10:58 1 --a------ C:\Windows\System32\SI.bin
2007-11-10 10:56 <DIR> d-------- C:\Users\All Users\DAEMON Tools Pro
2007-11-10 10:56 <DIR> d-------- C:\ProgramData\DAEMON Tools Pro
2007-11-10 10:55 <DIR> d-------- C:\Users\Martin Thorstein\AppData\Roaming\DAEMON Tools Pro
2007-11-10 10:55 <DIR> d-------- C:\Program Files\DAEMON Tools Pro
2007-11-09 18:10 <DIR> d-------- C:\Users\Martin Thorstein\AppData\Roaming\Sports Interactive
2007-11-09 17:29 685,816 --a------ C:\Windows\System32\drivers\sptd.sys
2007-11-09 17:26 <DIR> d-------- C:\Users\All Users\e-Safekey
2007-11-09 17:26 <DIR> d-------- C:\ProgramData\e-Safekey
2007-11-09 15:24 <DIR> d-------- C:\Program Files\Windows Live Safety Center
2007-11-08 21:14 <DIR> d-------- C:\Program Files\ScandicBookmakers.com
2007-11-08 20:57 <DIR> d--h----- C:\Windows\msdownld.tmp
2007-11-08 19:48 <DIR> d-------- C:\Program Files\TVUPlayer
2007-11-08 19:45 <DIR> d-------- C:\Users\Martin Thorstein\AppData\Roaming\SopCast
2007-11-08 19:45 <DIR> d-------- C:\Program Files\SopCast
2007-11-08 19:13 1,824,768 --a------ C:\Windows\System32\inetcpl.cpl
2007-11-08 19:13 1,383,424 --a------ C:\Windows\System32\mshtml.tlb
2007-11-08 19:13 737,792 --a------ C:\Windows\System32\inetcomm.dll
2007-11-08 19:13 84,480 --a------ C:\Windows\System32\INETRES.dll
2007-11-08 19:12 <DIR> d-------- C:\Program Files\MSXML 4.0
2007-11-08 19:12 788,992 --a------ C:\Windows\System32\rpcrt4.dll
2007-11-08 19:07 <DIR> d-------- C:\Users\Martin Thorstein\AppData\Roaming\Hamachi
2007-11-08 19:07 <DIR> d-------- C:\Program Files\Hamachi
2007-11-08 18:56 <DIR> d-------- C:\Windows\PCHEALTH
2007-11-08 18:53 <DIR> dr-h----- C:\Users\Martin Thorstein\AppData\Roaming\SecuROM
2007-11-08 18:53 <DIR> d-------- C:\Program Files\Windows Live
2007-11-08 18:53 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2007-11-08 18:53 1,712,984 --a------ C:\Windows\System32\wuaueng.dll
2007-11-08 18:53 1,524,224 --a------ C:\Windows\System32\wucltux.dll
2007-11-08 18:53 53,080 --a------ C:\Windows\System32\wuauclt.exe
2007-11-08 18:53 43,352 --a------ C:\Windows\System32\wups2.dll
2007-11-08 18:52 <DIR> d-------- C:\Users\All Users\WLInstaller
2007-11-08 18:52 <DIR> d-------- C:\ProgramData\WLInstaller
2007-11-08 18:52 549,720 --a------ C:\Windows\System32\wuapi.dll
2007-11-08 18:52 80,896 --a------ C:\Windows\System32\wudriver.dll
2007-11-08 18:52 33,624 --a------ C:\Windows\System32\wups.dll
2007-11-08 18:51 163,000 --a------ C:\Windows\System32\wuwebv.dll
2007-11-08 18:51 31,232 --a------ C:\Windows\System32\wuapp.exe
2007-11-08 18:49 <DIR> d--h----- C:\Program Files\Zero G Registry
2007-11-08 18:49 <DIR> d-------- C:\Program Files\Sports Interactive
2007-11-08 18:48 <DIR> d--h----- C:\Users\Martin Thorstein\InstallAnywhere
2007-11-08 18:45 <DIR> d-------- C:\Users\Martin Thorstein\AppData\Roaming\Roxio
2007-11-08 18:44 <DIR> dr------- C:\Users\Martin Thorstein\Searches
2007-11-08 18:43 <DIR> dr------- C:\Users\Martin Thorstein\Contacts
2007-11-08 18:42 <DIR> dr------- C:\Users\Martin Thorstein\Videos
2007-11-08 18:42 <DIR> dr------- C:\Users\Martin Thorstein\Saved Games
2007-11-08 18:42 <DIR> dr------- C:\Users\Martin Thorstein\Pictures
2007-11-08 18:42 <DIR> dr------- C:\Users\Martin Thorstein\Music
2007-11-08 18:42 <DIR> dr------- C:\Users\Martin Thorstein\Links
2007-11-08 18:42 <DIR> dr------- C:\Users\Martin Thorstein\Downloads
2007-11-08 18:42 <DIR> dr------- C:\Users\Martin Thorstein\Documents
2007-11-08 18:42 <DIR> d-------- C:\Users\Martin Thorstein\AppData\Roaming\Media Center Programs
2007-11-08 18:42 <DIR> d--h----- C:\Users\Martin Thorstein\AppData
2007-11-08 18:40 <DIR> dr------- C:\Windows\System32\config\systemprofile\Contacts
2007-11-01 18:28 <DIR> d-------- C:\Program Files\DellTPad
2007-11-01 18:28 2,411,520 --a------ C:\Windows\System32\drivers\atikmdag.sys
2007-11-01 18:28 1,419,232 --a------ C:\Windows\System32\WdfCoInstaller01005.dll
2007-11-01 18:28 811,008 --a------ C:\Windows\System32\cximage.dll
2007-11-01 18:28 385,024 --a------ C:\Windows\System32\OEM02Cvw.dll
2007-11-01 18:28 331,776 --a------ C:\Windows\System32\OEM02Cvw.crl
2007-11-01 18:28 260,330 --a------ C:\Windows\System32\OEM02Cvw.bff
2007-11-01 18:28 157,184 --a------ C:\Windows\System32\drivers\Apfiltr.sys
2007-11-01 18:28 122,880 --a------ C:\Windows\System32\drivers\ahcix86s.sys
2007-11-01 18:28 100,410 --a------ C:\Windows\System32\Vxdif.dll
2007-11-01 18:28 94,208 --a------ C:\Windows\System32\mdmxsdk.dll
2007-11-01 18:28 90,112 --a------ C:\Windows\System32\snymsico.dll
2007-11-01 18:28 49,152 --a------ C:\Windows\System32\drivers\ati2erec.dll
2007-11-01 18:28 36,864 --a------ C:\Windows\System32\CtCamMgr.dll
2007-11-01 18:28 32,768 --a------ C:\Windows\System32\OEM02Hwx.dll
2007-11-01 18:27 3,503,800 --a------ C:\Windows\System32\ntkrnlpa.exe
2007-11-01 18:27 3,469,496 --a------ C:\Windows\System32\ntoskrnl.exe
2007-11-01 18:27 2,605,568 --a------ C:\Windows\System32\SLsvc.exe
2007-11-01 18:27 566,784 --a------ C:\Windows\System32\SLCommDlg.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-08 18:13 56,320 ----a-w C:\Windows\System32\iesetup.dll
2007-11-08 18:13 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2007-11-08 18:13 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2007-11-08 18:11 750,080 ----a-w C:\Windows\System32\qmgr.dll
2007-11-08 18:07 25,280 ----a-w C:\Windows\system32\drivers\hamachi.sys
2007-11-08 17:41 --------- d-sh--w C:\ProgramData\Skrivebord
2007-11-08 17:41 --------- d-sh--w C:\ProgramData\Skabeloner
2007-11-08 17:41 --------- d-sh--w C:\ProgramData\Menuen Start
2007-11-08 17:41 --------- d-sh--w C:\ProgramData\Favoritter
2007-11-08 17:41 --------- d-sh--w C:\ProgramData\Dokumenter
2007-11-08 17:41 --------- d-sh--w C:\ProgramData\Application Data
2007-11-08 17:41 --------- d-sh--w C:\Program Files\Fælles filer
2007-11-01 17:27 540,672 ----a-w C:\Windows\System32\sysmain.dll
2007-11-01 17:27 45,240 ----a-w C:\Windows\system32\drivers\pciidex.sys
2007-11-01 17:27 268,288 ----a-w C:\Windows\System32\mcbuilder.exe
2007-11-01 17:27 25,784 ------w C:\Windows\system32\drivers\msahci.sys
2007-11-01 17:27 21,688 ----a-w C:\Windows\system32\drivers\atapi.sys
2007-11-01 17:27 20,152 ------w C:\Windows\system32\drivers\viaide.sys
2007-11-01 17:27 19,128 ------w C:\Windows\system32\drivers\cmdide.sys
2007-11-01 17:27 18,104 ------w C:\Windows\system32\drivers\amdide.sys
2007-11-01 17:27 17,592 ------w C:\Windows\system32\drivers\intelide.sys
2007-11-01 17:27 17,592 ------w C:\Windows\system32\drivers\aliide.sys
2007-11-01 17:27 16,056 ----a-w C:\Windows\system32\drivers\pciide.sys
2007-11-01 17:27 110,264 ----a-w C:\Windows\system32\drivers\ataport.sys
2007-11-01 17:26 39,424 ----a-w C:\Windows\System32\ACCTRES.dll
2007-11-01 17:26 229,888 ----a-w C:\Windows\System32\msshsq.dll
2007-11-01 17:26 --------- d-----w C:\Program Files\Windows Mail
2007-11-01 17:25 86,016 ----a-w C:\Windows\System32\icfupgd.dll
2007-11-01 17:25 475,136 ----a-w C:\Windows\System32\evr.dll
2007-11-01 17:25 392,192 ----a-w C:\Windows\System32\FirewallAPI.dll
2007-11-01 17:25 374,456 ----a-w C:\Windows\System32\mcupdate_GenuineIntel.dll
2007-11-01 17:25 178,688 ----a-w C:\Windows\System32\iphlpsvc.dll
2007-11-01 17:25 1,327,104 ----a-w C:\Windows\System32\quartz.dll
2007-11-01 17:25 1,244,672 ----a-w C:\Windows\System32\mcmde.dll
2007-11-01 17:24 633,856 ----a-w C:\Windows\System32\user32.dll
2007-11-01 17:24 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
2007-11-01 17:24 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2007-11-01 17:24 414,208 ----a-w C:\Windows\System32\msscp.dll
2007-11-01 17:24 4,247,552 ----a-w C:\Windows\System32\GameUXLegacyGDFs.dll
2007-11-01 17:24 292,352 ----a-w C:\Windows\System32\psisdecd.dll
2007-11-01 17:24 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll
2007-11-01 17:24 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2007-11-01 17:24 1,686,528 ----a-w C:\Windows\System32\gameux.dll
2007-11-01 17:23 8,704 ----a-w C:\Windows\System32\hccoin.dll
2007-11-01 17:23 38,912 ----a-w C:\Windows\system32\drivers\hidclass.sys
2007-11-01 17:23 25,472 ----a-w C:\Windows\system32\drivers\hidparse.sys
2007-11-01 17:23 13,312 ------w C:\Windows\system32\drivers\sffdisk.sys
2007-11-01 17:23 12,800 ------w C:\Windows\system32\drivers\sffp_sd.sys
2007-11-01 17:23 12,800 ------w C:\Windows\system32\drivers\sffp_mmc.sys
2007-11-01 17:23 12,288 ----a-w C:\Windows\system32\drivers\hidusb.sys
2007-11-01 17:22 --------- d-----w C:\Program Files\Windows Defender
2007-11-01 17:20 74,752 ----a-w C:\Windows\system32\drivers\rasl2tp.sys
2007-11-01 17:20 60,928 ----a-w C:\Windows\system32\drivers\raspptp.sys
2007-11-01 17:19 61,952 ----a-w C:\Windows\system32\drivers\ohci1394.sys
2007-11-01 17:19 53,760 ----a-w C:\Windows\system32\drivers\hdaudbus.sys
2007-11-01 17:19 51,896 ----a-w C:\Windows\system32\drivers\partmgr.sys
2007-11-01 17:19 160,872 ----a-w C:\Windows\System32\halmacpi.dll
2007-11-01 17:19 134,760 ----a-w C:\Windows\System32\halacpi.dll
2007-11-01 17:19 12,800 ----a-w C:\Windows\system32\drivers\fs_rec.sys
2007-11-01 17:18 98,304 ----a-w C:\Windows\System32\mssitlb.dll
2007-11-01 17:18 65,536 ----a-w C:\Windows\System32\propdefs.dll
2007-11-01 17:18 58,472 ------w C:\Windows\system32\drivers\ULIAGPKX.SYS
2007-11-01 17:18 54,888 ------w C:\Windows\system32\drivers\AMDAGP.SYS
2007-11-01 17:18 54,376 ------w C:\Windows\system32\drivers\VIAAGP.SYS
2007-11-01 17:18 53,864 ------w C:\Windows\system32\drivers\AGP440.sys
2007-11-01 17:18 53,352 ------w C:\Windows\system32\drivers\SISAGP.SYS
2007-11-01 17:18 52,224 ----a-w C:\Windows\System32\msstrc.dll
2007-11-01 17:18 51,200 ----a-w C:\Windows\System32\msscntrs.dll
2007-11-01 17:18 50,792 ----a-w C:\Windows\system32\drivers\termdd.sys
2007-11-01 17:18 50,280 ----a-w C:\Windows\system32\drivers\volmgr.sys
2007-11-01 17:18 47,208 ------w C:\Windows\system32\drivers\isapnp.sys
2007-11-01 17:18 331,264 ----a-w C:\Windows\System32\mssph.dll
2007-11-01 17:18 32,256 ----a-w C:\Windows\System32\mssprxy.dll
2007-11-01 17:18 28,776 ----a-w C:\Windows\system32\drivers\mssmbios.sys
2007-11-01 17:18 242,688 ------w C:\Windows\system32\drivers\rdpdr.sys
2007-11-01 17:18 23,552 ----a-w C:\Windows\System32\msscb.dll
2007-11-01 17:18 22,632 ----a-w C:\Windows\System32\streamci.dll
2007-11-01 17:18 167,424 ----a-w C:\Windows\System32\ActionQueue.dll
2007-11-01 17:18 158,720 ----a-w C:\Windows\System32\mssphtb.dll
2007-11-01 17:18 140,392 ----a-w C:\Windows\system32\drivers\pci.sys
2007-11-01 17:18 13,928 ----a-w C:\Windows\system32\drivers\msisadrv.sys
2007-11-01 17:18 12,776 ----a-w C:\Windows\system32\drivers\swenum.sys
2007-11-01 17:18 106,600 ------w C:\Windows\system32\drivers\NV_AGP.SYS
2007-11-01 17:18 1,695,232 ----a-w C:\Windows\System32\mssvp.dll
2007-11-01 17:18 1,499,648 ----a-w C:\Windows\System32\tquery.dll
2007-11-01 17:18 1,397,248 ----a-w C:\Windows\System32\mssrch.dll
2007-10-22 02:39 267,272 ----a-w C:\Windows\System32\xactengine2_10.dll
2007-10-22 02:37 17,928 ----a-w C:\Windows\System32\X3DAudio1_2.dll
2007-10-18 10:31 51,224 ----a-w C:\Windows\System32\sirenacm.dll
2007-10-12 14:14 3,734,536 ----a-w C:\Windows\System32\d3dx9_36.dll
2007-10-12 14:14 1,374,232 ----a-w C:\Windows\System32\D3DCompiler_36.dll
2007-10-02 08:56 444,776 ----a-w C:\Windows\System32\d3dx10_36.dll
2007-08-29 05:55 40,960 ----a-w C:\Windows\System32\OEM02Pin.dll
2007-08-29 05:55 24,576 ----a-w C:\Windows\System32\OEM02Srv.exe
2007-08-29 05:54 90,112 ----a-w C:\Windows\CtDrvIns.exe
2007-08-29 05:54 36,864 ----a-w C:\Windows\OEM02Mon.exe
2007-08-29 05:54 28,672 ----a-w C:\Windows\OEM02Cfg.exe
2006-11-02 12:50 174 --sha-w C:\Program Files\desktop.ini
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34]
"DAEMON Tools Pro Agent"="C:\Program Files\DAEMON Tools Pro\DTProAgent.exe" [2007-09-13 11:27]
"Spyware Doctor"="C:\Program Files\Spyware Doctor\swdoctor.exe" [2007-04-16 11:47]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-01-10 15:14]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-11-01 18:22]
"ECenter"="C:\Dell\E-Center\EULALauncher.exe" [2007-05-25 07:03]
"Apoint"="C:\Program Files\DellTPad\Apoint.exe" [2007-04-18 04:31]
"OEM02Mon.exe"="C:\Windows\OEM02Mon.exe" [2007-08-29 06:54]
"SunJavaUpdateSched"="c:\Program Files\Java\jre1.6.0\bin\jusched.exe" [2007-11-01 10:45]
"SigmatelSysTrayApp"="sttray.exe" [2007-03-06 21:37 C:\Windows\sttray.exe]
"DELL Webcam Manager"="C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe" [2007-07-27 17:43]
"Broadcom Wireless Manager UI"="C:\Windows\system32\WLTRAY.exe" [2007-03-21 20:33]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 12:37]
"RoxWatchTray"="C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-11-05 12:22]
"PCMService"="C:\Program Files\Dell\MediaDirect\PCMService.exe" [2007-04-16 17:10]
"MskAgentexe"="C:\Program Files\McAfee\MSK\MskAgent.exe" [2007-01-17 18:30]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-11-01 11:11]
"spywarefighterguard"="C:\Program Files\SPYWAREfighter\spftray.exe" [2007-06-08 11:52]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Spyware Doctor"="C:\Program Files\Spyware Doctor\swdoctor.exe" [2007-04-16 11:47]
C:\Users\Martin Thorstein\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
hamachi.lnk - C:\Program Files\Hamachi\hamachi.exe [2007-11-08 19:07:00]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2007-11-01 10:47:03]
QuickSet.lnk - C:\Windows\Installer\{7F0C4457-8E64-491B-8D7B-991504365D1E}\NewShortcut2_53A01CC614B04512A2E710D39BF83DC4.exe [2007-11-01 10:56:41]
[hklm\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2006-10-19 09:12 258048 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
R0 ahcix86s;ahcix86s;C:\Windows\system32\drivers\ahcix86s.sys
R0 AtiPcie;ATI PCI Express (3GIO) Filter;C:\Windows\system32\DRIVERS\AtiPcie.sys
R2 ATIWebPAM;ATI WebPAM;"C:\Program Files\ATI\WebPAM\jetty\extra\win32\Wrapper.exe" -s wrapper.conf
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
R2 XAudio;XAudio;C:\Windows\system32\DRIVERS\xaudio.sys
R3 atikmdag;atikmdag;C:\Windows\system32\DRIVERS\atikmdag.sys
R3 OEM02Dev;Creative Camera OEM002 Driver;C:\Windows\system32\DRIVERS\OEM02Dev.sys
R3 OEM02Vfx;Creative Camera OEM002 Video VFX Driver;C:\Windows\system32\DRIVERS\OEM02Vfx.sys
S3 R300;R300;C:\Windows\system32\DRIVERS\atikmdag.sys
S3 viaagp;VIA AGP Bus Filter;C:\Windows\system32\drivers\viaagp.sys
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalSystemNetworkRestricted hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc EMDMgmt TabletInputService wlansvc WPDBusEnum
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{37600e32-8f72-11dc-b512-001c23a4250c}]
\shell\AutoRun\command - F:\AutoRun.exe
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2007-11-01 10:14:05 C:\Windows\Tasks\McDefragTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe'
"2007-11-01 10:14:05 C:\Windows\Tasks\McQcTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe
.
**************************************************************************
catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2007-11-21 20:46:45
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-21 20:48:05
.
--- E O F ---