finally...
"Deborah" - 07-03-26 11:46:45 Service Pack 2
ComboFix 07-03-23 - Running from: "C:\Documents and Settings\Deborah\Desktop"
((((((((((((((((((((((((((((((((((((((((((((( Look2Me's Log ))))))))))))))))))))))))))))))))))))))))))))))))))
REGISTRY ENTRIES REMOVED:
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\clsid\{cb6e53b4-3fc4-4557-adb4-9555b9351d3c}]
@=""
[HKEY_CLASSES_ROOT\clsid\{cb6e53b4-3fc4-4557-adb4-9555b9351d3c}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\clsid\{cb6e53b4-3fc4-4557-adb4-9555b9351d3c}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\clsid\{cb6e53b4-3fc4-4557-adb4-9555b9351d3c}\InprocServer32]
@="C:\\WINDOWS\\system32\\mjaudite.dll"
"ThreadingModel"="Apartment"
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\keyboard1.dat
C:\WINDOWS\system325-11-14.exe
C:\WINDOWS\system327-11-16.exe
C:\WINDOWS\system32\1.exe~
C:\WINDOWS\system32\20-11-22.exe
C:\WINDOWS\system32\23-11-14.exe
C:\WINDOWS\system32\27-11-18.exe
C:\WINDOWS\system32\28-11-20.exe
C:\Program Files\Common Files\svchostsys\svchostsys.exe.config
C:\Program Files\Common Files\svchostsys\svchostupdate.exe.config
C:\Program Files\Common Files\svchostsys\sysid.exe
C:\Program Files\Common Files\svchostsys\Version.txt
C:\WINDOWS\system32\loadadv559.exe
C:\WINDOWS\system32\test.exe
C:\WINDOWS\system32\unsvchosts.lzma
C:\secure32.html
C:\Program Files\Common Files\{35A17~1
C:\Program Files\Common Files\{35A17~3
C:\Program Files\Common Files\{35A17~2
C:\Program Files\Common Files\{75A17~3
C:\Program Files\Common Files\{75A17~2
C:\Program Files\Common Files\{75A17~4
C:\Program Files\Common Files\{75A17~1
C:\Program Files\Common Files\misc001
C:\Program Files\Common Files\simtest
C:\Program Files\Common Files\svchostsys
C:\WINDOWS\system32\lzx32.sys
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\qoobox\purity\Program Files\SSTEM3~1
C:\qoobox\purity\Program Files\Common Files\CROSOF~1
C:\qoobox\purity\Program Files\SSTEM3~1\SSTEM3~1
((((((((((((((((((((((((((((((( Files Created from 2007-02-26 to 2007-03-26 ))))))))))))))))))))))))))))))))))
2007-03-23 10:08 6 --a------ C:\WINDOWS\system32\23-03-10.dat
2007-03-23 09:03 6 --a------ C:\WINDOWS\system32\23-03-09.dat
2007-03-23 08:59 6 --a------ C:\WINDOWS\system32\23-03-08.dat
2007-03-22 20:20 6 --a------ C:\WINDOWS\system32\22-03-20.dat
2007-03-22 15:00 6 --a------ C:\WINDOWS\system32\22-03-15.dat
2007-03-22 14:39 6 --a------ C:\WINDOWS\system32\22-03-14.dat
2007-03-22 14:28 <DIR> d-------- C:\WINDOWS\pss
2007-03-22 12:46 6 --a------ C:\WINDOWS\system32\22-03-12.dat
2007-03-22 11:57 786,432 --ah----- C:\DOCUME~1\ADMINI~1\NTUSER.DAT
2007-03-22 11:57 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\Symantec
2007-03-22 11:57 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\Apple Computer
2007-03-22 08:34 6 --a------ C:\WINDOWS\system32\22-03-08.dat
2007-03-21 10:07 6 --a------ C:\WINDOWS\system32\21-03-10.dat
2007-03-21 01:43 6 --a------ C:\WINDOWS\system32\21-03-01.dat
2007-03-20 22:27 6 --a------ C:\WINDOWS\system32\20-03-22.dat
2007-03-20 16:15 6 --a------ C:\WINDOWS\system32\20-03-16.dat
2007-03-20 14:37 6 --a------ C:\WINDOWS\system32\20-03-14.dat
2007-03-20 12:03 94,424 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2007-03-20 12:03 90,112 --a------ C:\WINDOWS\system32\AVASTSS.scr
2007-03-20 12:03 85,952 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2007-03-20 12:03 689,280 --a------ C:\WINDOWS\system32\aswBoot.exe
2007-03-20 12:03 43,176 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2007-03-20 12:03 31,560 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2007-03-20 12:03 23,352 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2007-03-20 12:03 <DIR> d-------- C:\Program Files\Alwil Software
2007-03-20 12:01 6 --a------ C:\WINDOWS\system32\20-03-12.dat
2007-03-20 11:55 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
2007-03-20 11:00 6 --a------ C:\WINDOWS\system32\20-03-11.dat
2007-03-20 10:00 6 --a------ C:\WINDOWS\system32\20-03-10.dat
2007-03-20 09:44 6 --a------ C:\WINDOWS\system32\20-03-09.dat
2007-03-20 03:35 6 --a------ C:\WINDOWS\system32\20-03-03.dat
2007-03-19 20:27 6 --a------ C:\WINDOWS\system32\19-03-20.dat
2007-03-19 13:12 6 --a------ C:\WINDOWS\system32\19-03-13.dat
2007-03-18 12:40 6 --a------ C:\WINDOWS\system32\18-03-12.dat
2007-03-17 11:12 6 --a------ C:\WINDOWS\system32\17-03-11.dat
2007-03-16 14:18 6 --a------ C:\WINDOWS\system32\16-03-14.dat
2007-03-16 12:12 6 --a------ C:\WINDOWS\system32\16-03-12.dat
2007-03-14 14:49 6 --a------ C:\WINDOWS\system32\14-03-14.dat
2007-03-14 12:08 6 --a------ C:\WINDOWS\system32\14-03-12.dat
2007-03-14 11:03 6 --a------ C:\WINDOWS\system32\14-03-11.dat
2007-03-14 10:54 6 --a------ C:\WINDOWS\system32\14-03-10.dat
2007-03-14 09:26 6 --a------ C:\WINDOWS\system32\14-03-09.dat
2007-03-14 08:14 6 --a------ C:\WINDOWS\system32\14-03-08.dat
2007-03-04 19:33 6 --a------ C:\WINDOWS\system324-03-18.dat
2007-03-04 13:55 6 --a------ C:\WINDOWS\system324-03-12.dat
2007-03-04 04:11 6 --a------ C:\WINDOWS\system324-03-03.dat
2007-03-04 03:15 6 --a------ C:\WINDOWS\system324-03-02.dat
2007-03-02 18:11 6 --a------ C:\WINDOWS\system322-03-17.dat
2007-02-27 11:46 26,624 --a------ C:\DOCUME~1\Deborah\PJNA.exe
2007-02-27 11:10 26,624 --a------ C:\DOCUME~1\Deborah\SQJT.exe
2007-02-26 15:05 26,624 --a------ C:\DOCUME~1\Deborah\RSHS.exe
2007-02-26 15:00 26,624 --a------ C:\DOCUME~1\Deborah\DUHJ.exe
2007-02-26 14:55 26,624 --a------ C:\DOCUME~1\Deborah\RTHF.exe
2007-02-26 14:13 26,624 --a------ C:\DOCUME~1\Deborah\QULL.exe
2007-02-26 14:11 26,624 --a------ C:\DOCUME~1\Deborah\QQEJ.exe
2007-02-26 14:07 26,624 --a------ C:\DOCUME~1\Deborah\UPKN.exe
2007-02-26 14:07 26,624 --a------ C:\DOCUME~1\Deborah\JKMT.exe
2007-02-26 14:06 26,624 --a------ C:\DOCUME~1\Deborah\SGGJ.exe
2007-02-26 14:06 26,624 --a------ C:\DOCUME~1\Deborah\FTOB.exe
2007-02-26 14:05 26,624 --a------ C:\DOCUME~1\Deborah\RIBT.exe
2007-02-26 14:05 26,624 --a------ C:\DOCUME~1\Deborah\MJKB.exe
2007-02-26 14:04 26,624 --a------ C:\DOCUME~1\Deborah\SOBO.exe
2007-02-26 14:00 26,624 --a------ C:\DOCUME~1\Deborah\KDSC.exe
2007-02-26 13:59 171,008 --a------ C:\WINDOWS\system32\LXAESUI.DLL
2007-02-26 13:47 6 --a------ C:\WINDOWS\system32\26-02-12.dat
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
[color=\"red\"]
Rootkit driver pe386 is present. ... attempting disinfection [/color]
[color=\"blue\"] pe386 ... driver unloaded successfully. Run ADS scan for remnant driver file [/color]
2007-03-23 10:39 -------- d-------- C:\Program Files\plaxo
2007-03-19 14:51 3764 --a------ C:\WINDOWS\mozver.dat
2007-03-19 14:51 -------- d-------- C:\Program Files\java
2007-03-19 14:42 -------- d-------- C:\Program Files\registrycleaner
2007-03-04 13:57 -------- d-------- C:\Program Files\pedevice
2007-03-04 03:08 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2007-02-24 13:08 6 --a------ C:\WINDOWS\system32\24-02-12.dat
2007-02-16 21:09 6 --a------ C:\WINDOWS\system32\16-02-20.dat
2007-02-13 21:10 -------- d-------- C:\Program Files\google
2007-02-12 19:30 6 --a------ C:\WINDOWS\system32\12-02-18.dat
2007-02-06 14:17 6 --a------ C:\WINDOWS\system326-02-13.dat
2007-02-05 20:52 0 --a------ C:\ywcbxykm.exe
2007-02-05 20:51 6 --a------ C:\WINDOWS\system325-02-19.dat
2007-02-04 21:23 622703 --a------ C:\WINDOWS\system32\registrycleanersetup.exe
2007-02-04 19:52 6 --a------ C:\WINDOWS\system324-02-18.dat
2007-02-04 14:31 6 --a------ C:\WINDOWS\system324-02-13.dat
2007-02-03 20:39 -------- d-------- C:\Program Files\limewire
2007-02-03 18:44 6 --a------ C:\WINDOWS\system323-02-17.dat
2007-02-01 13:24 0 --a------ C:\wdigv.exe
2007-02-01 13:24 0 --a------ C:\tqex.exe
2007-02-01 13:24 0 --a------ C:\rjayw.exe
2007-02-01 13:22 6 --a------ C:\WINDOWS\system321-02-12.dat
2007-02-01 12:13 6 --a------ C:\WINDOWS\system321-02-11.dat
2007-02-01 01:10 0 --a------ C:\qaliew.exe
2007-02-01 01:10 0 --a------ C:\avhbtqbc.exe
2007-02-01 01:09 6 --a------ C:\WINDOWS\system321-02-00.dat
2007-01-31 20:20 6 --a------ C:\WINDOWS\system32\31-01-19.dat
2007-01-31 13:20 6 --a------ C:\WINDOWS\system32\31-01-12.dat
2007-01-30 20:12 6 --a------ C:\WINDOWS\system32\30-01-19.dat
2007-01-21 14:03 6 --a------ C:\WINDOWS\system32\21-01-13.dat
2007-01-20 22:18 6 --a------ C:\WINDOWS\system32\20-01-21.dat
2007-01-20 00:06 0 --a------ C:\xsxqdxkh.exe
2007-01-20 00:06 0 --a------ C:\laqquruw.exe
2007-01-20 00:06 0 --a------ C:\igcqdm.exe
2007-01-20 00:06 0 --a------ C:\caign.exe
2007-01-20 00:05 6 --a------ C:\WINDOWS\system32\19-01-23.dat
2007-01-19 22:19 6 --a------ C:\WINDOWS\system32\19-01-21.dat
2007-01-18 18:49 6 --a------ C:\WINDOWS\system32\18-01-17.dat
2007-01-18 14:18 6 --a------ C:\WINDOWS\system32\18-01-13.dat
2007-01-17 21:23 6 --a------ C:\WINDOWS\system32\17-01-20.dat
2007-01-17 19:23 6 --a------ C:\WINDOWS\system32\17-01-18.dat
2007-01-16 02:00 6 --a------ C:\WINDOWS\system32\16-01-01.dat
2007-01-15 21:48 6 --a------ C:\WINDOWS\system32\15-01-20.dat
2007-01-15 15:52 6 --a------ C:\WINDOWS\system32\15-01-14.dat
2007-01-14 20:33 6 --a------ C:\WINDOWS\system32\14-01-19.dat
2007-01-14 02:02 6 --a------ C:\WINDOWS\system32\14-01-01.dat
2007-01-14 01:53 6 --a------ C:\WINDOWS\system32\14-01-00.dat
2007-01-14 00:16 6 --a------ C:\WINDOWS\system32\13-01-23.dat
2007-01-13 13:26 6 --a------ C:\WINDOWS\system32\13-01-12.dat
2007-01-12 11:39 6 --a------ C:\WINDOWS\system32\12-01-10.dat
2007-01-11 13:47 6 --a------ C:\WINDOWS\system32\11-01-12.dat
2007-01-10 10:17 6 --a------ C:\WINDOWS\system32\10-01-09.dat
2007-01-06 22:03 6 --a------ C:\WINDOWS\system326-01-21.dat
2007-01-01 03:38 0 --a------ C:\vmbbeqsy.exe
2007-01-01 03:38 0 --a------ C:\skfyhkya.exe
2007-01-01 03:38 0 --a------ C:\pjfjj.exe
2007-01-01 03:38 0 --a------ C:\pidp.exe
2007-01-01 03:38 0 --a------ C:\mtywy.exe
2007-01-01 03:38 0 --a------ C:\hrqri.exe
2007-01-01 03:38 0 --a------ C:\cvgk.exe
2007-01-01 03:38 0 --a------ C:\abeg.exe
2007-01-01 03:37 6 --a------ C:\WINDOWS\system321-01-02.dat
2007-01-01 02:11 6 --a------ C:\WINDOWS\system321-01-01.dat
2007-01-01 01:41 6 --a------ C:\WINDOWS\system321-01-00.dat
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"MSConfig"="C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\MSConfig.exe /auto"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\1]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="1"
"hkey"="HKCU"
"command"="\"C:\\WINDOWS\\system32\\1.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ACEJ]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ACEJ"
"hkey"="HKCU"
"command"="\"C:\\Documents and Settings\\Deborah\\ACEJ.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="atiptaxx"
"hkey"="HKLM"
"command"="C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast!]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ashDisp"
"hkey"="HKLM"
"command"="C:\\PROGRA~1\\ALWILS~1\\Avast4\\ashDisp.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CaAvTray]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="CAVTray"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\CA\\eTrust Internet Security Suite\\eTrust EZ Antivirus\\CAVTray.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CaISSDT]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="caissdt"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\CA\\eTrust Internet Security Suite\\caissdt.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CAVRID]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="CAVRID"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\CA\\eTrust Internet Security Suite\\eTrust EZ Antivirus\\CAVRID.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ccApp"
"hkey"="HKLM"
"command"="\"c:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cpqset]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="cpqset"
"hkey"="HKLM"
"command"="C:\\Program Files\\HPQ\\Default Settings\\cpqset.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cwingllib]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="atllsimm"
"hkey"="HKCU"
"command"="C:\\WINDOWS\\system32\\atllsimm.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DUHJ]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="DUHJ"
"hkey"="HKCU"
"command"="\"C:\\Documents and Settings\\Deborah\\DUHJ.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eabconfg.cpl]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="EabServr"
"hkey"="HKLM"
"command"="C:\\Program Files\\HPQ\\Quick Launch Buttons\\EabServr.exe /Start"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Fiyf]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="c?rss"
"hkey"="HKCU"
"command"="C:\\Program Files\\Common Files\\??crosoft\\c?rss.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GLFC]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="GLFC"
"hkey"="HKCU"
"command"="\"C:\\Documents and Settings\\Deborah\\GLFC.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="AOLSoftware"
"hkey"="HKLM"
"command"="C:\\Program Files\\Common Files\\AOL\\1135747143\\ee\\AOLSoftware.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="HPWuSchd2"
"hkey"="HKLM"
"command"="C:\\Program Files\\Hp\\HP Software Update\\HPWuSchd2.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpWirelessAssistant]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="HP Wireless Assistant"
"hkey"="HKLM"
"command"="C:\\Program Files\\hpq\\HP Wireless Assistant\\HP Wireless Assistant.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IPHSend]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="IPHSend"
"hkey"="HKLM"
"command"="C:\\Program Files\\Common Files\\AOL\\IPHSend\\IPHSend.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="iTunesHelper"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\JFPL]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="JFPL"
"hkey"="HKCU"
"command"="\"C:\\Documents and Settings\\Deborah\\JFPL.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KDSC]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="KDSC"
"hkey"="HKCU"
"command"="\"C:\\Documents and Settings\\Deborah\\KDSC.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="dumprep 0 -k"
"hkey"="HKLM"
"command"="%systemroot%\\system32\\dumprep 0 -k"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\kmwf]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="kmwfm"
"hkey"="HKCU"
"command"="C:\\PROGRA~1\\COMMON~1\\kmwf\\kmwfm.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KOPU]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="KOPU"
"hkey"="HKCU"
"command"="\"C:\\Documents and Settings\\Deborah\\KOPU.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lcoinst]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="lcoinst"
"hkey"="HKCU"
"command"="C:\\WINDOWS\\system32\\lcoinst.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\llsymvb]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="fldmelds"
"hkey"="HKCU"
"command"="C:\\WINDOWS\\system32\\fldmelds.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lmjvservc]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="cliwdcjk"
"hkey"="HKLM"
"command"="cliwdcjk.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Utility]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Logi_MwX"
"hkey"="HKLM"
"command"="Logi_MwX.Exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LPDS]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="LPDS"
"hkey"="HKCU"
"command"="\"C:\\Documents and Settings\\Deborah\\LPDS.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LSBWatcher]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="lsburnwatcher"
"hkey"="HKLM"
"command"="c:\\hp\\drivers\\hplsbwatcher\\lsburnwatcher.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NFIK]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NFIK"
"hkey"="HKCU"
"command"="\"C:\\Documents and Settings\\Deborah\\NFIK.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHKR]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="PHKR"
"hkey"="HKCU"
"command"="\"C:\\Documents and Settings\\Deborah\\PHKR.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PicasaNet]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Hello"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Hello\\Hello.exe\" -b"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PlaxoUpdate]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="PlaxoHelper"
"hkey"="HKCU"
"command"="C:\\Program Files\\Plaxo\\2.11.1.5\\PlaxoHelper.exe -a"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="qttask"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SQJT]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SQJT"
"hkey"="HKCU"
"command"="\"C:\\Documents and Settings\\Deborah\\SQJT.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="jusched"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Java\\jre1.5.0_11\\bin\\jusched.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="GoogleToolbarNotifier"
"hkey"="HKCU"
"command"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.1128.5462\\GoogleToolbarNotifier.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec NetDriver Monitor]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SNDMon"
"hkey"="HKLM"
"command"="C:\\PROGRA~1\\SYMNET~1\\SNDMon.exe /Consumer"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SynTPEnh"
"hkey"="HKLM"
"command"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPLpr]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SynTPLpr"
"hkey"="HKLM"
"command"="C:\\Program Files\\Synaptics\\SynTP\\SynTPLpr.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TENF]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="TENF"
"hkey"="HKCU"
"command"="\"C:\\Documents and Settings\\Deborah\\TENF.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="realsched"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\URLLSTCK.exe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="UrlLstCk"
"hkey"="HKLM"
"command"="c:\\Program Files\\Norton Internet Security\\UrlLstCk.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UTRF]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="UTRF"
"hkey"="HKCU"
"command"="\"C:\\Documents and Settings\\Deborah\\UTRF.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vmmanager]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="vmmanager"
"hkey"="HKCU"
"command"="C:\\WINDOWS\\system32\\vmmanager.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\weoip]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="weoip"
"hkey"="HKCU"
"command"="\"C:\\WINDOWS\\system32\\weoip.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\wigvy]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="wigvy"
"hkey"="HKCU"
"command"="\"C:\\WINDOWS\\system32\\wigvy.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinInit]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="311046"
"hkey"="HKCU"
"command"="\"C:\\DOCUME~1\\Deborah\\LOCALS~1\\Temp\\311046.exe \" "
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\wqbujei]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="wqbujei"
"hkey"="HKCU"
"command"="\"C:\\WINDOWS\\system32\\wqbujei.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\wuosiu]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="wuosiu"
"hkey"="HKCU"
"command"="\"C:\\WINDOWS\\system32\\wuosiu.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{75A175BE-03E1-1033-0903-050503030001}]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Update"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Common Files\\{75A175BE-03E1-1033-0903-050503030001}\\Update.exe\" mc-110-12-0000797"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{75A175BE-03E2-1033-0903-050503030001}]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Update"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Common Files\\{75A175BE-03E2-1033-0903-050503030001}\\Update.exe\" mc-110-12-0000797"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{75A175BE-06FE-1033-0903-050503030001}]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Update"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Common Files\\{75A175BE-06FE-1033-0903-050503030001}\\Update.exe\" mc-110-12-0000797"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{75A175BE-07C5-1033-0903-050503030001}]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Update"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Common Files\\{75A175BE-07C5-1033-0903-050503030001}\\Update.exe\" mc-110-12-0000797"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"dispex.exe"=dword:00000002
"msoeacct.exe"=dword:00000002
"msencode.exe"=dword:00000002
"ipsecsnp.exe"=dword:00000002
"Ati HotKey Poller"=dword:00000002
"xmlprov"=dword:00000003
"WZCSVC"=dword:00000002
"wuauserv"=dword:00000002
"wscsvc"=dword:00000002
"WmiApSrv"=dword:00000003
"WmdmPmSN"=dword:00000003
"winmgmt"=dword:00000002
"WebClient"=dword:00000002
"W32Time"=dword:00000002
"VSS"=dword:00000003
"Viewpoint Manager Service"=dword:00000002
"VETMSGNT"=dword:00000002
"UPS"=dword:00000003
"upnphost"=dword:00000003
"UMWdf"=dword:00000002
"TrkWks"=dword:00000002
"Themes"=dword:00000002
"TermService"=dword:00000003
"TapiSrv"=dword:00000003
"SysmonLog"=dword:00000003
"SymWSC"=dword:00000002
"SwPrv"=dword:00000003
"stisvc"=dword:00000003
"SSDPSRV"=dword:00000003
"srservice"=dword:00000002
"Spooler"=dword:00000002
"SPBBCSvc"=dword:00000003
"SNDSrvc"=dword:00000003
"ShellHWDetection"=dword:00000002
"SharedAccess"=dword:00000002
"SENS"=dword:00000002
"seclogon"=dword:00000002
"Schedule"=dword:00000002
"SCardSvr"=dword:00000003
"SamSs"=dword:00000002
"RSVP"=dword:00000003
"RDSessMgr"=dword:00000003
"RasMan"=dword:00000003
"RasAuto"=dword:00000003
"ProtectedStorage"=dword:00000002
"PolicyAgent"=dword:00000002
"PlugPlay"=dword:00000002
"NtmsSvc"=dword:00000003
"NtLmSsp"=dword:00000003
"Nla"=dword:00000003
"Netman"=dword:00000003
"Netlogon"=dword:00000003
"MSIServer"=dword:00000003
"MSDTC"=dword:00000003
"mnmsrvc"=dword:00000003
"LmHosts"=dword:00000002
"LightScribeService"=dword:00000002
"lanmanworkstation"=dword:00000002
"lanmanserver"=dword:00000002
"ISSVC"=dword:00000002
"iPod Service"=dword:00000003
"ImapiService"=dword:00000003
"IDriverT"=dword:00000003
"HTTPFilter"=dword:00000003
"hpqwmi"=dword:00000003
"helpsvc"=dword:00000002
"gusvc"=dword:00000003
"FastUserSwitchingCompatibility"=dword:00000003
"EventSystem"=dword:00000003
"Eventlog"=dword:00000002
"ERSvc"=dword:00000002
"Dnscache"=dword:00000002
"dmserver"=dword:00000003
"dmadmin"=dword:00000003
"Dhcp"=dword:00000002
"CryptSvc"=dword:00000003
"COMSysApp"=dword:00000003
"CiSvc"=dword:00000003
"ccSetMgr"=dword:00000002
"ccPwdSvc"=dword:00000003
"ccProxy"=dword:00000002
"ccEvtMgr"=dword:00000002
"CAISafe"=dword:00000002
"Browser"=dword:00000002
"BITS"=dword:00000002
"avast! Web Scanner"=dword:00000003
"avast! Mail Scanner"=dword:00000003
"avast! Antivirus"=dword:00000002
"AudioSrv"=dword:00000002
"aswUpdSv"=dword:00000002
"aspnet_state"=dword:00000003
"AppMgmt"=dword:00000003
"ALG"=dword:00000003
"Alerter"=dword:00000002
"Adobe LM Service"=dword:00000003
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"UPnPMonitor"="{e57ce738-33e8-4c51-8354-bb4de9d215d1}"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter
LocalService REG_MULTI_SZ AlerterWebClientLmHostsRemoteRegistryupnphostSSDPSRV
NetworkService REG_MULTI_SZ DnsCache
DcomLaunch REG_MULTI_SZ DcomLaunchTermService
rpcss REG_MULTI_SZ RpcSs
imgsvc REG_MULTI_SZ StiSvc
termsvcs REG_MULTI_SZ TermService
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\Symantec NetDetect.job
********************************************************************
catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.netscanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\SYSTEM.SAV\info.bom 16384 bytes
C:\SYSTEM.SAV\INFO.US 4096 bytes
C:\SYSTEM.SAV\Logs
C:\SYSTEM.SAV\Logs\Cia.ini 155648 bytes
C:\SYSTEM.SAV\Logs\Info.bom 16384 bytes
C:\SYSTEM.SAV\Logs\Install.log 368640 bytes
C:\SYSTEM.SAV\Logs\Preinchk.log 4096 bytes
C:\SYSTEM.SAV\Logs\Sysinfo.log 294912 bytes
C:\SYSTEM.SAV\Logs\UIADUMP.EUE 4096 bytes
C:\SYSTEM.SAV\Logs\UIADUMP.FPP 4096 bytes
C:\SYSTEM.SAV\mszone.log 16384 bytes
C:\SYSTEM.SAV\PREINCHK.log 4096 bytes
C:\SYSTEM.SAV\REBOOT.ME 48 bytes
C:\SYSTEM.SAV\REGFLUSH.LOG 4096 bytes
C:\SYSTEM.SAV\RmDev.log 20480 bytes
C:\SYSTEM.SAV\SYSINFO.LOG 294912 bytes
C:\SYSTEM.SAV\SysInfo.US 294912 bytes
C:\SYSTEM.SAV\UTIL
C:\SYSTEM.SAV\UTIL\BOOTSEC.NT4 512 bytes
C:\SYSTEM.SAV\UTIL\BrandIt.Log 20480 bytes
C:\SYSTEM.SAV\UTIL\CHKIMAGE.exe 126976 bytes
C:\SYSTEM.SAV\UTIL\CIA.CDC 69632 bytes
C:\SYSTEM.SAV\UTIL\CIA.INI 81920 bytes
C:\SYSTEM.SAV\UTIL\cpqci.dll 122880 bytes
C:\SYSTEM.SAV\UTIL\cvacompg.exe 118784 bytes
C:\SYSTEM.SAV\UTIL\cvacompg.tmp 168 bytes
C:\SYSTEM.SAV\UTIL\DelDir.exe 36864 bytes
C:\SYSTEM.SAV\UTIL\delmodem.ini 184 bytes
C:\SYSTEM.SAV\UTIL\DELMPLNK.bat 88 bytes
C:\SYSTEM.SAV\UTIL\DELMPLNK.js 480 bytes
C:\SYSTEM.SAV\UTIL\DETECTOS.INI 408 bytes
C:\SYSTEM.SAV\UTIL\DNSP1.LOG 16384 bytes
C:\SYSTEM.SAV\UTIL\EISDTICON.log 32 bytes
C:\SYSTEM.SAV\UTIL\EVENTDEL.VBS 208 bytes
C:\SYSTEM.SAV\UTIL\FB_EIS.log 32 bytes
C:\SYSTEM.SAV\UTIL\hpqnt.dll 77824 bytes
C:\SYSTEM.SAV\UTIL\INSTALL.LOG 368640 bytes
C:\SYSTEM.SAV\UTIL\ISLOGCHK.EXE 110592 bytes
C:\SYSTEM.SAV\UTIL\ISLOGCHK.INI 4096 bytes
C:\SYSTEM.SAV\UTIL\mscu.log 168 bytes
C:\SYSTEM.SAV\UTIL\PININST.EXE 110592 bytes
C:\SYSTEM.SAV\UTIL\PININST.INI 4096 bytes
C:\SYSTEM.SAV\UTIL\PININST.LOG 4096 bytes
C:\SYSTEM.SAV\UTIL\POSTOOBE.LOG 24 bytes
C:\SYSTEM.SAV\UTIL\postproc.ini 536 bytes
C:\SYSTEM.SAV\UTIL\powerset.log 88 bytes
C:\SYSTEM.SAV\UTIL\PREINCHK.BAT 216 bytes
C:\SYSTEM.SAV\UTIL\PREINFO.INI 200 bytes
C:\SYSTEM.SAV\UTIL\PREINFO2.EXE 86016 bytes
C:\SYSTEM.SAV\UTIL\qlb.log 176 bytes
C:\SYSTEM.SAV\UTIL\random.ini 40 bytes
C:\SYSTEM.SAV\UTIL\REGDEV.EXE 106496 bytes
C:\SYSTEM.SAV\UTIL\REGDEV.INI 560 bytes
C:\SYSTEM.SAV\UTIL\sedinst.log 168 bytes
C:\SYSTEM.SAV\UTIL\STRTMENU.EXE 24576 bytes
C:\SYSTEM.SAV\UTIL\SWSET_B.INI 4096 bytes
C:\SYSTEM.SAV\UTIL\ticrdbus.log 32 bytes
C:\SYSTEM.SAV\UTIL\touchpad.log 192 bytes
C:\SYSTEM.SAV\UTIL\WINdvd.log 168 bytes
C:\SYSTEM.SAV\UTIL\wlassistant.log 176 bytes
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 60
********************************************************************
Completion time: 07-03-26 12:01:54