ComboFix 07-09-21.2 - "Blain" 2007-09-27 22:59:30.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.118 [GMT -4:00]
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CnsMin.zip
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CnsMin1.zip
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CnsMin2.zip
C:\Program Files\3721
C:\Program Files\3721\assist\asbar.dll
C:\Program Files\3721\helper.dll
C:\Program Files\Accoona
C:\Program Files\Accoona\ASearchAssist.dll
C:\Program Files\akl
C:\Program Files\akl\akl.dll
C:\Program Files\akl\akl.exe
C:\Program Files\akl\curlog.htm
C:\Program Files\akl\keylog.txt
C:\Program Files\akl\readme.txt
C:\Program Files\akl\uninstall.exe
C:\Program Files\akl\unsetup.dat
C:\Program Files\akl\unsetup.exe
C:\Program Files\amsys
C:\Program Files\amsys\awmsg.dat
C:\Program Files\amsys\guid.dat
C:\Program Files\amsys\ijl15.dll
C:\Program Files\amsys\mfc42.dll
C:\Program Files\amsys\msvcrt.dll
C:\Program Files\amsys\unins000.dat
C:\Program Files\amsys\unis000.exe
C:\Program Files\amsys\winam.dat
C:\Program Files\e-zshopper
C:\Program Files\e-zshopper\BarLcher.dll
C:\Program Files\p2pnetworks
C:\Program Files\p2pnetworks\amp2pl.exe
C:\WINDOWS\764.exe
C:\WINDOWS\7search.dll
C:\WINDOWS\aconti.exe
C:\WINDOWS\adbar.dll
C:\WINDOWS\cbinst$.exe
C:\WINDOWS\daxtime.dll
C:\WINDOWS\dp0.dll
C:\WINDOWS\eventlowg.dll
C:\WINDOWS\fhfmm-Uninstaller.exe
C:\WINDOWS\fhfmm.exe
C:\WINDOWS\flt.dll
C:\WINDOWS\hcwprn.exe
C:\WINDOWS\hotporn.exe
C:\WINDOWS\ie_32.exe
C:\WINDOWS\iexplorr23.dll
C:\WINDOWS\jd2002.dll
C:\WINDOWS\kkcomp$.exe
C:\WINDOWS\kkcomp.dll
C:\WINDOWS\kkcomp.exe
C:\WINDOWS\kvnab$.exe
C:\WINDOWS\kvnab.dll
C:\WINDOWS\kvnab.exe
C:\WINDOWS\liqad$.exe
C:\WINDOWS\liqad.dll
C:\WINDOWS\liqad.exe
C:\WINDOWS\liqui-Uninstaller.exe
C:\WINDOWS\liqui.dll
C:\WINDOWS\liqui.exe
C:\WINDOWS\ngd.dll
C:\WINDOWS\pbar.dll
C:\WINDOWS\pbsysie.dll
C:\WINDOWS\settn.dll
C:\WINDOWS\spredirect.dll
C:\WINDOWS\system32\~.exe
C:\WINDOWS\system32\drivers\alert_icon.gif
C:\WINDOWS\system32\drivers\close_icon.gif
C:\WINDOWS\system32\drivers\detect.htm
C:\WINDOWS\system32\drivers\header_bg.gif
C:\WINDOWS\system32\drivers\icon_warning.gif
C:\WINDOWS\system32\drivers\perfect_cleaner_box.jpg
C:\WINDOWS\system32\drivers\pt.htm
C:\WINDOWS\system32\drivers\s_detect.htm
C:\WINDOWS\system32\drivers\secuity_center_logo.gif
C:\WINDOWS\system32\drivers\spy_away_box.jpg
C:\WINDOWS\system32\drivers\v.gif
C:\WINDOWS\system32\drivers\x.gif
C:\WINDOWS\system32\ESHOPEE.exe
C:\WINDOWS\system32\gtv_sd.bin
C:\WINDOWS\system32\msole32.exe
C:\WINDOWS\system32\vxddsk.exe
C:\WINDOWS\system32\wml.exe
C:\WINDOWS\vxddsk.exe
C:\WINDOWS\wbeCheck.exe
C:\WINDOWS\wbeInst$.exe
C:\WINDOWS\wml.exe
C:\WINDOWS\xadbrk.dll
C:\WINDOWS\xadbrk.exe
C:\WINDOWS\xadbrk_.exe
C:\WINDOWS\xxxvideo.exe
.
((((((((((((((((((((((((( Files Created from 2007-08-28 to 2007-09-28 )))))))))))))))))))))))))))))))
.
2007-09-27 23:03 <DIR> d-------- C:\Program Files\p2pnetworks
2007-09-27 23:03 <DIR> d-------- C:\Program Files\e-zshopper
2007-09-27 23:03 <DIR> d-------- C:\Program Files\amsys
2007-09-27 23:03 <DIR> d-------- C:\Program Files\akl
2007-09-27 23:03 <DIR> d-------- C:\Program Files\Accoona
2007-09-27 23:03 <DIR> d-------- C:\Program Files\3721
2007-09-27 22:57 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-09-27 22:21 3,152 --a------ C:\WINDOWS\system32\tmp.reg
2007-09-27 22:19 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-09-27 22:19 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-09-27 22:19 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2007-09-27 22:19 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2007-09-22 23:31 <DIR> d-------- C:\Program Files\Windows Defender
2007-09-22 23:04 <DIR> d-------- C:\!KillBox
2007-09-22 17:19 22,528 --a------ C:\WINDOWS\system32\ace16win.dll
2007-09-22 14:07 0 --a------ C:\WINDOWS\system32\drivers\wnmsav.dat
2007-09-22 13:57 71,552 --a------ C:\WINDOWS\system32\drivers\pavdrv51.sys
2007-09-22 13:56 9,216 --a------ C:\WINDOWS\system32\drivers\fnetmon.sys
2007-09-22 13:56 44,544 --a------ C:\WINDOWS\system32\drivers\APPFLT.SYS
2007-09-22 13:56 36,864 --a------ C:\WINDOWS\system32\drivers\dsaflt.sys
2007-09-22 13:56 23,296 --a------ C:\WINDOWS\system32\drivers\smsflt.sys
2007-09-22 13:56 229,084 --a------ C:\WINDOWS\system32\drivers\APPFCONT.DAT
2007-09-22 13:56 185,472 --a------ C:\WINDOWS\system32\drivers\idsflt.sys
2007-09-22 13:56 16,256 --a------ C:\WINDOWS\system32\drivers\wnmflt.sys
2007-09-22 13:53 <DIR> d-------- C:\Program Files\Panda Software
2007-09-22 13:52 26,752 --a------ C:\WINDOWS\system32\drivers\ShldDrv.sys
2007-09-22 13:52 165,120 --a------ C:\WINDOWS\system32\drivers\PavProc.sys
2007-09-22 13:47 <DIR> d-------- C:\Program Files\Common Files\Panda Software
2007-09-22 12:09 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-09-20 21:13 4 --a------ C:\WINDOWS\system32\stfv.bin
2007-09-20 20:45 <DIR> d-------- C:\WINDOWS\system32\acespy
2007-09-20 20:25 21,504 --a------ C:\WINDOWS\system32\qiawpbjj.dll
2007-09-20 20:25 12 --a------ C:\WINDOWS\system32\gtv_sd.bin
2007-09-19 19:47 89,088 --a------ C:\WINDOWS\system32\rtnka.dll
2007-09-19 19:47 1,592,320 --a------ C:\WINDOWS\system32\rtnka.dat
2007-09-18 16:52 492,544 --a------ C:\WINDOWS\system32\HtBt.dll
2007-09-17 20:14 541,696 --a------ C:\WINDOWS\system32\GE.dll
2007-09-17 20:14 <DIR> d-------- C:\Program Files\SoftPortal
2007-09-17 19:00 76,800 --a------ C:\WINDOWS\system32\unrar.dll
2007-09-17 19:00 1,590,784 --a------ C:\WINDOWS\system32\SoUI.dll
2007-09-14 10:24 1,659,017 --a------ C:\WINDOWS\system32\1074.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-09-27 23:12 1132 --a------ C:\WINDOWS\system32\drivers\APPFLTR.CFG
2007-09-27 23:03 9984 --a------ C:\WINDOWS\764.exe
2007-09-27 23:03 9216 --a------ C:\WINDOWS\xadbrk_.exe
2007-09-27 23:03 8448 --a------ C:\WINDOWS\liqad$.exe
2007-09-27 23:03 32256 --a------ C:\WINDOWS\pbsysie.dll
2007-09-27 23:03 31232 --a------ C:\WINDOWS\kkcomp.dll
2007-09-27 23:03 30720 --a------ C:\WINDOWS\fhfmm.exe
2007-09-27 23:03 30464 --a------ C:\WINDOWS\spredirect.dll
2007-09-27 23:03 30208 --a------ C:\WINDOWS\aconti.exe
2007-09-27 23:03 29696 --a------ C:\WINDOWS\kkcomp.exe
2007-09-27 23:03 28928 --a------ C:\WINDOWS\dp0.dll
2007-09-27 23:03 28928 --a------ C:\WINDOWS\cbinst$.exe
2007-09-27 23:03 28672 --a------ C:\WINDOWS\liqui.exe
2007-09-27 23:03 28416 --a------ C:\WINDOWS\wml.exe
2007-09-27 23:03 27648 --a------ C:\WINDOWS\ngd.dll
2007-09-27 23:03 27648 --a------ C:\WINDOWS\7search.dll
2007-09-27 23:03 27392 --a------ C:\WINDOWS\jd2002.dll
2007-09-27 23:03 26880 --a------ C:\WINDOWS\xadbrk.dll
2007-09-27 23:03 26368 --a------ C:\WINDOWS\hotporn.exe
2007-09-27 23:03 25600 --a------ C:\WINDOWS\xadbrk.exe
2007-09-27 23:03 24832 --a------ C:\WINDOWS\wbeInst$.exe
2007-09-27 23:03 22528 --a------ C:\WINDOWS\liqui.dll
2007-09-27 23:03 20736 --a------ C:\WINDOWS\wbeCheck.exe
2007-09-27 23:03 20736 --a------ C:\WINDOWS\adbar.dll
2007-09-27 23:03 20480 --a------ C:\WINDOWS\ie_32.exe
2007-09-27 23:03 20480 --a------ C:\WINDOWS\daxtime.dll
2007-09-27 23:03 19968 --a------ C:\WINDOWS\settn.dll
2007-09-27 23:03 19456 --a------ C:\WINDOWS\xxxvideo.exe
2007-09-27 23:03 19200 --a------ C:\WINDOWS\liqad.exe
2007-09-27 23:03 17664 --a------ C:\WINDOWS\kvnab.exe
2007-09-27 23:03 17408 --a------ C:\WINDOWS\iexplorr23.dll
2007-09-27 23:03 17152 --a------ C:\WINDOWS\eventlowg.dll
2007-09-27 23:03 15104 --a------ C:\WINDOWS\liqad.dll
2007-09-27 23:03 13312 --a------ C:\WINDOWS\kkcomp$.exe
2007-09-27 23:03 13056 --a------ C:\WINDOWS\kvnab$.exe
2007-09-27 23:03 12544 --a------ C:\WINDOWS\liqui-Uninstaller.exe
2007-09-27 23:03 12288 --a------ C:\WINDOWS\flt.dll
2007-09-27 23:03 12032 --a------ C:\WINDOWS\fhfmm-Uninstaller.exe
2007-09-27 23:03 11776 --a------ C:\WINDOWS\kvnab.dll
2007-09-27 23:03 11520 --a------ C:\WINDOWS\vxddsk.exe
2007-09-27 23:03 11008 --a------ C:\WINDOWS\hcwprn.exe
2007-09-27 23:03 10240 --a------ C:\WINDOWS\pbar.dll
2007-09-26 1rogram Files\QuickTime
2007-09-26 1rogram Files\Microsoft ActiveSync
2007-09-26 1rogram Files\iTunes
2007-09-24 2OCUME~1\Blain\APPLIC~1\uTorrent
2007-09-24 1rogram Files\Google
2007-09-23 1rogram Files\uTorrent
2007-09-22 1rogram Files\Punk O Rama IV
2007-09-22 1rogram Files\InstallShield Installation Information
2007-09-22 1rogram Files\Symantec
2007-09-22 1rogram Files\Common Files\Symantec Shared
2007-09-22 1OCUME~1\ALLUSE~1\APPLIC~1\Symantec
2007-09-20 20:24 841 --a------ C:\WINDOWS\system32\drivers\perfect_cleaner_header_small.gif
2007-09-20 20:24 811 --a------ C:\WINDOWS\system32\drivers\download_btn.gif
2007-09-20 20:24 746 --a------ C:\WINDOWS\system32\drivers\buy_btn.gif
2007-09-20 20:24 737 --a------ C:\WINDOWS\system32\drivers\logo_bg.gif
2007-09-20 20:24 580 --a------ C:\WINDOWS\system32\drivers\features.gif
2007-09-20 20:24 579 --a------ C:\WINDOWS\system32\drivers\spy_away_header_small.gif
2007-09-20 20:24 567 --a------ C:\WINDOWS\system32\drivers\users_rating.gif
2007-09-20 20:24 5097 --a------ C:\WINDOWS\system32\drivers\spy_away_box_small.jpg
2007-09-20 20:24 4557 --a------ C:\WINDOWS\system32\drivers\perfect_cleaner_box_small.jpg
2007-09-20 20:24 427 --a------ C:\WINDOWS\system32\drivers\4_stars.gif
2007-09-20 20:24 365 --a------ C:\WINDOWS\system32\drivers\5_stars.gif
2007-09-20 20:24 1804 --a------ C:\WINDOWS\system32\drivers\perfect_cleaner_header.gif
2007-09-20 20:24 14484 --a------ C:\WINDOWS\system32\drivers\protect.gif
2007-09-20 20:24 1139 --a------ C:\WINDOWS\system32\drivers\spy_away_header.gif
2007-09-20 20:24 1009 --a------ C:\WINDOWS\system32\drivers\arrow.gif
2007-09-18 2rogram Files\Rainbow
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{00000000-d9e3-4bc6-a0bd-3d0ca4be5271}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{00000012-890e-4aac-afd9-eff6954a34dd}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{026B5895-3E8E-49A9-8EEE-B52A326DA962}]
2007-09-20 20:25 21504 --a------ C:\WINDOWS\system32\qiawpbjj.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{029e02f0-a0e5-4b19-b958-7bf2db29fb13}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06dfedaa-6196-11d5-bfc8-00508b4a487d}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1adbcce8-cf84-441e-9b38-afc7a19c06a4}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2d7cb618-cc1c-4126-a7e3-f5b12d3bcf71}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{51641ef3-8a7a-4d84-8659-b0911e947cc8}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53C330D6-A4AB-419B-B45D-FD4411C1FEF4}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{54645654-2225-4455-44A1-9F4543D34546}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{669695bc-a811-4a9d-8cdf-ba8c795f261e}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6abc861a-31e7-4d91-b43b-d3c98f22a5c0}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{944864a5-3916-46e2-96a9-a2e84f3f1208}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a4a435cf-3583-11d4-91bd-0048546a1450}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{b8875bfe-b021-11d4-bfa8-00508b8e9bd3}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c2680e10-1655-4a0e-87f8-4259325a84b7}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c4ca6559-2cf1-48b6-96b2-8340a06fd129}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c5af2622-8c75-4dfb-9693-23ab7686a456}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ca1d1b05-9c66-11d5-a009-000103c1e50b}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d8efadf1-9009-11d6-8c73-608c5dc19089}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e9147a0a-a866-4214-b47c-da821891240f}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e9306072-417e-43e3-81d5-369490beef7c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EF3446E8-FC32-4E55-9C56-0B8DA015FC10}]
2007-09-24 23:00 541696 --a------ C:\WINDOWS\system32\GE.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PRONoMgr.exe"="c:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe" [2002-10-23 10:15]
"SoundMan"="SOUNDMAN.EXE" [2003-04-24 16:53 C:\WINDOWS\SOUNDMAN.EXE]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2002-10-15 23:18]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2002-10-15 23:05]
"NeroCheck"="C:\WINDOWS\System32\\NeroCheck.exe" [2001-07-09 06:50]
"Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2003-06-07 07:32]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd.exe" [2003-08-04 17:28]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 08:38]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-02-23 16:45]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-05-20 20:56]
"APVXDWIN"="C:\Program Files\Panda Software\Panda Internet Security 2007\APVXDWIN.exe" [2006-10-11 12:09]
"SCANINICIO"="C:\Program Files\Panda Software\Panda Internet Security 2007\Inicio.exe" [2006-02-01 18:13]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" []
"MoneyAgent"="C:\Program Files\Microsoft Money\System\mnyexpr.exe" [2003-06-18 12:00]
"RHSI SHS"="C:\Program Files\Rogers\SelfHealing\SHS.exe" [2007-04-25 10:46]
"Update Manager"="C:\Program Files\Rogers\Update Manager\UpdateManager.exe" [2007-04-25 10:46]
"SHS"="C:\Program Files\Rogers\SelfHealing\SHS.exe" [2007-04-25 10:46]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2005-11-15 19:44]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-08-07 10:58]
"RogersAgent"="c:\Program Files\Rogers\SelfHealing\rogersagent.exe" [2007-04-23 16:51]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"RunNarrator"=Narrator.exe
C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2003-09-16 05:19:24]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04]
Picture Package Menu.lnk - C:\Program Files\Sony\Picture Package\Picture Package Menu\SonyTray.exe [2004-12-31 21:44:00]
Picture Package VCD Maker.lnk - C:\Program Files\Sony\Picture Package\Picture Package Applications\Residence.exe [2004-12-31 21:43:54]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avldr]
avldr.dll 2005-09-27 12:13 45056 C:\WINDOWS\system32\avldr.dll
R0 netflt;Panda Net Driver [NDIS Layer];C:\WINDOWS\system32\drivers\netflt.sys
R1 APPFLT;App Filter Plugin;\??\C:\WINDOWS\system32\Drivers\APPFLT.SYS
R1 cdrbsvsd;cdrbsvsd;C:\WINDOWS\system32\drivers\cdrbsvsd.sys
R1 DSAFLT;DSA Filter Plugin;\??\C:\WINDOWS\system32\Drivers\DSAFLT.SYS
R1 FNETMON;NetMon Filter Plugin;\??\C:\WINDOWS\system32\Drivers\fnetmon.SYS
R1 IDSFLT;Ids Filter Plugin;\??\C:\WINDOWS\system32\Drivers\IDSFLT.SYS
R1 NETFLTDI;Panda Net Driver [TDI Layer];\??\C:\WINDOWS\system32\Drivers\NETFLTDI.SYS
R1 ShldDrv;Panda File Shield Driver;C:\WINDOWS\system32\drivers\ShldDrv.sys
R1 SMSFLT;SMS Filter Plugin;\??\C:\WINDOWS\system32\Drivers\SMSFLT.SYS
R1 WNMFLT;Wifi Monitor Filter Plugin;\??\C:\WINDOWS\system32\Drivers\WNMFLT.SYS
R2 cpoint;Panda CPoint Driver;C:\WINDOWS\system32\drivers\cpoint.sys
R2 PAVDRV;pavdrv;C:\WINDOWS\system32\DRIVERS\pavdrv51.sys
R2 PavProc;Panda Process Protection Driver;\??\C:\WINDOWS\system32\DRIVERS\PavProc.sys
R3 AvFlt;Antivirus Filter Driver;C:\WINDOWS\system32\drivers\av5flt.sys
R3 PavSRK.sys;PavSRK.sys;\??\C:\WINDOWS\system32\PavSRK.sys
R3 PavTPK.sys;PavTPK.sys;\??\C:\WINDOWS\system32\PavTPK.sys
S3 JL2005;JL2005A Toy Camera;C:\WINDOWS\system32\Drivers\toywdm.sys
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3cc2b7c3-b491-11db-9995-000cf1edc90b}]
AutoRun\command- E:\setupSNK.exe
.
Contents of the 'Scheduled Tasks' folder
"2007-09-28 03:11:59 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
"2007-09-28 03:00:21 C:\WINDOWS\Tasks\Symantec NetDetect.job"
.
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-27 23:10:44
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-09-27 23:16:23 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-09-27 23:16
.
--- E O F ---