new combofix log:
"Priit" - 07-05-30 9:44:13 Service Pack 2
ComboFix 07-04-25.4V - Running from: "C:\Documents and Settings\Priit\Desktop\siim\kaitse\"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\rpcc.dll
C:\WINDOWS\system32\taskmgr.com
C:\WINDOWS\regedit.com
((((((((((((((((((((((((((((((( Files Created from 2007-04-28 to 2007-05-30 ))))))))))))))))))))))))))))))))))
2007-05-07 18:33 19,968 --a------ C:\WINDOWS\system32\33196412ld.exe
2007-05-07 18:23 19,968 --a------ C:\WINDOWS\system32\2322632ld.exe
2007-05-07 18:12 19,968 --a------ C:\WINDOWS\system32\12398482ld.exe
2007-05-07 18:02 19,968 --a------ C:\WINDOWS\system32\2159612ld.exe
2007-05-07 17:52 19,968 --a------ C:\WINDOWS\system32\52107812ld.exe
2007-05-07 17:41 19,968 --a------ C:\WINDOWS\system32\41344962ld.exe
2007-05-07 17:24 19,968 --a------ C:\WINDOWS\system32\24467672ld.exe
2007-05-07 17:14 19,968 --a------ C:\WINDOWS\system32\1441262ld.exe
2007-05-06 18:10 <DIR> d-a------ C:\WINDOWS\zts2.exe
2007-05-06 18:10 <DIR> d-a------ C:\WINDOWS\system32\vcmgcd32.dll
2007-05-06 18:10 <DIR> d-a------ C:\WINDOWS\system32\iifgfgf.dll
2007-05-06 18:10 <DIR> d-a------ C:\WINDOWS\rundll16.exe
2007-05-06 18:10 <DIR> d-a------ C:\WINDOWS\rundl132.dll
2007-05-06 18:10 <DIR> d-a------ C:\WINDOWS\logo1_.exe
2007-05-06 18:05 146,432 --a------ C:\WINDOWS\R.COM
2007-05-06 18:05 135,680 --a------ C:\WINDOWS\system32\T.COM
2007-05-06 14:09 <DIR> d-------- C:\Program Files\Microsoft ActiveSync
2007-05-06 14:08 <DIR> d-------- C:\WINDOWS\SHELLNEW
2007-05-06 14:04 <DIR> dr-h----- C:\MSOCache
2007-05-06 10:26 <DIR> d-------- C:\avenger
2007-05-05 10:05 132,660 --a------ C:\WINDOWS\system32\hughyqaq.dll
2007-05-03 20:33 20,480 --a------ C:\WINDOWS\system32\33488082ld.exe
2007-05-03 20:23 20,480 --a------ C:\WINDOWS\system32\23313002ld.exe
2007-05-03 20:13 20,480 --a------ C:\WINDOWS\system32\13131712ld.exe
2007-05-03 20:02 20,480 --a------ C:\WINDOWS\system32\2554732ld.exe
2007-05-03 19:52 20,480 --a------ C:\WINDOWS\system32\52363022ld.exe
2007-05-03 19:42 20,480 --a------ C:\WINDOWS\system32\42168922ld.exe
2007-05-03 19:32 20,480 --a------ C:\WINDOWS\system32\31593142ld.exe
2007-05-03 19:21 20,480 --a------ C:\WINDOWS\system32\21423062ld.exe
2007-05-03 19:11 20,480 --a------ C:\WINDOWS\system32\11243482ld.exe
2007-05-03 19:01 20,480 --a------ C:\WINDOWS\system32\16992ld.exe
2007-05-03 18:50 20,480 --a------ C:\WINDOWS\system32\50482202ld.exe
2007-05-03 18:40 20,480 --a------ C:\WINDOWS\system32\40303822ld.exe
2007-05-03 18:30 20,480 --a------ C:\WINDOWS\system32\30129742ld.exe
2007-05-03 18:19 20,480 --a------ C:\WINDOWS\system32\19518212ld.exe
2007-05-03 18:09 20,480 --a------ C:\WINDOWS\system32\9337122ld.exe
2007-05-03 17:59 20,480 --a------ C:\WINDOWS\system32\59162442ld.exe
2007-05-03 17:49 20,480 --a------ C:\WINDOWS\system32\48592472ld.exe
2007-05-03 17:38 20,480 --a------ C:\WINDOWS\system32\38373832ld.exe
2007-05-03 17:28 20,480 --a------ C:\WINDOWS\system32\28155492ld.exe
2007-05-03 17:17 20,480 --a------ C:\WINDOWS\system32\17563382ld.exe
2007-05-03 17:07 20,480 --a------ C:\WINDOWS\system32\7351352ld.exe
2007-05-03 16:57 20,480 --a------ C:\WINDOWS\system32\57169562ld.exe
2007-05-03 16:46 20,480 --a------ C:\WINDOWS\system32\46562142ld.exe
2007-05-03 16:36 20,480 --a------ C:\WINDOWS\system32\36346102ld.exe
2007-05-03 16:26 20,480 --a------ C:\WINDOWS\system32\2672282ld.exe
2007-05-03 16:15 20,480 --a------ C:\WINDOWS\system32\15471662ld.exe
2007-05-03 16:05 20,480 --a------ C:\WINDOWS\system32\529772ld.exe
2007-05-03 15:55 20,480 --a------ C:\WINDOWS\system32\55115592ld.exe
2007-05-03 15:44 20,480 --a------ C:\WINDOWS\system32\44537912ld.exe
2007-05-03 15:34 20,480 --a------ C:\WINDOWS\system32\34349212ld.exe
2007-05-03 15:24 20,480 --a------ C:\WINDOWS\system32\24151302ld.exe
2007-05-03 15:13 20,480 --a------ C:\WINDOWS\system32\13543172ld.exe
2007-05-03 15:03 20,480 --a------ C:\WINDOWS\system32\3358582ld.exe
2007-05-03 14:53 20,480 --a------ C:\WINDOWS\system32\53168182ld.exe
2007-05-03 14:43 20,480 --a------ C:\WINDOWS\system32\42597502ld.exe
2007-05-01 22:32 20,480 --a------ C:\WINDOWS\system32\32298722ld.exe
2007-05-01 22:22 20,480 --a------ C:\WINDOWS\system32\2291602ld.exe
2007-05-01 22:11 20,480 --a------ C:\WINDOWS\system32\11483872ld.exe
2007-05-01 22:03 <DIR> d-------- C:\Program Files\Common Files\DriveCleaner Free
2007-05-01 22:01 20,480 --a------ C:\WINDOWS\system32\1283352ld.exe
2007-05-01 21:51 20,480 --a------ C:\WINDOWS\system32\5194152ld.exe
2007-05-01 21:40 20,480 --a------ C:\WINDOWS\system32\40477622ld.exe
2007-05-01 21:30 20,480 --a------ C:\WINDOWS\system32\30287812ld.exe
2007-05-01 21:20 20,480 --a------ C:\WINDOWS\system32\20102222ld.exe
2007-05-01 21:09 20,480 --a------ C:\WINDOWS\system32\9521032ld.exe
2007-05-01 20:59 20,480 --a------ C:\WINDOWS\system32\59329332ld.exe
2007-05-01 20:49 20,480 --a------ C:\WINDOWS\system32\4915742ld.exe
2007-05-01 20:38 20,480 --a------ C:\WINDOWS\system32\38567852ld.exe
2007-05-01 20:28 20,480 --a------ C:\WINDOWS\system32\2839272ld.exe
2007-05-01 20:18 20,480 --a------ C:\WINDOWS\system32\18142492ld.exe
2007-05-01 20:07 20,480 --a------ C:\WINDOWS\system32\7554292ld.exe
2007-05-01 19:57 20,480 --a------ C:\WINDOWS\system32\5731212ld.exe
2007-05-01 19:47 20,480 --a------ C:\WINDOWS\system32\47132132ld.exe
2007-05-01 19:36 20,480 --a------ C:\WINDOWS\system32\36545132ld.exe
2007-05-01 19:26 20,480 --a------ C:\WINDOWS\system32\26365952ld.exe
2007-05-01 19:16 20,480 --a------ C:\WINDOWS\system32\16191872ld.exe
2007-05-01 19:06 20,480 --a------ C:\WINDOWS\system32\5556102ld.exe
2007-05-01 18:55 20,480 --a------ C:\WINDOWS\system32\55376512ld.exe
2007-05-01 18:45 20,480 --a------ C:\WINDOWS\system32\45152262ld.exe
2007-05-01 18:34 20,480 --a------ C:\WINDOWS\system32\34568572ld.exe
2007-05-01 18:24 20,480 --a------ C:\WINDOWS\system32\24365252ld.exe
2007-05-01 18:14 20,480 --a------ C:\WINDOWS\system32\14184172ld.exe
2007-05-01 18:03 20,480 --a------ C:\WINDOWS\system32\3572732ld.exe
2007-05-01 17:53 20,480 --a------ C:\WINDOWS\system32\53391752ld.exe
2007-05-01 17:43 20,480 --a------ C:\WINDOWS\system32\43216372ld.exe
2007-05-01 17:33 20,480 --a------ C:\WINDOWS\system32\3334682ld.exe
2007-05-01 17:22 20,480 --a------ C:\WINDOWS\system32\22459202ld.exe
2007-05-01 17:12 20,480 --a------ C:\WINDOWS\system32\12285422ld.exe
2007-05-01 17:02 20,480 --a------ C:\WINDOWS\system32\289512ld.exe
2007-05-01 16:51 20,480 --a------ C:\WINDOWS\system32\51513132ld.exe
2007-05-01 16:41 20,480 --a------ C:\WINDOWS\system32\41332042ld.exe
2007-05-01 16:31 20,480 --a------ C:\WINDOWS\system32\31153162ld.exe
2007-05-01 16:20 20,480 --a------ C:\WINDOWS\system32\20572972ld.exe
2007-05-01 16:10 20,480 --a------ C:\WINDOWS\system32\10366852ld.exe
2007-05-01 16:00 20,480 --a------ C:\WINDOWS\system32157922ld.exe
2007-05-01 15:49 20,480 --a------ C:\WINDOWS\system32\49496922ld.exe
2007-05-01 15:39 20,480 --a------ C:\WINDOWS\system32\39317632ld.exe
2007-05-01 15:29 20,480 --a------ C:\WINDOWS\system32\29103192ld.exe
2007-05-01 15:18 20,480 --a------ C:\WINDOWS\system32\18457712ld.exe
2007-05-01 15:08 20,480 --a------ C:\WINDOWS\system32\8268012ld.exe
2007-04-30 23:34 20,480 --a------ C:\WINDOWS\system32\340852ld.exe
2007-04-30 23:23 20,480 --a------ C:\WINDOWS\system32\23284162ld.exe
2007-04-30 23:13 20,480 --a------ C:\WINDOWS\system32\1317552ld.exe
2007-04-30 23:02 20,480 --a------ C:\WINDOWS\system32\2281342ld.exe
2007-04-30 22:51 20,480 --a------ C:\WINDOWS\system32\51347152ld.exe
2007-04-30 22:41 20,480 --a------ C:\WINDOWS\system32\4121352ld.exe
2007-04-30 22:30 20,480 --a------ C:\WINDOWS\system32\30352542ld.exe
2007-04-30 22:20 20,480 --a------ C:\WINDOWS\system32\201632ld.exe
2007-04-30 22:09 20,480 --a------ C:\WINDOWS\system32\9584852ld.exe
2007-04-30 21:59 20,480 --a------ C:\WINDOWS\system32\59369212ld.exe
2007-04-30 21:49 20,480 --a------ C:\WINDOWS\system32\4975462ld.exe
2007-04-30 21:38 20,480 --a------ C:\WINDOWS\system32\38494082ld.exe
2007-04-30 21:28 20,480 --a------ C:\WINDOWS\system32\28271032ld.exe
2007-04-30 21:18 20,480 --a------ C:\WINDOWS\system32\1812732ld.exe
2007-04-30 21:07 20,480 --a------ C:\WINDOWS\system32\7305662ld.exe
2007-04-30 20:57 20,480 --a------ C:\WINDOWS\system32\5755272ld.exe
2007-04-30 20:46 20,480 --a------ C:\WINDOWS\system32\46443442ld.exe
2007-04-30 20:36 20,480 --a------ C:\WINDOWS\system32\36186842ld.exe
2007-04-30 20:25 20,480 --a------ C:\WINDOWS\system32\25536562ld.exe
2007-04-30 20:15 20,480 --a------ C:\WINDOWS\system32\15301792ld.exe
2007-04-30 20:05 20,480 --a------ C:\WINDOWS\system32\511392ld.exe
2007-04-30 19:54 20,480 --a------ C:\WINDOWS\system32\54522592ld.exe
2007-04-30 19:44 20,480 --a------ C:\WINDOWS\system32\44324882ld.exe
2007-04-30 19:34 20,480 --a------ C:\WINDOWS\system32\34141192ld.exe
2007-04-30 19:23 20,480 --a------ C:\WINDOWS\system32\23401772ld.exe
2007-04-30 19:13 20,480 --a------ C:\WINDOWS\system32\13165402ld.exe
2007-04-30 19:02 20,480 --a------ C:\WINDOWS\system32\2484872ld.exe
2007-04-30 18:52 20,480 --a------ C:\WINDOWS\system32\52252512ld.exe
2007-04-30 18:42 20,480 --a------ C:\WINDOWS\system32\425892ld.exe
2007-04-30 18:31 20,480 --a------ C:\WINDOWS\system32\31429752ld.exe
2007-04-30 18:21 20,480 --a------ C:\WINDOWS\system32\21199392ld.exe
2007-04-30 18:11 20,480 --a------ C:\WINDOWS\system32\10594972ld.exe
2007-04-30 18:00 20,480 --a------ C:\WINDOWS\system32323352ld.exe
2007-04-30 17:50 20,480 --a------ C:\WINDOWS\system32\50117732ld.exe
2007-04-30 17:39 20,480 --a------ C:\WINDOWS\system32\39442002ld.exe
2007-04-30 17:29 20,480 --a------ C:\WINDOWS\system32\29125722ld.exe
2007-04-30 17:18 20,480 --a------ C:\WINDOWS\system32\18481942ld.exe
2007-04-30 17:08 20,480 --a------ C:\WINDOWS\system32\828422ld.exe
2007-04-30 16:58 20,480 --a------ C:\WINDOWS\system32\5857082ld.exe
2007-04-30 10:09 <DIR> d-------- C:\ConvertTemp
2007-04-30 10:08 <DIR> d-------- C:\DOCUME~1\Priit\APPLIC~1\Samsung
2007-04-30 09:59 <DIR> d-------- C:\WINDOWS\system32\Samsung PC Studio Codecs
2007-04-30 09:45 94,000 --a------ C:\WINDOWS\system32\drivers\ss_mdm.sys
2007-04-30 09:45 8,304 --a------ C:\WINDOWS\system32\drivers\ss_mdfl.sys
2007-04-30 09:45 6,144 --a------ C:\WINDOWS\system32\drivers\ss_cmnt.sys
2007-04-30 09:45 6,144 --a------ C:\WINDOWS\system32\drivers\ss_cm.sys
2007-04-30 09:45 58,320 --a------ C:\WINDOWS\system32\drivers\ss_bus.sys
2007-04-30 09:45 5,808 --a------ C:\WINDOWS\system32\drivers\ss_whnt.sys
2007-04-30 09:45 5,808 --a------ C:\WINDOWS\system32\drivers\ss_wh.sys
2007-04-30 09:45 <DIR> d-------- C:\WINDOWS\system32\Samsung_USB_Drivers
2007-04-30 09:44 <DIR> d-------- C:\Program Files\Samsung
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
Rootkit driver pe386 is present. A rootkit scan is required
Rootkit driver pe386 is present. ... attempting disinfection
msguard ...... driver unloaded successfully.
2007-05-09 15:21 -------- d-------- C:\Program Files\morpheus
2007-05-06 13:12 -------- d--h----- C:\Program Files\installshield installation information
2007-05-06 00:38 -------- d-------- C:\Program Files\spywareguard
2007-05-06 00:37 -------- d-------- C:\Program Files\spywareblaster
2007-05-05 20:40 -------- d-------- C:\Program Files\msn games
2007-05-01 22:40 -------- d-------- C:\Program Files\Common Files\symantec shared
2007-05-01 22:37 -------- d-------- C:\Program Files\norton antivirus
2007-04-30 16:47 -------- d-------- C:\Program Files\symantec
2007-04-30 09:42 -------- d-------- C:\Program Files\Common Files\installshield
2007-04-26 22:32 20480 --a------ C:\WINDOWS\system32\32207202ld.exe
2007-04-26 22:21 20480 --a------ C:\WINDOWS\system32\2144442ld.exe
2007-04-26 22:11 20480 --a------ C:\WINDOWS\system32\11155802ld.exe
2007-04-26 22:00 20480 --a------ C:\WINDOWS\system32298622ld.exe
2007-04-26 21:50 20480 --a------ C:\WINDOWS\system32\49582542ld.exe
2007-04-26 21:39 20480 --a------ C:\WINDOWS\system32\39314222ld.exe
2007-04-26 21:29 20480 --a------ C:\WINDOWS\system32\2984472ld.exe
2007-04-26 21:18 20480 --a------ C:\WINDOWS\system32\18414552ld.exe
2007-04-26 21:08 20480 --a------ C:\WINDOWS\system32\8198712ld.exe
2007-04-26 20:57 20480 --a------ C:\WINDOWS\system32\57458802ld.exe
2007-04-26 20:47 20480 --a------ C:\WINDOWS\system32\47196892ld.exe
2007-04-26 20:36 20480 --a------ C:\WINDOWS\system32\36535692ld.exe
2007-04-26 20:26 20480 --a------ C:\WINDOWS\system32\26346392ld.exe
2007-04-26 20:16 20480 --a------ C:\WINDOWS\system32\1647832ld.exe
2007-04-26 20:05 20480 --a------ C:\WINDOWS\system32\5401352ld.exe
2007-04-26 19:55 20480 --a------ C:\WINDOWS\system32\55127332ld.exe
2007-04-26 19:44 20480 --a------ C:\WINDOWS\system32\44535322ld.exe
2007-04-26 19:34 20480 --a------ C:\WINDOWS\system32\34307872ld.exe
2007-04-26 19:24 20480 --a------ C:\WINDOWS\system32\2453082ld.exe
2007-04-26 19:13 20480 --a------ C:\WINDOWS\system32\13464482ld.exe
2007-04-26 19:03 20480 --a------ C:\WINDOWS\system32\3281892ld.exe
2007-04-26 18:53 20480 --a------ C:\WINDOWS\system32\52517242ld.exe
2007-04-26 18:42 20480 --a------ C:\WINDOWS\system32\42309412ld.exe
2007-04-26 18:41 20480 --a------ C:\WINDOWS\system32\41143112ld.exe
2007-04-26 18:36 20480 --a------ C:\WINDOWS\system32\3613582ld.exe
2007-04-26 18:32 20480 --a------ C:\WINDOWS\system32\3271242ld.exe
2007-04-26 18:21 20480 --a------ C:\WINDOWS\system32\21423362ld.exe
2007-04-26 18:11 20480 --a------ C:\WINDOWS\system32\11241272ld.exe
2007-04-26 18:00 20480 --a------ C:\WINDOWS\system32584572ld.exe
2007-04-26 17:50 20480 --a------ C:\WINDOWS\system32\50211102ld.exe
2007-04-26 17:40 20480 --a------ C:\WINDOWS\system32\39587562ld.exe
2007-04-26 17:29 20480 --a------ C:\WINDOWS\system32\29407572ld.exe
2007-04-26 17:19 20480 --a------ C:\WINDOWS\system32\19209362ld.exe
2007-04-26 17:09 20480 --a------ C:\WINDOWS\system32\927772ld.exe
2007-04-26 16:48 20480 --a------ C:\WINDOWS\system32\48211112ld.exe
2007-04-24 17:36 19968 --a------ C:\WINDOWS\system32\36416792ld.exe
2007-04-24 14:28 19968 --a------ C:\WINDOWS\system32\28378542ld.exe
2007-04-24 12:42 72957 --a------ C:\WINDOWS\nybtyhrtg.exe
2007-04-22 15:55 76560 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2007-04-22 12:18 196608 --a------ C:\WINDOWS\system32\ssleay32.dll
2007-04-22 12:18 1040384 --a------ C:\WINDOWS\system32\libeay32.dll
2007-04-22 12:15 -------- d-------- C:\Program Files\winamp
2007-04-18 19:12 2854400 --a------ C:\WINDOWS\system32\msi.dll
2007-03-31 09:45 4212 ---h----- C:\WINDOWS\system32\zllictbl.dat
2007-03-17 16:43 292864 --a------ C:\WINDOWS\system32\winsrv.dll
2007-03-09 00:02 75512 --a------ C:\WINDOWS\zllsputility.exe
2007-03-09 00:01 1087216 --a------ C:\WINDOWS\system32\zpeng24.dll
2007-03-08 18:36 577536 --a------ C:\WINDOWS\system32\user32.dll
2007-03-08 18:36 40960 --a------ C:\WINDOWS\system32\mf3216.dll
2007-03-08 18:36 281600 --a------ C:\WINDOWS\system32\gdi32.dll
2007-03-08 16:47 1843584 --a------ C:\WINDOWS\system32\win32k.sys
2007-03-05 21:54 4096 --a------ C:\WINDOWS\d3dx.dat
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{4A368E80-174F-4872-96B5-0B27DDD11DB2} C:\Program Files\SpywareGuard\dlprotect.dll
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
{E917494F-0F54-42BE-9BE4-99B5093911B3} C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP744\A0258874.dll [x]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"ezShieldProtector for Px"="C:\\WINDOWS\\system32\\ezSP_Px.exe"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_11\\bin\\jusched.exe\""
"ATIPTA"="atiptaxx.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"BluetoothAuthenticationAgent"="rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent"
"ZoneAlarm Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\""
"sacmemds"="C:\\WINDOWS\\system32\\smcntlwio.exe"
"WindowsService"="rundll32.exe \"C:\\WINDOWS\\system32\\hughyqaq.dll\",realset"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"BitComet"="\"C:\\Program Files\\BitLord\\BitLord.exe\""
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"RunNarrator"="Narrator.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
"{8BFA0939-92D5-4762-B188-2F45AE6D445B}"="System Registry Hook"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"UPnPMonitor"="{e57ce738-33e8-4c51-8354-bb4de9d215d1}"
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages REG_MULTI_SZ msv1_0\
Security Packages REG_MULTI_SZ kerberosmsv1_0schannelwdigest\
Notification Packages REG_MULTI_SZ scecli\
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Adobe Reader Speed Launch.lnk"
"backup"="C:\\WINDOWS\\pss\\Adobe Reader Speed Launch.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\Adobe\\ACROBA~1.0\\Reader\\READER~1.EXE "
"item"="Adobe Reader Speed Launch"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Advanced Tools Check]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ADVCHK"
"hkey"="HKLM"
"command"="C:\\PROGRA~1\\NORTON~1\\AdvTools\\ADVCHK.EXE"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AtiPTA]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Atiptaxx"
"hkey"="HKLM"
"command"="Atiptaxx.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ccApp"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccRegVfy]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ccRegVfy"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccRegVfy.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ctfmon"
"hkey"="HKCU"
"command"="C:\\WINDOWS\\system32\\ctfmon.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="daemon"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\D-Tools\\daemon.exe\" -lang 1033"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Easy-PrintToolBox]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="BJPSMAIN"
"hkey"="HKLM"
"command"="C:\\Program Files\\Canon\\Easy-PrintToolBox\\BJPSMAIN.EXE /logon"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ezShieldProtector for Px]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ezSP_Px"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\system32\\ezSP_Px.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="iTunesHelper"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="msmsgs"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NeroCheck"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NvCpl"
"hkey"="HKLM"
"command"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NVMCTRAY"
"hkey"="HKCU"
"command"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NVMCTRAY.DLL,NvTaskbarInit"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="nwiz"
"hkey"="HKLM"
"command"="nwiz.exe /install"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Oobpjma]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Cuowq"
"hkey"="HKLM"
"command"="C:\\Program Files\\Gvfa\\Cuowq.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="qttask"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="soundman"
"hkey"="HKLM"
"command"="soundman.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="jusched"
"hkey"="HKLM"
"command"="C:\\Program Files\\Java\\jre1.5.0_04\\bin\\jusched.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec NetDriver Monitor]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SNDMon"
"hkey"="HKLM"
"command"="C:\\PROGRA~1\\SYMNET~1\\SNDMon.exe /Consumer"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UserFaultCheck]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="dumprep 0 -u"
"hkey"="HKLM"
"command"="%systemroot%\\system32\\dumprep 0 -u"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\
LocalService REG_MULTI_SZ AlerterWebClientLmHostsRemoteRegistryupnphostSSDPSRV\
NetworkService REG_MULTI_SZ DnsCache\
DcomLaunch REG_MULTI_SZ DcomLaunchTermService\
rpcss REG_MULTI_SZ RpcSs\
imgsvc REG_MULTI_SZ StiSvc\
termsvcs REG_MULTI_SZ TermService\
WudfServiceGroup REG_MULTI_SZ WUDFSvc\
bthsvcs REG_MULTI_SZ BthServ\
********************************************************************
catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-05-30 09:54:10
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
********************************************************************
Completion time: 07-05-30 9:55:26 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 07-05-30 09:55