Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 6:30:39 PM, on 12/27/2007 Platform: Windows 2000 SP4 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Boot mode: Normal
Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\WINDOWS\system32\regsvc.exe C:\WINDOWS\system32\MSTask.exe C:\WINDOWS\System32\WBEM\WinMgmt.exe C:\WINDOWS\system32\mspmspsv.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\rundll32.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas .exe C:\Documents and Settings\Administrator\Desktop\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1 F3 - REG:win.ini: load=C:\WINDOWS\system32\pmkhf.exe O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx O4 - HKLM\..\Run: [ATIPTA] C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATIPTAXX.EXE O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon O4 - HKLM\..\Run: [CloneCDTray] "d:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas .exe" /minimized O4 - HKLM\..\RunServices: [Microsoft Updates] svehost.exe O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033 O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user') O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm O8 - Extra context menu item: &Search - http://kl.bar.need2find.com/KL/menusearch.html?p=KLO8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O15 - Trusted Zone: maps.google.ca O15 - Trusted Zone: www.google.caO16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www2.snapfish.com/SnapfishActivia.cabO16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.com/s/v/25.25/uploader2.cabO16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{7D5391BA-3020-443D-B265-10C0C495A9D0}: Domain = va.shawcable.net O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINDOWS\System32\dmadmin.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
-- End of file - 3971 bytes
********************************* ROOTCHK-(5-12-07)-LOG, by ejvindh Thu 12/27/2007 6:14:41.35
Driver npf (visible) is present. Run COMBOFIX by sUBs.
********************************* ROOTCHK-LOG-end
catchme 0.3.1319 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.netRootkit scan 2007-12-27 06:14:43 Windows 5.0.2195 Service Pack 4 scanning hidden processes ...
scanning hidden services & system hive ... [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg] "s1"=dword:48dc877d "s2"=dword:afeb9a70 "h0"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4] "h0"=dword:00000000 "khjeh"=hex:d9,ca,29,bd,25,b4,b3,c3,3d,fc,08,75,1f,45,9d,2a,b2,c2,76,d8,13,.. "p0"="C:\Program Files\DAEMON Tools\" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001] "a0"=hex:20,01,00,00,12,62,85,9e,2b,bd,2d,f5,a6,7e,36,11,52,46,da,d7,a4,.. "khjeh"=hex:51,55,65,9c,ea,d6,37,b1,05,0a,72,a5,5d,ea,be,d5,8f,c8,30,f8,5a,.. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40] "khjeh"=hex:54,3c,9e,74,24,1b,da,07,08,40,a4,d7,f1,2e,0e,3c,c9,39,f8,12,59,.. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4] "h0"=dword:00000000 "khjeh"=hex:d9,ca,29,bd,25,b4,b3,c3,3d,fc,08,75,1f,45,9d,2a,b2,c2,76,d8,13,.. "p0"="C:\Program Files\DAEMON Tools\" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001] "a0"=hex:20,01,00,00,12,62,85,9e,2b,bd,2d,f5,a6,7e,36,11,52,46,da,d7,a4,.. "khjeh"=hex:51,55,65,9c,ea,d6,37,b1,05,0a,72,a5,5d,ea,be,d5,8f,c8,30,f8,5a,.. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40] "khjeh"=hex:54,3c,9e,74,24,1b,da,07,08,40,a4,d7,f1,2e,0e,3c,c9,39,f8,12,59,..
scanning hidden registry entries ...
scanning hidden files ...
hidden processes: 0 hidden services: 0 hidden files: 0
ComboFix 07-12-21.4 - Administrator 12/27/2007 6:16:56.1 - NTFSx86 MINIMAL Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe .
((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) .
C:\Documents and Settings\Administrator\My Documents\MCROSO~1.NET C:\Documents and Settings\Administrator\My Documents\MCROSO~1.NET\M?crosoft.NET\ C:\Documents and Settings\Administrator\My Documents\MCROSO~1.NET\netdde .exe C:\Documents and Settings\Administrator\My Documents\STEM32~1 C:\Documents and Settings\Administrator\My Documents\STEM32~1\d?xplore.exe C:\Documents and Settings\Administrator\Start Menu\Programs\Outerinfo C:\Documents and Settings\Administrator\Start Menu\Programs\Outerinfo\Terms.lnk C:\Documents and Settings\Administrator\Start Menu\Programs\Outerinfo\Uninstall.lnk C:\Program Files\Common Files\{0C48F~1 C:\Program Files\Common Files\{3C48F~1 C:\Program Files\Common Files\{3C48F~1\toolbardll.lzma C:\Program Files\Common Files\dobe~1 C:\Program Files\Common Files\Yazzle1281OinAdmin.exe C:\Program Files\Common Files\Yazzle1281OinUninstaller.exe C:\Program Files\network monitor C:\Program Files\outerinfo C:\Program Files\outerinfo\FF\chrome.manifest C:\Program Files\outerinfo\FF\components\FF.dll C:\Program Files\outerinfo\FF\components\OuterinfoAds.xpt C:\Program Files\outerinfo\FF\install.rdf C:\Program Files\outerinfo\Terms.rtf C:\Program Files\security tools C:\Program Files\security tools\ot.ico C:\Program Files\security tools\ts.ico C:\Temp\1cb C:\Temp\1cb\syscheck.log C:\WINDOWS\start.exe C:\WINDOWS\system32\atmtd.dll C:\WINDOWS\system32\atmtd.dll._ C:\WINDOWS\system32\drivers\npf.sys C:\WINDOWS\SYSTEM32\fhkmp.ini C:\WINDOWS\SYSTEM32\fhkmp.ini2 C:\WINDOWS\system32\kernel32.exe C:\WINDOWS\system32\opnlmmn.dll C:\WINDOWS\system32\pac.txt C:\WINDOWS\system32\packet.dll C:\WINDOWS\system32\pmkhf.dll C:\WINDOWS\system32\rqrpoli.dll C:\WINDOWS\system32\unsvchosts.lzma C:\WINDOWS\system32\wpcap.dll C:\WINDOWS\TTC-4444.exe C:\WINDOWS\Z3JlZw\
. ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
. -------\LEGACY_CMDSERVICE -------\LEGACY_COM+_MESSAGES -------\LEGACY_NETDOWN -------\LEGACY_NETWORK_MONITOR -------\cmdService -------\NETDown -------\Network Monitor -------\nm -------\NPF
((((((((((((((((((((((((( Files Created from 2007-11-27 to 2007-12-27 ))))))))))))))))))))))))))))))) .
2007-12-27 06:22 . 16,384 C:\WINDOWS\SYSTEM32\Perflib_Perfdata_3fc.dat 2007-12-27 06:17 . 07-12-27 06:17 348,160 --a------ C:\WINDOWS\SYSTEM32\pmkhf.exe 2007-12-26 22:35 . 07-12-26 22:35 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Grisoft 2007-12-26 22:34 . 07-12-26 22:34 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft 2007-12-26 22:34 . 07-05-30 04:10 10,872 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\AvgAsCln.sys 2007-12-26 22:27 . 07-12-26 22:27 <DIR> d-------- C:\Program Files\CCleaner 2007-12-26 22:08 . 07-12-26 22:52 143 --a------ C:\WINDOWS\SYSTEM32\mcrh.tmp 2007-12-26 22:01 . 07-12-26 22:01 <DIR> d-------- C:\Documents and Settings\Default User\Application Data\NetMon 2007-12-26 22:00 . 07-12-26 22:00 <DIR> d-------- C:\WINDOWS\SYSTEM32\pop3 2007-12-26 22:00 . 07-12-27 06:12 <DIR> d-------- C:\WINDOWS\SYSTEM32\level2 2007-12-26 22:00 . 07-12-26 22:00 39,936 --a------ C:\WINDOWS\17PHolmes572.exe 2007-12-26 22:00 . 07-12-26 22:00 39,936 --a------ C:\WINDOWS\17PHolmes1000106.exe 2007-12-26 21:59 . 07-12-26 21:59 <DIR> d-------- C:\WINDOWS\SYSTEM32\ardCo01 2007-12-26 21:59 . 07-12-26 22:00 <DIR> d-------- C:\Temp\cEeer12 2007-12-26 21:59 . 07-12-27 06:19 <DIR> d-------- C:\Temp 2007-12-26 00:02 . 07-12-26 00:02 <DIR> d-------- C:\MySlideshow 2007-12-25 13:54 . 07-12-25 13:54 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Anvsoft 2007-12-25 13:17 . 07-12-25 13:17 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\LightScribe 2007-12-25 13:07 . 07-12-25 13:07 <DIR> d-------- C:\Program Files\LightScribeTemplateLabeler 2007-12-25 13:01 . 07-12-25 13:02 <DIR> d-------- C:\Program Files\Common Files\LightScribe 2007-12-25 12:53 . 07-12-25 12:53 <DIR> d-------- C:\PhotoDVD 2007-12-02 08:24 . 07-12-02 08:24 <DIR> d-------- C:\Program Files\PowerISO 2007-11-30 17:25 . 07-11-30 17:26 24 ---hs---- C:\WINDOWS\S86B9AD64.tmp 2007-11-28 23:37 . 07-11-28 23:37 8,464 --a------ C:\WINDOWS\SYSTEM32\sporder.dll
. (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2007-12-27 14:12 --------- d-----w C:\Program Files\QuickTime 2007-12-27 14:12 --------- d-----w C:\Program Files\PLUS! 2007-12-27 14:12 --------- d-----w C:\Program Files\MSN Messenger 2007-12-27 14:12 --------- d-----w C:\Program Files\MessengerPlus! 3 2007-12-27 14:12 --------- d-----w C:\Program Files\DAEMON Tools 2007-12-27 05:13 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP 2007-12-23 22:00 --------- d-----w C:\Documents and Settings\Administrator\Application Data\LimeWire 2007-11-27 02:03 --------- d-----w C:\Program Files\snow2 2007-11-26 06:14 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Nero 2007-11-26 06:13 --------- d-----w C:\Program Files\Common Files\Nero 2007-11-23 22:21 --------- d--h--w C:\Program Files\InstallShield Installation Information 2007-11-17 18:41 --------- d-----w C:\Program Files\Common Files\Adobe 2007-11-17 06:12 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Snapfish 2007-11-15 01:07 --------- d-----w C:\Program Files\LimeWire 2007-11-14 21:58 --------- d-----w C:\Documents and Settings\Administrator\Application Data\SHARP 2006-12-24 00:18 305 ---h--w C:\Program Files\desktop.ini 2006-12-24 00:17 21,952 ---h--w C:\Program Files\folder.htt 2000-07-26 20:00 32,528 ----a-w C:\WINDOWS\inf\wbfirdma.sys .
((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{37D2AC3B-2C95-4184-98DE-BACE4164EBDA}] C:\Program Files\Online Services\nipyxabe4444.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3C5E6017-5B43-4404-679E-3EAC64CE6D87}] C:\Program Files\PLUS!\rybi.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{95F7AF11-46FE-7C59-8B2C-3AE67682029B}] C:\WINDOWS\system32\radpi.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E72F6699-4BD2-4410-94B8-640417DB3CB9}] C:\Program Files\Online Services\nipyxabe83122.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SlowFile Icon Overlay] @={7D688A77-C613-11D0-999B-00C04FD655E1}
[HKEY_CLASSES_ROOT\CLSID\{7D688A77-C613-11D0-999B-00C04FD655E1}] 06-07-13 12:39 2362640 --a------ C:\WINDOWS\system32\SHELL32.DLL
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MessengerPlus3"="C:\Program Files\MessengerPlus! 3\MsgPlus.exe" [] "DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [] "msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ATIPTA"="C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATIPTAXX.EXE" [] "Synchronization Manager"="mobsync.exe" [03-06-19 19:05 C:\WINDOWS\SYSTEM32\mobsync.exe] "CloneCDTray"="d:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" [06-09-28 11:21 ] "!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas .exe" [07-12-27 06:17 ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices] "Microsoft Updates"="svehost.exe" []
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "^SetupICWDesktop"="C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe" [03-06-19 11:05 ]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader] 05-06-06 23:46 57344 --a------ D:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher] 07-10-10 19:51 39792 --a------ D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aown] C:\DOCUME~1\ADMINI~1\MYDOCU~1\MCROSO~1.NET\netdde.exe -vt yazb [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ClamWin] D:\Program Files\ClamWin\bin\ClamTray.exe --logon [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cpoylz] C:\Documents and Settings\Administrator\My Documents\??stem32\d?xplore.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IpWins] C:\Program Files\ipwins\ipwins.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] 06-10-30 09:36 256576 --a------ C:\Program Files\iTunes\iTunesHelper.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Load] 07-12-27 06:17 348160 --a------ C:\WINDOWS\system32\pmkhf.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Updates] svehost.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr] C:\Program Files\MSN Messenger\MsnMsgr.Exe /background [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ntdll.dll] C:\WINDOWS\mrofinu1000106.exe 61A847B5BBF72813329B385772FF01F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310 [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] C:\Program Files\QuickTime\qttask.exe -atboottime [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1] C:\WINDOWS\mrofinu572.exe 61A847B5BBF728173599284503996897C881250221C8670836AC4FA7C8833201749139 [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Services] C:\WINDOWS\system32\hpcelrsb.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Smapp] 01-10-12 15:45 69632 --a------ C:\Program Files\Analog Devices\SoundMAX\Smtray.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spooler SubSystem App] C:\WINDOWS\system32\spooIsv.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] 06-11-09 15:07 49263 --a------ C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Synchronization Manager] mobsync.exe /logon [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SystemTray] SysTray.Exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TELUS_eCare_Lite_McciTrayApp] 07-01-26 10:59 1007720 --a------ C:\Program Files\TELUS_eCare_Lite\eCareTrayApp.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{0C48F6A2-0361-1033-0825-000310150001}] C:\Program Files\Common Files\{0C48F6A2-0361-1033-0825-000310150001}\Update.exe mc-110-12-0000144
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "RpcPatch"=2 (0x2) "iPod Service"=3 (0x3) "COM+ Messages"=2 (0x2) "Portable Media Serial Number"=2 (0x2) "SBHookSvc"=3 (0x3) "NETDown"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "{0C48F6A2-0361-1033-0825-000310150001}"="C:\Program 11Files\Common Files\{0C48F6A2-0361-1033-0825-000310150001}\Update.exe" mc-110-12-0000144
R1 sdcplh;sdcplh;C:\WINDOWS\system32\drivers\sdcplh.sys [05-11-03 10:50 ] S3 f3185a19-d348-43c7-98b0-b45e3fdba6e0;f3185a19-d348-43c7-98b0-b45e3fdba6e0;D:\Player\cds300.dll [] S3 hpddndnt;HP DeskDirect Ethernet Adapter NT Driver;C:\WINDOWS\system32\DRIVERS\hpddnd4.sys [99-11-05 13:37 ] S4 Portable Media Serial Number;ntv;C:\WINDOWS\ntv.exe []
*Newly Created Service* - IPNAT *Newly Created Service* - RASAUTO *Newly Created Service* - SHAREDACCESS
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}] "C:\Program Files\Common Files\LightScribe\LSRunOnce.exe" . Contents of the 'Scheduled Tasks' folder "2007-12-06 03:00:00 C:\WINDOWS\Tasks\Tune-up Application Start.job" . **************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.netRootkit scan 2007-12-27 06:23:38 Windows 5.0.2195 Service Pack 4 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully hidden files: 0
************************************************************************** . Completion time: 2007-12-27 6:25:00 - machine was rebooted
|