ComboFix-ComboFix 08-02-23.2 - HP_Owner 2008-02-23 11:14:56.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.109 [GMT -6:00]
Running from: C:\Documents and Settings\HP_Owner\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\WinAntiVirus Pro 2006
C:\Documents and Settings\HP_Owner\Application Data\WinAntiVirus Pro 2006
C:\Documents and Settings\HP_Owner\Application Data\WinAntiVirus Pro 2006\Logs\update.log
C:\Documents and Settings\HP_Owner\Application Data\WinAntiVirus Pro 2006\Logs\wa6Support.log
C:\Documents and Settings\HP_Owner\Application Data\WinAntiVirus Pro 2006\Logs\winav.log
C:\Documents and Settings\HP_Owner\Application Data\WinAntiVirus Pro 2006\PGE.dat
C:\Documents and Settings\HP_Owner\err.log
C:\Program Files\Common Files\companion wizard
C:\Program Files\Common Files\companion wizard\compwiz.exe
C:\Program Files\Common Files\companion wizard\log.txt
C:\Program Files\Common Files\companion wizard\WapCHK.dll
C:\Program Files\FunWebProducts
C:\Program Files\FunWebProducts\ScreenSaver\Images\15AC63A2.urr
C:\Program Files\FunWebProducts\Shared\Cache\CursorManiaBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\FunBuddyIconBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\MyFunCardsIMBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\SmileyCentralBtn.html
C:\Program Files\MyWebSearch
C:\Program Files\MyWebSearch\bar\2.bin\F3HTMLMU.DLL
C:\Program Files\MyWebSearch\bar\2.bin\M3HTML.DLL
C:\Program Files\MyWebSearch\bar\2.bin\MWSBAR.DLL
C:\Program Files\MyWebSearch\bar\2.bin\MWSOEMON.EXE
C:\Program Files\MyWebSearch\bar\2.bin\MWSOEPLG.DLL
C:\Program Files\MyWebSearch\bar\2.bin\MWSOESTB.DLL
C:\Program Files\MyWebSearch\bar\3.bin\F3BKGERR.JPG
C:\Program Files\MyWebSearch\bar\3.bin\F3CJPEG.DLL
C:\Program Files\MyWebSearch\bar\3.bin\F3DTACTL.DLL
C:\Program Files\MyWebSearch\bar\3.bin\F3HISTSW.DLL
C:\Program Files\MyWebSearch\bar\3.bin\F3HTMLMU.DLL
C:\Program Files\MyWebSearch\bar\3.bin\F3HTTPCT.DLL
C:\Program Files\MyWebSearch\bar\3.bin\F3POPSWT.DLL
C:\Program Files\MyWebSearch\bar\3.bin\F3PSSAVR.SCR
C:\Program Files\MyWebSearch\bar\3.bin\F3REPROX.DLL
C:\Program Files\MyWebSearch\bar\3.bin\F3RESTUB.DLL
C:\Program Files\MyWebSearch\bar\3.bin\F3SCHMON.EXE
C:\Program Files\MyWebSearch\bar\3.bin\F3SCRCTR.DLL
C:\Program Files\MyWebSearch\bar\3.bin\F3SHLLVW.DLL
C:\Program Files\MyWebSearch\bar\3.bin\F3SPACER.WMV
C:\Program Files\MyWebSearch\bar\3.bin\F3WALLPP.DAT
C:\Program Files\MyWebSearch\bar\3.bin\F3WPHOOK.DLL
C:\Program Files\MyWebSearch\bar\3.bin\M3FFXTBR.JAR
C:\Program Files\MyWebSearch\bar\3.bin\M3FFXTBR.MANIFEST
C:\Program Files\MyWebSearch\bar\3.bin\M3HTML.DLL
C:\Program Files\MyWebSearch\bar\3.bin\M3IDLE.DLL
C:\Program Files\MyWebSearch\bar\3.bin\M3NTSTBR.JAR
C:\Program Files\MyWebSearch\bar\3.bin\M3OUTLCN.DLL
C:\Program Files\MyWebSearch\bar\3.bin\M3PLUGIN.DLL
C:\Program Files\MyWebSearch\bar\3.bin\M3SKIN.DLL
C:\Program Files\MyWebSearch\bar\3.bin\M3SKPLAY.EXE
C:\Program Files\MyWebSearch\bar\3.bin\MWSBAR.DLL
C:\Program Files\MyWebSearch\bar\3.bin\MWSOEMON.EXE
C:\Program Files\MyWebSearch\bar\3.bin\MWSOEPLG.DLL
C:\Program Files\MyWebSearch\bar\3.bin\MWSOESTB.DLL
C:\Program Files\MyWebSearch\bar\3.bin\NPMYWEBS.DLL
C:\Program Files\MyWebSearch\bar\Cache\[u]0[/u]0071A0D
C:\Program Files\MyWebSearch\bar\Cache\[u]0[/u]10EFD69
C:\Program Files\MyWebSearch\bar\Cache\[u]0[/u]155EDDF.bin
C:\Program Files\MyWebSearch\bar\Cache\[u]0[/u]17986CA
C:\Program Files\MyWebSearch\bar\Cache\[u]0[/u]1AEF08E
C:\Program Files\MyWebSearch\bar\Cache\[u]0[/u]34DAD2A.bin
C:\Program Files\MyWebSearch\bar\Cache\[u]0[/u]34DB23A.bin
C:\Program Files\MyWebSearch\bar\Cache\[u]0[/u]34DBAE5.bin
C:\Program Files\MyWebSearch\bar\Cache\[u]0[/u]34DC229.bin
C:\Program Files\MyWebSearch\bar\Cache\[u]0[/u]4991C83.bin
C:\Program Files\MyWebSearch\bar\Cache\[u]0[/u]499258C.bin
C:\Program Files\MyWebSearch\bar\Cache\[u]0[/u]5779C2B.bin
C:\Program Files\MyWebSearch\bar\Cache\[u]0[/u]6B548E0.bin
C:\Program Files\MyWebSearch\bar\Cache\[u]0[/u]6B55024.bin
C:\Program Files\MyWebSearch\bar\Cache\[u]0[/u]ABE0C54
C:\Program Files\MyWebSearch\bar\Cache\16EEEAC5.bin
C:\Program Files\MyWebSearch\bar\Cache\16EEF526.bin
C:\Program Files\MyWebSearch\bar\Cache\16EF0284.bin
C:\Program Files\MyWebSearch\bar\Cache\2CF2CB42
C:\Program Files\MyWebSearch\bar\Cache\4442655F
C:\Program Files\MyWebSearch\bar\Cache\511384C7
C:\Program Files\MyWebSearch\bar\Cache\files.ini
C:\Program Files\MyWebSearch\bar\Game\CHECKERS.F3S
C:\Program Files\MyWebSearch\bar\Game\CHESS.F3S
C:\Program Files\MyWebSearch\bar\Game\REVERSI.F3S
C:\Program Files\MyWebSearch\bar\History\search
C:\Program Files\MyWebSearch\bar\History\search2
C:\Program Files\MyWebSearch\bar\Settings\prevcfg.htm
C:\Program Files\MyWebSearch\bar\Settings\prevcfg2.htm
C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat
C:\Program Files\MyWebSearch\bar\Settings\setting2.htm
C:\Program Files\MyWebSearch\bar\Settings\settings.dat
C:\Program Files\MyWebSearch\bar\Settings\settings.dat.bak
C:\Program Files\MyWebSearch\bar\Settings\settings.htm
C:\Program Files\MyWebSearch\SrchAstt\2.bin\MWSSRCAS.DLL
C:\Program Files\MyWebSearch\SrchAstt\3.bin\MWSSRCAS.DLL
C:\Program Files\newdotnet
C:\Program Files\newdotnet\readme.html
C:\Program Files\newdotnet\uninstall.exe
C:\WA6P
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\afrhucgj.ini
C:\WINDOWS\system32\f3PSSavr.scr
C:\WINDOWS\system32\fgetqoeb.ini
C:\WINDOWS\system32\gqkojcfs.ini
C:\WINDOWS\system32\ieixapqp.ini
C:\WINDOWS\system32\nGpxx01
C:\WINDOWS\system32\nmllm.ini
C:\WINDOWS\system32\nmllm.ini2
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\qundhudb.ini
C:\WINDOWS\system32\sntsmacm.ini
C:\WINDOWS\system32\stera.job
C:\WINDOWS\system32\stera.log
C:\WINDOWS\system32\vmrbkvat.ini
D:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_FOPN
-------\LEGACY_NNSERV
-------\LEGACY_VSPF
-------\LEGACY_VSPF_HK
-------\FOPN
-------\vspf
-------\vspf_hk
((((((((((((((((((((((((( Files Created from 2008-01-23 to 2008-02-23 )))))))))))))))))))))))))))))))
.
2008-02-23 10:51 . 2008-02-23 11:07 <DIR> d-------- C:\VundoFix Backups
2008-02-22 21:46 . 2008-02-22 21:46 91,700 --a------ C:\WINDOWS\system32\drivers\klin.dat
2008-02-22 21:46 . 2008-02-22 21:46 85,860 --a------ C:\WINDOWS\system32\drivers\klick.dat
2008-02-22 21:44 . 2008-02-22 21:44 <DIR> d-------- C:\Program Files\Kaspersky Lab
2008-02-22 21:44 . 2008-02-23 11:19 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-02-22 21:44 . 2008-02-23 11:19 3,607,328 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-02-22 21:44 . 2008-02-23 11:18 49,364 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-02-22 21:44 . 2008-02-23 11:19 6,176 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-02-22 21:44 . 2008-02-23 11:18 1,628 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-02-22 21:32 . 2008-02-22 21:32 <DIR> d-------- C:\kav
2008-02-21 15:32 . 2008-02-21 15:32 70,820 --a------ C:\WINDOWS\BM77e02ee0.xml
2008-02-21 15:32 . 2008-02-22 21:55 22 --a------ C:\WINDOWS\pskt.ini
2008-02-16 19:39 . 2008-02-23 11:19 181 --a------ C:\WINDOWS\system\hpsysdrv.DAT
2008-02-16 12:46 . 2008-02-16 12:46 <DIR> d---s---- C:\Documents and Settings\LocalService\UserData
2008-02-16 12:43 . 2008-02-16 12:43 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\Symantec
2008-02-14 16:06 . 2008-02-16 11:00 <DIR> d-------- C:\Program Files\MalwareAlarm
2008-02-08 18:37 . 2008-02-08 18:37 219,664 --a------ C:\WINDOWS\system32\klogon.dll
2008-02-08 18:35 . 2008-02-08 18:35 23,604 --a------ C:\WINDOWS\system32\drivers\klopp.dat
2008-02-02 12:59 . 2008-02-02 12:59 16,384 --a------ C:\WINDOWS\~DF3457.tmp
2008-02-01 09:44 . 2008-02-01 09:44 0 --a------ C:\WINDOWS\iPlayer.INI
2008-02-01 09:43 . 2008-02-01 09:44 <DIR> d-------- C:\Program Files\InterActual
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-23 02:03 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-02-23 01:43 --------- d-----w C:\Program Files\Symantec
2008-02-21 22:07 --------- d-----w C:\Program Files\eGames
2008-02-21 21:59 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-21 21:59 --------- d-----w C:\Program Files\Common Files\NewSoft
2008-02-21 21:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-02-21 21:49 --------- d-----w C:\Documents and Settings\HP_Owner\Application Data\Lavasoft
2008-02-16 21:07 --------- d-----w C:\Program Files\Common Files\Real
2008-02-14 22:25 --------- d-----w C:\Program Files\Selectsoft
2008-02-02 18:59 16,384 ----a-w C:\WINDOWS\~DF3457.tmp
2008-01-30 23:31 --------- d-----w C:\Program Files\MySpace
2008-01-06 22:00 --------- d-----w C:\Program Files\Insaniquarium Deluxe
2008-01-06 21:59 737,280 -c--a-w C:\WINDOWS\iun6002.exe
2007-03-26 20:42 24,192 -c--a-w C:\Documents and Settings\HP_Owner\usbsermptxp.sys
2007-03-26 20:42 22,768 -c--a-w C:\Documents and Settings\HP_Owner\usbsermpt.sys
2006-11-06 21:59 0 -c--a-w C:\Program Files\Common Files\err.log
2005-09-26 19:47 774,144 ----a-w C:\Program Files\RngInterstitial.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4226cec1-aab3-4233-b951-667ecaa8d729}]
C:\WINDOWS\system32\ekwlklnx.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{51528F4D-F083-4D1A-8BB5-2A8ACE6E6B6C}]
C:\WINDOWS\system32\mllmn.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 06:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 17:04 52736]
"HPHUPD06"="c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe" [2004-06-07 19:53 49152]
"HPHmon06"="C:\WINDOWS\system32\hphmon06.exe" [2004-06-07 19:42 659456]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2004-04-14 21:43 233472]
"SiSPower"="SiSPower.dll" [2004-09-24 10:49 49152 C:\WINDOWS\system32\SiSPower.dll]
"AGRSMMSG"="AGRSMMSG.exe" [2004-06-29 18:06 88363 C:\WINDOWS\AGRSMMSG.exe]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2002-10-16 17:57 81920]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-04-17 14:41 196608]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 21:47 57344 C:\WINDOWS\ALCXMNTR.EXE]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-02-23 16:45 155648]
"SM_IAN"="C:\Program Files\AdvancedCleaner Free\ian_monitor.exe" [ ]
"74d31d7c"="C:\WINDOWS\system32\wgkgqnuo.dll" [ ]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" [2008-02-08 18:36 227856]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-12-18 19:47 8720384]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2004-05-29 06:31:38 241664]
Updates from HP.lnk - C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe [2004-10-21 20:25:38 45056]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\fccaabc]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^GStartup.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\GStartup.lnk
backup=C:\WINDOWS\pss\GStartup.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^MyWebSearch Email Plugin.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\MyWebSearch Email Plugin.lnk
backup=C:\WINDOWS\pss\MyWebSearch Email Plugin.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Photags AutoDetect.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Photags AutoDetect.lnk
backup=C:\WINDOWS\pss\Photags AutoDetect.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SpySubtract.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SpySubtract.lnk
backup=C:\WINDOWS\pss\SpySubtract.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ymetray.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ymetray.lnk
backup=C:\WINDOWS\pss\ymetray.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^HP_Owner^Start Menu^Programs^Startup^MyWebSearch Email Plugin.lnk]
path=C:\Documents and Settings\HP_Owner\Start Menu\Programs\Startup\MyWebSearch Email Plugin.lnk
backup=C:\WINDOWS\pss\MyWebSearch Email Plugin.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2005-12-16 12:57 94208 C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DC6_check]
C:\Program Files\Common Files\dc6_startupmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ERS_check]
C:\Program Files\Common Files\ers_startupmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
--a------ 2004-08-20 23:55 155648 C:\WINDOWS\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
--a------ 2004-04-13 08:07 69632 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LSBWatcher]
--a------ 2004-10-14 22:54 253952 c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSGRAPH01]
c:\program files\common files\system\7mi3qd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MyWebSearch Email Plugin]
C:\PROGRA~1\MYWEBS~1\bar\3.bin\mwsoemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 10:50 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2006-02-23 16:45 155648 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Smart Start UP]
C:\Program Files\NewSoft\Smart Start UP\PnPDetect.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2004-10-21 18:27 32881 C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2007-08-30 17:43 4670704 C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"= %windir%\\system32\\sessmgr.exe:@xpsp2res.dll,-22019
"C:\\Program Files\\Updates from HP\\309731\\Program\\Updates from HP.exe"=
"C:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\LimeWire\\LimeWire 4.2.6 Pro\\LimeWire.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\msncall.exe"=
"C:\\Documents and Settings\\HP_Owner\\My Documents\\iTunes.exe"=
"C:\\Program Files\\WinAntiVirus Pro 2006\\Updater.exe"=
"C:\\Program Files\\Yahoo!\\Yahoo! Music Jukebox\\YahooMusicEngine.exe"=
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2007-12-13 13:28]
S2 Ca536av;FashionCam Video Camera Device;C:\WINDOWS\system32\Drivers\Ca536av.sys [2003-09-05 12:47]
S3 USBCamera;FashionCam Digital Still Camera Device;C:\WINDOWS\system32\Drivers\Bulk536.sys [2003-05-14 16:28]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-23 11:19:51
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
r Running Proce
.
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\rundll32.exe
.
**************************************************************************
.
Completion time: 2008-02-23 11:22:16 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-23 17:22:09
.
2008-02-15 09:02:00 --- E O F ---