Hello QuikDraw,
Here are the logs for SmitFraud,
HijackThis and ComboFix..
SmitFraudFix v2.274
Scan done at 12:00:12.83, 23/12/2007
Run from C:\Users\BPL\Desktop\SmitfraudFix
OS: Microsoft Windows [Version 6.0.6000] - Windows_NT
The filesystem type is NTFS
Fix run in safe mode
»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before
SmitFraudFix
!!!Attention, following keys are not inevitably
infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» Killing process
»»»»»»»»»»»»»»»»»»»»»»»» hosts
127.0.0.1 localhost
::1 localhost
»»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix
S!Ri's WS2Fix: LSP not Found.
»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix
GenericRenosFix by S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files
»»»»»»»»»»»»»»»»»»»»»»»» IEDFix
IEDFix.exe by S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» DNS
»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files
»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning
Registry Cleaning done.
»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After
SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» End
Logfile for
HijackThis......
Logfile of Trend Micro
HijackThis v2.0.2
Scan saved at 12:27:19, on 23/12/2007
Platform: Windows Vista (WinNT 6.00.1904)
MSIE:
Internet Explorer v7.00 (7.00.6000.16575)
Boot mode: Safe mode
Running processes:
C:\Windows\system32\userinit.exe
C:\Windows\Explorer.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO:
RealPlayer Download and Record Plugin for
Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO:
BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.5.19.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\Scriptcl.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SunJavaUpdateSched] "c:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [ECenter] c:\dell\E-Center\EULALauncher.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [AVFX Engine] C:\Program Files\Creative\Creative Live! Cam\VideoFX\StartFX.exe
O4 - HKLM\..\Run: [V0220Mon.exe] C:\Windows\V0220Mon.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [diagnostics] "C:\Program Files\Thomson\ST330\diagnostics\diagnostics.exe" /icon -l:en
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &D&ownload &with
BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with
BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with
BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Roxio\Roxio MyDVD DE\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: ServiceLayer -
Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SpeedTouch 330 Manager (st330service) -
THOMSON Telecom Belgium - C:\Program Files/Thomson/ST330/service/st330service.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
--
End of file - 7380 bytes
Logfile for ComboFix...
ComboFix 07-12-21.4 - akkumar 23/12/2007 12:13:05.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.1366 [GMT 0:00]
Running from: C:\Users\BPL\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\webmediaplayer
C:\Program Files\webmediaplayer\Privacy Policy.url
C:\Program Files\webmediaplayer\resources\languages_v2.xml
C:\Program Files\webmediaplayer\resources\webmedias
C:\Program Files\webmediaplayer\skins\classic.skn
C:\Program Files\webmediaplayer\sqlite3.dll
C:\Program Files\webmediaplayer\Terms and conditions.url
C:\Program Files\webmediaplayer\uninst.exe
C:\Program Files\webmediaplayer\WebMediaPlayer.exe
C:\Program Files\webmediaplayer\Website.url
C:\ProgramData\Microsoft\Windows\Start Menu\Programs.\WebMediaPlayer
C:\ProgramData\Microsoft\Windows\Start Menu\Programs.\WebMediaPlayer\Privacy Policy.lnk
C:\ProgramData\Microsoft\Windows\Start Menu\Programs.\WebMediaPlayer\Terms and conditions.lnk
C:\ProgramData\Microsoft\Windows\Start Menu\Programs.\WebMediaPlayer\WebMediaPlayer.lnk
C:\ProgramData\Microsoft\Windows\Start Menu\Programs.\WebMediaPlayer\Website.lnk
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WebMediaPlayer\Privacy Policy.lnk
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WebMediaPlayer\Terms and conditions.lnk
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WebMediaPlayer\WebMediaPlayer.lnk
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WebMediaPlayer\Website.lnk
C:\Users\BPL\AppData\Local\jkzhape.dat
C:\Users\BPL\AppData\Local\jkzhape.exe
C:\Users\BPL\AppData\Local\jkzhape_nav.dat
C:\Users\BPL\AppData\Local\jkzhape_navps.dat
C:\Users\Public\Desktop\webmediaplayer.lnk
C:\Windows\system32\nvs2.inf
.
((((((((((((((((((((((((( Files Created from 2007-11-23 to 2007-12-23 )))))))))))))))))))))))))))))))
.
2007-12-23 10:35 . 23/12/2007 10:35 <DIR> d-------- C:\Program Files\Trend Micro
2007-12-22 12:38 . 23/12/2007 12:00 3,730 --a------ C:\Windows\System32\tmp.reg
2007-12-18 20:31 . 18/12/2007 20:31 <DIR> dr-h----- C:\Users\akkumar\AppData\Roaming\SecuROM
2007-12-18 20:31 . 18/12/2007 20:31 107,888 --a------ C:\Windows\System32\CmdLineExt.dll
2007-12-15 11:54 . 15/12/2007 11:54 <DIR> dr-h----- C:\Users\BPL\AppData\Roaming\SecuROM
2007-12-12 22:49 . 12/12/2007 22:49 1,327,104 --a------ C:\Windows\System32\quartz.dll
2007-12-12 22:49 . 12/12/2007 22:49 223,232 --a------ C:\Windows\System32\WMASF.DLL
2007-12-12 22:49 . 12/12/2007 22:49 9,728 --a------ C:\Windows\System32\LAPRXY.DLL
2007-12-12 22:49 . 12/12/2007 22:49 2,048 --a------ C:\Windows\System32\asferror.dll
2007-12-12 22:39 . 12/12/2007 22:39 130,048 --a------ C:\Windows\System32\drivers\srv2.sys
2007-12-12 22:39 . 12/12/2007 22:39 101,888 --a------ C:\Windows\System32\drivers\mrxsmb.sys
2007-12-12 22:39 . 12/12/2007 22:39 84,992 --a------ C:\Windows\System32\drivers\srvnet.sys
2007-12-12 22:39 . 12/12/2007 22:39 58,368 --a------ C:\Windows\System32\drivers\mrxsmb20.sys
2007-12-12 22:39 . 12/12/2007 22:39 0 --a------ C:\Windows\ativpsrm.bin
2007-12-12 22:36 . 12/12/2007 22:36 3,504,824 --a------ C:\Windows\System32\ntkrnlpa.exe
2007-12-12 22:36 . 12/12/2007 22:36 3,470,520 --a------ C:\Windows\System32\ntoskrnl.exe
2007-12-12 22:35 . 12/12/2007 22:35 2,048 --a------ C:\Windows\System32\tzres.dll
2007-11-24 23:57 . 24/11/2007 23:57 <DIR> d-------- C:\Program Files\Common Files\xing shared
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-22 12:37 --------- d-----w C:\Program Files\Common Files\NSV
2007-12-16 13:12 --------- d-----w C:\Users\BPL\AppData\Roaming\SopCast
2007-12-12 22:50 --------- d-----w C:\ProgramData\Microsoft Help
2007-12-12 22:48 56,320 ----a-w C:\Windows\System32\iesetup.dll
2007-12-12 22:48 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2007-12-12 22:48 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2007-12-09 23:09 --------- d-----w C:\Users\BPL\AppData\Roaming\Winamp
2007-11-24 23:57 --------- d-----w C:\Program Files\Common Files\Real
2007-11-23 21:30 --------- d-----w C:\Program Files\Thomson
2007-11-17 18:51 1,244,672 ----a-w C:\Windows\System32\mcmde.dll
2007-11-17 18:26 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-11-15 08:27 704,000 ----a-w C:\Windows\System32\PhotoScreensaver.scr
2007-11-15 08:27 67,584 ----a-w C:\Windows\System32\wlanhlp.dll
2007-11-15 08:27 542,720 ----a-w C:\Windows\System32\sysmain.dll
2007-11-15 08:27 502,784 ----a-w C:\Windows\System32\wlansvc.dll
2007-11-15 08:27 47,104 ----a-w C:\Windows\System32\wlanapi.dll
2007-11-15 08:27 297,984 ----a-w C:\Windows\System32\wlansec.dll
2007-11-15 08:27 290,816 ----a-w C:\Windows\System32\wlanmsm.dll
2007-11-15 08:27 258,232 ----a-w C:\Windows\system32\drivers\acpi.sys
2007-11-15 08:27 24,064 ----a-w C:\Windows\System32\wtsapi32.dll
2007-11-15 08:27 2,923,520 ----a-w C:\Windows\explorer.exe
2007-11-15 08:27 2,027,008 ----a-w C:\Windows\System32\win32k.sys
2007-11-15 08:24 8,704 ----a-w C:\Windows\System32\hcrstco.dll
2007-11-15 08:24 8,704 ----a-w C:\Windows\System32\hccoin.dll
2007-11-15 08:24 73,216 ----a-w C:\Windows\system32\drivers\usbccgp.sys
2007-11-15 08:24 38,400 ----a-w C:\Windows\system32\drivers\usbehci.sys
2007-11-15 08:24 224,768 ----a-w C:\Windows\system32\drivers\usbport.sys
2007-11-15 08:24 192,000 ----a-w C:\Windows\system32\drivers\usbhub.sys
2007-11-15 08:24 19,456 ----a-w C:\Windows\system32\drivers\usbohci.sys
2007-11-15 08:23 --------- d-----w C:\Program Files\Windows Mail
2007-11-14 20:56 --------- d-----w C:\Program Files\Electronic Arts
2007-10-28 12:37 --------- d-----w C:\Users\akkumar\AppData\Roaming\SopCast
2007-10-28 12:36 --------- d-----w C:\Program Files\SopCast
2007-10-11 06:45 8,147,968 ----a-w C:\Windows\System32\wmploc.DLL
2007-10-11 06:45 7,680 ----a-w C:\Windows\System32\spwmp.dll
2007-10-11 06:45 4,096 ----a-w C:\Windows\System32\dxmasf.dll
2007-10-11 06:45 356,864 ----a-w C:\Windows\System32\MediaMetadataHandler.dll
2007-10-11 06:43 84,480 ----a-w C:\Windows\System32\INETRES.dll
2007-10-11 06:43 788,992 ----a-w C:\Windows\System32\rpcrt4.dll
2007-10-11 06:43 737,792 ----a-w C:\Windows\System32\inetcomm.dll
2007-09-29 03:03 9,850,880 ----a-w C:\Windows\System32\atioglxx.dll
2007-09-29 03:02 43,520 ----a-w C:\Windows\System32\ati2edxx.dll
2007-09-29 03:02 356,352 ----a-w C:\Windows\System32\ATIDEMGX.dll
2007-09-29 03:02 266,240 ----a-w C:\Windows\System32\atipdlxx.dll
2007-09-29 03:02 245,760 ----a-w C:\Windows\System32\Ati2evxx.dll
2007-09-29 03:02 237,568 ----a-w C:\Windows\System32\Oemdspif.dll
2007-09-29 03:02 159,744 ----a-w C:\Windows\System32\atitmmxx.dll
2007-09-29 03:01 610,304 ----a-w C:\Windows\System32\Ati2evxx.exe
2007-09-29 02:50 3,071,488 ----a-w C:\Windows\System32\atiumdag.dll
2007-09-29 02:37 3,887,104 ----a-w C:\Windows\System32\atiumdva.dll
2007-09-29 02:27 48,128 ----a-w C:\Windows\System32\amdpcom32.dll
2007-08-31 09:53 174 --sha-w C:\Program Files\desktop.ini
2007-04-23 21:19 0 ----a-w C:\Users\BPL\AppData\Roaming\wklnhst.dat
2007-05-23 21:34 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2007-05-23 21:34 32,768 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2007-05-23 21:34 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [02/11/2006 12:35]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [27/03/2007 14:22]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [28/05/2007 09:29]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [23/05/2007 18:19]
"SunJavaUpdateSched"="c:\Program Files\Java\jre1.6.0\bin\jusched.exe" [17/04/2007 01:04]
"SigmatelSysTrayApp"="sttray.exe" [08/02/2007 05:16 C:\Windows\sttray.exe]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [03/10/2006 10:37]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [17/04/2007 01:16]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [17/11/2006 21:13]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [03/10/2006 10:35]
"RoxWatchTray"="C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [05/11/2006 10:22]
"RoxioDragToDisc"="C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe" [17/08/2006 08:00]
"ShStatEXE"="C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.exe" [22/02/2007 19:50]
"McAfeeUpdaterUI"="C:\Program Files\McAfee\Common Framework\UdaterUI.exe" [19/12/2006 10:27]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [24/08/2007 07:00]
"AVFX Engine"="C:\Program Files\Creative\Creative Live! Cam\VideoFX\StartFX.exe" [09/06/2006 00:11]
"V0220Mon.exe"="C:\Windows\V0220Mon.exe" [28/06/2006 17:01]
"PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [18/06/2007 14:10]
"diagnostics"="C:\Program Files\Thomson\ST330\diagnostics\diagnostics.exe" [23/11/2007 21:30]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [24/11/2007 23:56]
"MSConfig"="C:\Windows\system32\msconfig.exe" [02/11/2006 09:45]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [19/06/2007 09:17]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders credssp.dll
R1 DLARTL_M;DLARTL_M;C:\Windows\system32\Drivers\DLARTL_M.SYS [11/08/2006 09:35]
R3 atikmdag;atikmdag;C:\Windows\system32\DRIVERS\atikmdag.sys [29/09/2007 03:13]
R3 ST330;ST330;C:\Windows\system32\drivers\st330.sys [23/05/2007 18:06]
R3 STBUS;STBUS;C:\Windows\system32\drivers\stbus.sys [23/05/2007 18:06]
R3 stppp;Speedtouch PPP Adapter Adapter;C:\Windows\system32\DRIVERS\stppp.sys [23/05/2007 18:06]
S3 R300;R300;C:\Windows\system32\DRIVERS\atikmdag.sys [29/09/2007 03:13]
S3 V0220Dev;Live! Cam Video IM;C:\Windows\system32\DRIVERS\V0220Dev.sys [29/06/2006 05:58]
S3 V0220Vfx;V0220VFX;C:\Windows\system32\DRIVERS\V0220Vfx.sys [08/06/2006 08:00]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalSystemNetworkRestricted REG_MULTI_SZ hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc EMDMgmt TabletInputService wlansvc WPDBusEnum
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder
"2007-12-23 12:15:27 C:\Windows\Tasks\User_Feed_Synchronization-{1B49C41A-5BB8-40F5-9EBE-A6DA0E3E073D}.job"
- C:\Windows\system32\msfeedssync.exe
"2007-12-23 12:15:27 C:\Windows\Tasks\User_Feed_Synchronization-{F48C7CFB-64FB-4593-9A37-58AAC2CDB372}.job"
- C:\Windows\system32\msfeedssync.exe
.
**************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by
Gmer,
http://www.gmer.net
Rootkit scan 2007-12-23 12:16:25
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 23/12/2007 12:17:21
.
2007-12-21 09:09:52 --- E O F ---
Many Thanks,
Dev