Thaks a lot for help
Please find the following logs
Logs from Hijak this:-
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:47:35, on 09/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\isafe.exe
C:\WINDOWS\system32\lxczcoms.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
C:\Program Files\Webroot\Washer\WasherSvc.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger .exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched .exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger .exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\VIP\Desktop\HiJackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie...
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie...
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie...
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 212.62.97.21:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 10.0.0.2;<local>
R3 - Default URLSearchHook is missing
F3 - REG:win.ini: load=C:\WINDOWS\system32\awvvt.exe
O1 - Hosts: 62.189.6.83 _sip._tls.ijkl.winnerip.com
O1 - Hosts: 62.189.6.83 _sip._ssl.ijkl.winnerip.com
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - Toolbar: Nexus Radio Toolbar - {2462d2d8-b36e-44ab-84bf-c5a9383d2429} - C:\Program Files\Nexus_Radio\tbNex1.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [4ce9994c] rundll32.exe "C:\WINDOWS\system32\tawepvpe.dll",b
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger .exe" -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: BlueSoleil.lnk = ?
O8 - Extra context menu item: &Search - ?p=ZBxdm210YYSA
O8 - Extra context menu item: &WordWeb... - res://C:\WINDOWS\system32\wweb32.dll/lookup.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - http://sifyimg.speedera.net/sify.co...
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} - http://a516.g.akamai.net/f/516/2517...
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
O16 - DPF: {512FC5A1-7DE1-43F1-BC0C-371622FCB409} (TotalScan Installer Class) - http://www.nanoscan.com/as/cabs/asc...
O16 - DPF: {8436FE12-31DB-48BF-83BF-FE682F9160B4} (NanoInstaller Class) - http://www.nanoscan.com/cabs/nanoin...
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\isafe.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: lxcz_device - - C:\WINDOWS\system32\lxczcoms.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
O23 - Service: Window Washer Engine (wwEngineSvc) - Webroot Software, Inc. - C:\Program Files\Webroot\Washer\WasherSvc.exe
--
End of file - 6613 bytes
========================================
and logs from Combofix is:-
ComboFix 08-02.05.3 - VIP 2008-02-09 17:57:52.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1033.18.149 [GMT 3:00]
Running from: C:\Documents and Settings\VIP\Desktop\ComboFix.exe
* Created a new restore point
[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetTray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Free Download Manager\FUM\fumoei.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\JustVoip.com\JustVoip\JustVoip .exe
C:\Program Files\JustVoip.com\JustVoip\JustVoip .exe
C:\Program Files\JustVoip.com\JustVoip\JustVoip .exe
C:\Program Files\JustVoip.com\JustVoip\JustVoip .exe
C:\Program Files\JustVoip.com\JustVoip\JustVoip .exe
C:\Program Files\JustVoip.com\JustVoip\JustVoip .exe
C:\Program Files\JustVoip.com\JustVoip\JustVoip .exe
C:\Program Files\JustVoip.com\JustVoip\JustVoip .exe
C:\Program Files\JustVoip.com\JustVoip\JustVoip .exe
C:\Program Files\JustVoip.com\JustVoip\JustVoip .exe
C:\Program Files\JustVoip.com\JustVoip\JustVoip.exe
C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe
C:\Program Files\Lexmark Fax Solutions\fm3032.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Webroot\Washer\wwDisp.exe
C:\Program Files\Yahoo!\Messenger\YAHOOM~1 .EXE
C:\Program Files\Yahoo!\Messenger\YAHOOM~1 .EXE
C:\Program Files\Yahoo!\Messenger\YAHOOM~1 .EXE
C:\Program Files\Yahoo!\Messenger\YAHOOM~1 .EXE
C:\Program Files\Yahoo!\Messenger\YAHOOM~1 .EXE
C:\Program Files\Yahoo!\Messenger\YAHOOM~1 .EXE
C:\Program Files\Yahoo!\Messenger\YAHOOM~1 .EXE
C:\Program Files\Yahoo!\Messenger\YAHOOM~1 .EXE
C:\Program Files\Yahoo!\Messenger\YAHOOM~1 .EXE
C:\Program Files\Yahoo!\Messenger\YAHOOM~1 .EXE
C:\Program Files\Yahoo!\Messenger\YAHOOM~1 .EXE
C:\Program Files\Yahoo!\Messenger\YAHOOM~1 .EXE
C:\Program Files\Yahoo!\Messenger\YAHOOM~1 .EXE
C:\Program Files\Yahoo!\Messenger\YAHOOM~1 .EXE
C:\Program Files\Yahoo!\Messenger\YAHOOM~1.EXE
C:\Program Files\Yahoo!\Messenger\YahooMessenger .exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger .exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger .exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger .exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger .exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger .exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger .exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger .exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger .exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger .exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger .exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger .exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\_000008_.tmp.dll
C:\WINDOWS\system32\ashloirs.ini
C:\WINDOWS\system32\awvvt.dll
C:\WINDOWS\system32\awvvt.exe
C:\WINDOWS\system32\awwjnqgu.ini
C:\WINDOWS\system32\ctfmon.exe.tmp
C:\WINDOWS\system32\cyratuad.ini
C:\WINDOWS\system32\eagfddmy.ini
C:\WINDOWS\system32\eigkjpvy.ini
C:\WINDOWS\system32\hxqaneys.ini
C:\WINDOWS\system32\lvouulek.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mlyrraqo.ini
C:\WINDOWS\system32\MRT.exe
C:\WINDOWS\system32\ojifjnxf.ini
C:\WINDOWS\system32\pajejklg.ini
C:\WINDOWS\system32\plahaxyu.ini
C:\WINDOWS\system32\pmdskdxl.ini
C:\WINDOWS\system32\qnnsxxcg.ini
C:\WINDOWS\system32\RCX10.tmp
C:\WINDOWS\system32\RCX11.tmp
C:\WINDOWS\system32\RCX12.tmp
C:\WINDOWS\system32\RCX13.tmp
C:\WINDOWS\system32\RCX15.tmp
C:\WINDOWS\system32\RCX16.tmp
C:\WINDOWS\system32\RCX35.tmp
C:\WINDOWS\system32\RCX67.tmp
C:\WINDOWS\system32\RCX85.tmp
C:\WINDOWS\system32\RCXA.tmp
C:\WINDOWS\system32\RCXB.tmp
C:\WINDOWS\system32\RCXC.tmp
C:\WINDOWS\system32\RCXD.tmp
C:\WINDOWS\system32\RCXE.tmp
C:\WINDOWS\system32\RCXF.tmp
C:\WINDOWS\system32\rirpmqgu.ini
C:\WINDOWS\system32\systocz.dll
C:\WINDOWS\system32\tvvwa.ini
C:\WINDOWS\system32\tvvwa.ini2
C:\WINDOWS\system32\update.exe
C:\WINDOWS\system32\windows
C:\WINDOWS\system32\xplytvpj.ini
C:\WINDOWS\system32\xpnlloac.ini
C:\WINDOWS\system32\xyhmqixr.ini
C:\WINDOWS\system32\yqywywso.ini
----- BITS: Possible infected sites -----
hxxp://www.download.windowsupdate.com
.
((((((((((((((((((((((((( Files Created from 2008-01-09 to 2008-02-09 )))))))))))))))))))))))))))))))
.
2008-02-09 17:41 . 2008-02-09 17:41 24,576 --a------ C:\WINDOWS\system32\VundoFixSVC.exe
2008-02-07 23:42 . 2008-02-07 23:42 154,511 --a------ C:\[u]0[/u]130007WELLFIT AUTO CARE (WHOLESALE).fbk
2008-02-07 21:47 . 2008-02-07 21:52 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Bluetooth
2008-02-07 21:42 . 2008-02-07 21:42 <DIR> d-------- C:\Program Files\IVT Corporation
2008-02-05 22:35 . 2008-02-05 22:35 90,688 --a------ C:\WINDOWS\system32\rxiqmhyx.dll
2008-02-04 18:03 . 2008-02-04 18:03 <DIR> d-------- C:\Program Files\FDRLab
2008-02-04 14:45 . 2008-02-04 14:51 13,824 ---hs---- C:\WINDOWS\system32\53341Rapid.Hacker.exe
2008-02-04 14:42 . 2008-02-04 14:40 608,448 --a------ C:\WINDOWS\system32\comctl32.ocx
2008-02-04 14:25 . 2008-02-04 14:51 872,448 ---hs---- C:\WINDOWS\system32\70554Rapid Hacker v3.0 Final - Maximum Edition.exe
2008-02-02 21:43 . 2004-08-04 01:56 388,608 --a------ C:\kmd.exe
2008-02-02 21:27 . 2008-02-02 21:25 1,593,209 --a------ C:\ComboFix.exe
2008-02-02 18:08 . 2008-02-02 18:09 <DIR> d-------- C:\WINDOWS\ERUNT
2008-02-02 16:40 . 2008-02-02 21:08 <DIR> d-------- C:\SDFix
2008-01-30 14:03 . 2006-10-20 15:21 21,056 --a------ C:\WINDOWS\system32\drivers\sskbfd.sys
2008-01-28 14:31 . 2008-01-28 14:31 24 --a------ C:\WINDOWS\cdplayer.ini
2008-01-27 18:11 . 2008-01-27 21:38 <DIR> d-------- C:\Program Files\Panda Security
2008-01-27 17:17 . 2008-01-27 17:17 163,904 --a------ C:\WINDOWS\system32\eulucumj.dll.vir
2008-01-26 22:51 . 2008-01-26 22:51 <DIR> d-------- C:\Documents and Settings\VIP\Application Data\FaxCtr
2008-01-26 22:36 . 2008-01-26 22:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\FaxCtr
2008-01-26 22:36 . 2006-04-28 12:16 339,968 --a------ C:\WINDOWS\system32\IMGMAN32.DLL
2008-01-26 22:36 . 2006-04-28 12:16 98,345 --a------ C:\WINDOWS\system32\IMHOST32.DLL
2008-01-26 22:36 . 2006-04-28 12:16 98,304 --a------ C:\WINDOWS\system32\IM31XPNG.DEL
2008-01-26 22:36 . 2006-04-28 12:16 69,632 --a------ C:\WINDOWS\system32\IM31XTIF.DEL
2008-01-26 22:36 . 2006-04-28 12:16 49,152 --a------ C:\WINDOWS\system32\IM31IMG.DIL
2008-01-26 22:36 . 2006-11-22 16:51 45,056 --a------ C:\WINDOWS\system32\LXPRMON.DLL
2008-01-26 22:36 . 2006-11-22 16:50 32,768 --a------ C:\WINDOWS\system32\LXPMONUI.DLL
2008-01-26 22:36 . 2006-11-22 17:08 12,288 --a------ C:\WINDOWS\system32\LXPMONRC.DLL
2008-01-26 22:35 . 2008-02-09 18:03 <DIR> d-------- C:\Program Files\Lexmark Fax Solutions
2008-01-26 22:34 . 2008-01-26 22:35 <DIR> d-------- C:\Program Files\Abbyy FineReader 6.0 Sprint
2008-01-26 22:32 . 2007-01-22 16:49 344,064 --a------ C:\WINDOWS\system32\lxczcoin.dll
2008-01-26 22:32 . 2006-03-27 19:19 40,960 --a------ C:\WINDOWS\system32\lxczvs.dll
2008-01-26 22:32 . 2008-02-02 11:46 274 --a------ C:\WINDOWS\Lexstat.ini
2008-01-26 22:31 . 2008-02-09 18:03 <DIR> d-------- C:\Program Files\Lexmark 1200 Series
2008-01-26 22:30 . 2007-02-09 01:44 1,851 --a------ C:\WINDOWS\system32\lxcz.loc
2008-01-26 21:41 . 2001-08-17 22:36 87,040 --a------ C:\WINDOWS\system32\wiafbdrv.dll
2008-01-26 21:41 . 2001-08-17 22:36 87,040 --a--c--- C:\WINDOWS\system32\dllcache\wiafbdrv.dll
2008-01-26 21:41 . 2007-01-23 06:30 73,728 -ra------ C:\WINDOWS\system32\lxczcfg.dll
2008-01-26 21:41 . 2007-02-08 01:58 39,899 -ra------ C:\WINDOWS\system32\rtsicis.ini
2008-01-23 12:31 . 2008-01-23 12:31 <DIR> d-------- C:\Program Files\JustVoip.com
2008-01-23 12:27 . 2008-01-23 12:27 <DIR> d-------- C:\Program Files\Intuwave Ltd
2008-01-23 12:23 . 2007-12-11 14:04 267,592 --a------ C:\Program Files\Uninstall Ask Toolbar.dll
2008-01-21 22:51 . 2008-01-21 22:51 125,509 --a------ C:\[u]0[/u]130011WELLFIT AUTO CARE (WHOLESALE).fbk
2008-01-21 22:51 . 2008-01-31 23:03 65,866 --a------ C:\[u]0[/u]330011WELLFIT AUTO CARE CENTER - JEDDAH.fbk
2008-01-21 12:32 . 2008-02-09 17:25 <DIR> d-------- C:\VundoFix Backups
2008-01-20 12:36 . 2008-01-20 12:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\RoboForm
2008-01-20 12:35 . 2008-01-20 12:35 <DIR> d-------- C:\Program Files\Siber Systems
2008-01-19 23:10 . 2008-01-29 23:17 153,288 --a------ C:\[u]0[/u]130009WELLFIT AUTO CARE (WHOLESALE).fbk
2008-01-17 16:55 . 2008-02-09 18:05 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-01-17 16:54 . 2008-02-05 13:35 <DIR> d-------- C:\Program Files\Spyware Doctor
2008-01-17 16:54 . 2008-01-17 16:54 <DIR> d-------- C:\Documents and Settings\VIP\Application Data\PC Tools
2008-01-17 16:54 . 2007-12-10 14:53 81,288 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2008-01-17 16:54 . 2007-12-10 14:53 66,952 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2008-01-17 16:54 . 2007-12-10 14:53 41,864 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-01-17 16:54 . 2007-12-10 14:53 29,576 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2008-01-17 11:44 . 2008-01-19 17:22 <DIR> d-------- C:\Program Files\Enigma Software Group
2008-01-16 20:46 . 2008-01-16 20:46 342,528 --a------ C:\WINDOWS\system32\RCX259C.tmp
2008-01-16 19:08 . 2008-02-06 23:24 154,047 --a------ C:\[u]0[/u]130006WELLFIT AUTO CARE (WHOLESALE).fbk
2008-01-16 18:33 . 2008-01-16 18:33 17,642,616 --a------ C:\WINDOWS\system32\MRT .exe
2008-01-16 14:29 . 2008-01-16 14:29 118 --a------ C:\WINDOWS\system32\MRT.INI
2008-01-16 11:27 . 2008-01-19 21:41 <DIR> d-------- C:\Program Files\Mightyfax
2008-01-16 11:27 . 2005-05-13 09:21 120,832 --a------ C:\WINDOWS\system32\APFAXCNV.DLL
2008-01-16 11:27 . 2001-07-16 02:06 12,288 --a------ C:\WINDOWS\system32\APFMON40.DLL
2008-01-16 11:27 . 2008-02-07 12:43 92 --a------ C:\WINDOWS\mfpd.ini
2008-01-16 11:20 . 2008-01-16 12:26 227 --a------ C:\WINDOWS\wininit.ini
2008-01-16 10:35 . 2008-01-16 11:24 <DIR> d-------- C:\Program Files\RegCure
2008-01-15 22:05 . 2008-01-15 22:05 59,312 --a------ C:\[u]0[/u]330005WELLFIT AUTO CARE CENTER - JEDDAH.fbk
2008-01-14 23:12 . 2008-01-24 23:33 139,894 --a------ C:\[u]0[/u]130004WELLFIT AUTO CARE (WHOLESALE).fbk
2008-01-14 23:12 . 2008-02-04 23:38 68,124 --a------ C:\[u]0[/u]330004WELLFIT AUTO CARE CENTER - JEDDAH.fbk
2008-01-13 22:18 . 2008-01-13 22:18 <DIR> d-------- C:\WINDOWS\Applian FLV Player
2008-01-13 22:18 . 2008-01-13 22:18 <DIR> d-------- C:\Program Files\FLV Player
2008-01-13 09:22 . 2008-02-09 12:23 15,360 --a------ C:\WINDOWS\system32\ctfmon .exe
2008-01-12 23:30 . 2008-01-22 22:57 131,918 --a------ C:\[u]0[/u]130002WELLFIT AUTO CARE (WHOLESALE).fbk
2008-01-12 18:27 . 2008-01-21 11:50 155,648 --a------ C:\WINDOWS\system32\NeroCheck .exe
2008-01-12 18:08 . 2008-01-12 18:08 <DIR> d-------- C:\Program Files\Radio Dum Dum
2008-01-12 11:20 . 2008-01-12 11:20 <DIR> d-------- C:\Program Files\Lavasoft
2008-01-12 11:20 . 2008-01-17 13:23 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-12 10:59 . 2008-01-12 18:08 <DIR> d-------- C:\Program Files\Registry Clean Pro
2008-01-10 13:42 . 2008-01-30 18:13 65,012 --a------ C:\[u]0[/u]330000WELLFIT AUTO CARE CENTER - JEDDAH.fbk
2008-01-10 00:00 . 2008-01-30 18:13 153,404 --a------ C:\[u]0[/u]130000WELLFIT AUTO CARE (WHOLESALE).fbk
2008-01-09 23:59 . 2008-01-29 23:15 64,854 --a------ C:\[u]0[/u]330009WELLFIT AUTO CARE CENTER - JEDDAH.fbk
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-09 15:03 --------- d-----w C:\Program Files\Microsoft IntelliType Pro
2008-02-09 15:03 --------- d-----w C:\Program Files\Microsoft IntelliPoint
2008-02-07 18:42 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-07 11:56 --------- d-----w C:\Program Files\MSN Messenger
2008-02-06 13:28 --------- d-----w C:\Documents and Settings\VIP\Application Data\LimeWire
2008-02-06 11:14 --------- d-----w C:\Program Files\LimeWire
2008-02-03 18:12 158,208 ----a-w C:\WINDOWS\pchealth\helpctr\binaries\MSConfig .exe
2008-02-02 13:48 503,296 ----a-w C:\WINDOWS\pchealth\helpctr\binaries\msconfig.exe.tmp
2008-01-30 12:02 --------- d-----w C:\Program Files\Webroot
2008-01-30 12:02 --------- d-----w C:\Documents and Settings\VIP\Application Data\Webroot
2008-01-30 12:02 --------- d-----w C:\Documents and Settings\All Users\Application Data\Webroot
2008-01-28 12:02 --------- d-----w C:\Documents and Settings\VIP\Application Data\Launchy
2008-01-23 20:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-19 14:42 --------- d-----w C:\Program Files\HTTP-Tunnel
2008-01-19 13:40 --------- d-----w C:\Program Files\Java
2008-01-19 12:18 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-01-19 12:15 --------- d-----w C:\Program Files\Quran_AR
2008-01-13 06:27 --------- d-----w C:\Program Files\Nexus Radio
2008-01-12 15:08 --------- d-----w C:\Program Files\Nexus_Radio
2008-01-10 14:21 --------- d-----w C:\Documents and Settings\VIP\Application Data\FrostWire
2008-01-05 09:27 --------- d-----w C:\Documents and Settings\VIP\Application Data\JustVoip
2007-12-12 15:12 737,280 ----a-w C:\WINDOWS\iun6002.exe
2007-12-11 10:57 --------- d-----w C:\Program Files\Morpheus
2007-12-10 08:37 --------- d-----w C:\Program Files\RKS Fax
2007-06-13 10:23 843,776 --sh--r C:\WINDOWS\system32\kssolc.exe
.
[code]
----a-w 39,792 2008-01-28 11:40:20 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl .exe
----a-w 1,450,096 2008-01-28 11:40:22 C:\Program Files\Ahead\InCD\InCD .exe
----a-w 106,496 2008-01-28 11:40:17 C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetTray .exe
----a-w 180,269 2008-02-09 14:44:37 C:\Program Files\Common Files\Real\Update_OB\realsched .exe
----a-w 847,872 2008-01-19 11:13:59 C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3 .exe
----a-w 40,960 2008-01-28 11:40:52 C:\Program Files\Free Download Manager\FUM\fumoei .exe
----a-w 132,496 2008-01-19 12:00:16 C:\Program Files\Java\jre1.6.0_02\bin\jusched .exe
----a-w 132,496 2008-01-28 11:40:15 C:\Program Files\Java\jre1.6.0_03\bin\jusched .exe
----a-w 74,672 2008-01-28 15:03:36 C:\Program Files\Lexmark 1200 Series\lxczbmgr .exe
----a-w 295,856 2008-01-28 11:40:26 C:\Program Files\Lexmark Fax Solutions\fm3032 .exe
----a-w 600,896 2008-01-28 11:40:21 C:\Program Files\Microsoft IntelliPoint\ipoint .exe
----a-w 576,320 2008-01-28 11:40:20 C:\Program Files\Microsoft IntelliType Pro\itype .exe
----a-w 2,947,584 2008-01-13 06:22:13 C:\Program Files\Nexus Radio\Nexus Radio .exe
----a-w 335,872 2008-01-19 12:00:21 C:\Program Files\Quran_AR\Quran_AR .exe
----a-w 160,592 2008-01-21 08:50:28 C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon .exe
----a-w 1,103,752 2008-01-30 11:57:30 C:\Program Files\Spyware Doctor\pctsTray .exe
----a-w 1,206,600 2008-02-06 20:11:54 C:\Program Files\Webroot\Washer\wwDisp .exe
----a-w 4,670,968 2008-01-28 11:40:42 C:\Program Files\Yahoo!\Messenger\YahooMessenger .exe
----a-w 158,208 2008-02-03 18:12:40 C:\WINDOWS\pchealth\helpctr\binaries\MSConfig .exe
----a-w 15,360 2008-02-09 09:23:51 C:\WINDOWS\system32\ctfmon .exe
----a-w 17,642,616 2008-01-16 15:33:35 C:\WINDOWS\system32\MRT .exe
----a-w 155,648 2008-01-21 08:50:20 C:\WINDOWS\system32\NeroCheck .exe
[/code]
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2462d2d8-b36e-44ab-84bf-c5a9383d2429}]
2007-12-11 20:19 1502232 --a------ C:\Program Files\Nexus_Radio\tbNex1.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B7111AEF-7F4B-42DA-80AD-9AD4BB969D8A}]
C:\WINDOWS\system32\awvvt.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c700f645-611c-4f5e-9489-c5ef81a78318}]
C:\WINDOWS\system32\ovxsbbnv.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{BA52B914-B692-46C4-B683-905236F6F655}
{E0E899AB-F487-11D5-8D29-0050BA6940E3}
{2462D2D8-B36E-44AB-84BF-C5A9383D2429}
[HKEY_CLASSES_ROOT\clsid\{2462d2d8-b36e-44ab-84bf-c5a9383d2429}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{2462D2D8-B36E-44AB-84BF-C5A9383D2429}"= C:\Program Files\Nexus_Radio\tbNex1.dll [2007-12-11 20:19 1502232]
[HKEY_CLASSES_ROOT\clsid\{2462d2d8-b36e-44ab-84bf-c5a9383d2429}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger .exe" [ ]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:56 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [ ]
"ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [ ]
"4ce9994c"="C:\WINDOWS\system32\tawepvpe.dll" [ ]
"combofix"="C:\WINDOWS\system32\kmd.exe" [2004-08-04 01:56 388608]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ajwzwgrb]
ajwzwgrb.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\khfcyxv]
khfcyxv.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Launchy.lnk]
backup=C:\WINDOWS\pss\Launchy.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^LUMIX Simple Viewer.lnk]
backup=C:\WINDOWS\pss\LUMIX Simple Viewer.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^MightyFAX Controller.lnk]
backup=C:\WINDOWS\pss\MightyFAX Controller.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WordWeb.lnk]
backup=C:\WINDOWS\pss\WordWeb.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^VIP^Start Menu^Programs^Startup^PowerReg Scheduler .exe]
backup=C:\WINDOWS\pss\PowerReg Scheduler .exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^VIP^Start Menu^Programs^Startup^PowerReg Scheduler .exe]
backup=C:\WINDOWS\pss\PowerReg Scheduler .exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^VIP^Start Menu^Programs^Startup^PowerReg Scheduler .exe]
backup=C:\WINDOWS\pss\PowerReg Scheduler .exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^VIP^Start Menu^Programs^Startup^PowerReg Scheduler .exe]
backup=C:\WINDOWS\pss\PowerReg Scheduler .exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^VIP^Start Menu^Programs^Startup^PowerReg Scheduler .exe]
backup=C:\WINDOWS\pss\PowerReg Scheduler .exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^VIP^Start Menu^Programs^Startup^PowerReg Scheduler .exe]
backup=C:\WINDOWS\pss\PowerReg Scheduler .exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^VIP^Start Menu^Programs^Startup^PowerReg Scheduler .exe]
backup=C:\WINDOWS\pss\PowerReg Scheduler .exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^VIP^Start Menu^Programs^Startup^PowerReg Scheduler .exe]
backup=C:\WINDOWS\pss\PowerReg Scheduler .exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^VIP^Start Menu^Programs^Startup^PowerReg Scheduler .exe]
backup=C:\WINDOWS\pss\PowerReg Scheduler .exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^VIP^Start Menu^Programs^Startup^PowerReg Scheduler .exe]
backup=C:\WINDOWS\pss\PowerReg Scheduler .exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^VIP^Start Menu^Programs^Startup^PowerReg Scheduler .exe]
backup=C:\WINDOWS\pss\PowerReg Scheduler .exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^VIP^Start Menu^Programs^Startup^PowerReg Scheduler .exe]
backup=C:\WINDOWS\pss\PowerReg Scheduler .exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^VIP^Start Menu^Programs^Startup^PowerReg Scheduler .exe]
backup=C:\WINDOWS\pss\PowerReg Scheduler .exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^VIP^Start Menu^Programs^Startup^PowerReg Scheduler .exe]
backup=C:\WINDOWS\pss\PowerReg Scheduler .exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^VIP^Start Menu^Programs^Startup^PowerReg Scheduler .exe]
backup=C:\WINDOWS\pss\PowerReg Scheduler .exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^VIP^Start Menu^Programs^Startup^PowerReg Scheduler .exe]
backup=C:\WINDOWS\pss\PowerReg Scheduler .exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^VIP^Start Menu^Programs^Startup^PowerReg Scheduler .exe]
backup=C:\WINDOWS\pss\PowerReg Scheduler .exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^VIP^Start Menu^Programs^Startup^PowerReg Scheduler .exe]
backup=C:\WINDOWS\pss\PowerReg Scheduler .exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^VIP^Start Menu^Programs^Startup^PowerReg Scheduler .exe]
backup=C:\WINDOWS\pss\PowerReg Scheduler .exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^VIP^Start Menu^Programs^Startup^PowerReg Scheduler .exe]
backup=C:\WINDOWS\pss\PowerReg Scheduler .exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^VIP^Start Menu^Programs^Startup^PowerReg Scheduler .exe]
backup=C:\WINDOWS\pss\PowerReg Scheduler .exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^VIP^Start Menu^Programs^Startup^PowerReg Scheduler .exe]
backup=C:\WINDOWS\pss\PowerReg Scheduler .exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^VIP^Start Menu^Programs^Startup^PowerReg Scheduler .exe]
backup=C:\WINDOWS\pss\PowerReg Scheduler .exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^VIP^Start Menu^Programs^Startup^PowerReg Scheduler .exe]
backup=C:\WINDOWS\pss\PowerReg Scheduler .exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^VIP^Start Menu^Programs^Startup^PowerReg Scheduler .exe]
backup=C:\WINDOWS\pss\PowerReg Scheduler .exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^VIP^Start Menu^Programs^Startup^PowerReg Scheduler .exe]
backup=C:\WINDOWS\pss\PowerReg Scheduler .exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^VIP^Start Menu^Programs^Startup^PowerReg Scheduler .exe]
backup=C:\WINDOWS\pss\PowerReg Scheduler .exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^VIP^Start Menu^Programs^Startup^PowerReg Scheduler .exe]
backup=C:\WINDOWS\pss\PowerReg Scheduler .exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^VIP^Start Menu^Programs^Startup^PowerReg Scheduler .exe]
backup=C:\WINDOWS\pss\PowerReg Scheduler .exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^VIP^Start Menu^Programs^Startup^PowerReg Scheduler .exe]
backup=C:\WINDOWS\pss\PowerReg Scheduler .exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^VIP^Start Menu^Programs^Startup^PowerReg Scheduler .exe]
backup=C:\WINDOWS\pss\PowerReg Scheduler .exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^VIP^Start Menu^Programs^Startup^PowerReg Scheduler .exe]
backup=C:\WINDOWS\pss\PowerReg Scheduler .exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^VIP^Start Menu^Programs^Startup^PowerReg Scheduler .exe]
backup=C:\WINDOWS\pss\PowerReg Scheduler .exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^VIP^Start Menu^Programs^Startup^PowerReg Scheduler .exe]
backup=C:\WINDOWS\pss\PowerReg Scheduler .exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^VIP^Start Menu^Programs^Startup^PowerReg Scheduler.exe]
backup=C:\WINDOWS\pss\PowerReg Scheduler.exeStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
-r------- 2005-05-04 04:43 69632 C:\WINDOWS\Alcmtr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2004-08-04 01:56 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FaxCenterServer]
C:\Program Files\Lexmark Fax Solutions\fm3032.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Free Uploader Oe Integration]
C:\Program Files\Free Download Manager\FUM\fumoei.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
C:\Program Files\Ahead\InCD\InCD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelliPoint]
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISTray]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\itype]
C:\Program Files\Microsoft IntelliType Pro\itype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\JustVoip]
C:\Program Files\JustVoip.com\JustVoip\JustVoip .exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Load]
C:\WINDOWS\system32\awvvt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxczbmgr.exe]
C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--a------ 2004-11-02 20:24 32768 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
-ra------ 2005-09-22 23:36 14854144 C:\WINDOWS\RTHDCPL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VetTray]
C:\PROGRA~1\CA\ETRUST~1\ETRUST~1\VetTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Window Washer]
C:\Program Files\Webroot\Washer\wwDisp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2008-01-28 14:40 4670968 C:\Program Files\Yahoo!\Messenger\YahooMessenger .exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wscsvc"=2 (0x2)
R2 lxcz_device;lxcz_device;C:\WINDOWS\system32\lxczcoms.exe [2007-02-09 01:50]
R2 wwEngineSvc;Window Washer Engine;C:\Program Files\Webroot\Washer\WasherSvc.exe [2007-10-03 09:33]
S3 BTNetFilter;Bluetooth Network Filter;C:\WINDOWS\system32\drivers\BTNetFilter.sys [2004-12-16 16:32]
S3 FTLUND;Lundinova Filter Driver;C:\WINDOWS\system32\drivers\ftlund.sys [2004-01-19 18:27]
S3 GNDHVF;Genius VideoCAM Smart300 V2;C:\WINDOWS\system32\DRIVERS\gndhvf.sys []
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4A6147C6-1320-9C42-021B-C3ABFAE0E786}]
C:\WINDOWS\system32\update.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-02-09 15:06:17 C:\WINDOWS\Tasks\RegCure Program Check.job"
- C:\Program Files\RegCure\RegCure.exe
"2008-01-24 10:16:19 C:\WINDOWS\Tasks\RegCure.job"
- C:\Program Files\RegCure\RegCure.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-09 18:06:57
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
r Running Proce
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\isafe.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
.
**************************************************************************
.
Completion time: 2008-02-09 18:10:45 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-09 15:10:35
.
2008-01-19 11:27:52 --- E O F ---
=================
Thankyou