first of all, thanks for helping me mate
i followed your instructions and here are the logs that you needed
combofix log:
ComboFix 07-10-21.1** - DEMIL 2007-10-21 19:28:53.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.334 [GMT 10:00]
Running from: C:\Documents and Settings\DEMIL\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Start Menu\Live Safety Center.lnk
C:\Documents and Settings\All Users\Start Menu\Online Security Guide.lnk
C:\Documents and Settings\DEMIL\Application Data\addon.dat
C:\Documents and Settings\DEMIL\Desktop\Live Safety Center.lnk
C:\Documents and Settings\DEMIL\Desktop\Online Security Guide.lnk
C:\Documents and Settings\DEMIL\Favorites\Online Security Guide.lnk
C:\Documents and Settings\DEMIL\My Documents\RACLE~1
C:\Documents and Settings\DEMIL\My Documents\RACLE~1\s?chost.exe
C:\Documents and Settings\DEMIL\My Documents\SKS~1
C:\Documents and Settings\DEMIL\My Documents\SKS~1\??sks\
C:\Documents and Settings\DEMIL\My Documents\SKS~1\wuaclt.exe
C:\Documents and Settings\DEMIL\Start Menu\Programs\Outerinfo
C:\Documents and Settings\DEMIL\Start Menu\Programs\Outerinfo\Terms.lnk
C:\Documents and Settings\DEMIL\Start Menu\Programs\Outerinfo\Uninstall.lnk
C:\Program Files\Common Files\Yazzle1848OinUninstaller.exe
C:\Program Files\outerinfo
C:\Program Files\outerinfo\outerinfo.ico
C:\Program Files\outerinfo\Terms.rtf
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\avagcpvj.dll
C:\WINDOWS\system32\bkoqkmfe.exe
C:\WINDOWS\system32\drivers\sfsync03.sys
C:\WINDOWS\system32\fnts~1
C:\WINDOWS\system32\gahldpvw.dll
C:\WINDOWS\system32\kalpbzrh.dll
C:\WINDOWS\system32\mmkmsqyr.dllbox
C:\WINDOWS\system32\rtstv.bak1
C:\WINDOWS\system32\rtstv.bak2
C:\WINDOWS\system32\rtstv.ini
C:\WINDOWS\system32\uttss.bak1
C:\WINDOWS\system32\vtstr.dll
C:\WINDOWS\system32\zvnmznou.dllbox
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_SFSYNC03
-------\sfsync03
((((((((((((((((((((((((( Files Created from 2007-09-21 to 2007-10-21 )))))))))))))))))))))))))))))))
.
2007-10-21 19:26 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-10-19 18:46 35,840 --a------ C:\WINDOWS\system32\qomnonn.dll
2007-10-19 18:26 49,152 --a------ C:\WINDOWS\unezas.exe
2007-10-19 16:30 159,808 --a------ C:\WINDOWS\system32\pguard.dat
2007-10-19 16:30 77,928 --a------ C:\WINDOWS\system32\pghash.dat
2007-10-19 16:28 <DIR> d-------- C:\Program Files\ProcessGuard
2007-10-19 16:28 44,544 --a------ C:\WINDOWS\system32\procguard.dll
2007-10-19 16:28 26,688 --a------ C:\WINDOWS\system32\drivers\procguard.sys
2007-10-19 16:17 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-10-19 06:20 340,032 --a------ C:\WINDOWS\system32\mmkmsqyr.dll
2007-10-19 06:19 340,032 --a------ C:\WINDOWS\system32\lsiubrok.dll
2007-10-18 17:12 <DIR> d-------- C:\Program Files\Trojan Remover
2007-10-18 17:12 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Simply Super Software
2007-10-18 17:12 162,304 --a------ C:\WINDOWS\system32\ztvunrar36.dll
2007-10-18 17:12 77,312 --a------ C:\WINDOWS\system32\ztvunace26.dll
2007-10-18 17:12 69,632 --a------ C:\WINDOWS\system32\ztvcabinet.dll
2007-10-18 16:40 153,088 --a------ C:\WINDOWS\system32\UNRAR3.dll
2007-10-18 16:40 75,264 --a------ C:\WINDOWS\system32\unacev2.dll
2007-10-16 19:11 <DIR> d-------- C:\Documents and Settings\DEMIL\Application Data\Nero
2007-10-16 19:07 <DIR> d-------- C:\Program Files\Common Files\Nero
2007-10-16 19:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Nero
2007-10-16 19:06 35,840 --a------ C:\WINDOWS\system32\xxywxyv.dll
2007-10-16 18:35 <DIR> d-------- C:\Program Files\EZVideo
2007-10-10 18:54 584,192 -----c--- C:\WINDOWS\system32\dllcache\rpcrt4.dll
2007-10-09 18:11 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2007-10-09 18:09 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2007-10-09 03:04 128,896 -----c--- C:\WINDOWS\system32\dllcache\fltmgr.sys
2007-10-09 03:04 23,040 -----c--- C:\WINDOWS\system32\dllcache\fltmc.exe
2007-10-09 03:04 16,896 -----c--- C:\WINDOWS\system32\dllcache\fltlib.dll
2007-10-09 03:01 <DIR> d-------- C:\Program Files\MSXML 4.0
2007-10-08 19:03 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2007-10-07 14:30 <DIR> d-------- C:\Documents and Settings\Guest\Application Data\Bitdefender
2007-10-06 17:01 <DIR> d-------- C:\Documents and Settings\DEMIL\Application Data\Bitdefender
2007-10-06 16:53 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\BitDefender
2007-10-06 16:46 <DIR> d-------- C:\Program Files\hkSFV
2007-10-06 12:59 26,787 --a------ C:\WINDOWS\system32\drivers\vetmonnt.sys
2007-10-06 10:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-10-03 20:53 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Test Drive Unlimited
2007-10-03 20:35 <DIR> d-------- C:\Program Files\Atari
2007-10-03 16:14 <DIR> d-------- C:\Documents and Settings\Guest\Application Data\Roxio
2007-10-03 16:10 <DIR> d-------- C:\Documents and Settings\Guest\Application Data\Syntrillium
2007-09-30 22:18 <DIR> d-------- C:\Program Files\BIB DRV DEAD
2007-09-24 09:05 132,904 --a------ C:\WINDOWS\system32\drivers\imagesrv.sys
2007-09-24 09:05 11,304 --a------ C:\WINDOWS\system32\drivers\imagedrv.sys
2007-09-21 18:49 <DIR> d-------- C:\BMW M3 Challenge
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-21 09:34 81,984 ----a-w C:\WINDOWS\system32\bdod.bin
2007-10-20 00:06 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-10-19 14:10 --------- d-----w C:\Program Files\SUPERAntiSpyware
2007-10-19 14:10 --------- d-----w C:\Program Files\Common Files\Scanner
2007-10-18 06:34 --------- d-----w C:\Program Files\Google
2007-10-17 20:31 --------- d-----w C:\Documents and Settings\DEMIL\Application Data\BIB DRV DEAD
2007-10-16 09:07 --------- d-----w C:\Program Files\Nero
2007-10-16 09:02 --------- d-----w C:\Program Files\Common Files\Ahead
2007-10-12 06:46 --------- d-----w C:\Documents and Settings\DEMIL\Application Data\Roxio
2007-10-10 23:21 --------- d-----w C:\Program Files\Java
2007-10-08 13:04 --------- d-----w C:\Program Files\MSN Messenger
2007-10-08 09:38 96,256 ----a-w C:\WINDOWS\system32\drivers\sptd9357.sys
2007-10-06 02:58 879,832 ----a-w C:\WINDOWS\system32\drivers\VetEFile.sys
2007-10-06 02:58 108,360 ----a-w C:\WINDOWS\system32\drivers\VetEBoot.sys
2007-10-06 02:52 75,280 ----a-w C:\WINDOWS\system32\VetRedir.dll
2007-10-06 02:52 21,043 ----a-w C:\WINDOWS\system32\drivers\Vet-Filt.sys
2007-10-06 02:52 16,227 ----a-w C:\WINDOWS\system32\drivers\VetFDDNT.sys
2007-10-06 02:52 15,490 ----a-w C:\WINDOWS\system32\drivers\Vet-Rec.sys
2007-10-06 02:52 112,144 ----a-w C:\WINDOWS\AVShlExt.dll
2007-10-06 02:52 103,952 ----a-w C:\WINDOWS\UnVet32.exe
2007-10-06 02:52 --------- d-----w C:\Program Files\CA
2007-10-06 00:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg7
2007-10-05 06:31 --------- d-----w C:\Documents and Settings\DEMIL\Application Data\AVG7
2007-10-03 10:09 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-10-03 04:04 --------- d-----w C:\Documents and Settings\Guest\Application Data\AVG7
2007-10-01 23:10 --------- d-----w C:\Program Files\Anyplace Control
2007-09-30 23:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\DassaultSystemes
2007-09-30 23:21 --------- d-----w C:\Program Files\America's Army
2007-09-30 23:16 --------- d-----w C:\Program Files\Electronic Arts
2007-09-30 18:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\title 64 default software
2007-09-25 09:26 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2007-09-25 09:26 103,736 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
2007-09-19 23:59 972,072 ----a-w C:\WINDOWS\UNRecode.exe
2007-09-19 23:55 972,072 ----a-w C:\WINDOWS\UNNeroMediaHome.exe
2007-09-19 23:55 95,600 ----a-w C:\WINDOWS\system32\NeroCo.dll
2007-09-17 09:18 --------- d-----w C:\Documents and Settings\DEMIL\Application Data\Vso
2007-09-12 06:54 --------- d-----w C:\Program Files\EACom
2007-09-11 09:43 --------- d-----w C:\Program Files\coolpro2
2007-09-11 09:29 --------- d-----w C:\Documents and Settings\DEMIL\Application Data\Syntrillium
2007-09-10 13:24 --------- d-----w C:\Program Files\Spyware Doctor
2007-09-10 13:24 --------- d-----w C:\Program Files\NokiaFREE Unlock Codes Calculator
2007-09-10 13:24 --------- d-----w C:\Program Files\Fast Torrent
2007-09-10 13:24 --------- d-----w C:\Program Files\BitSpirit
2007-09-10 13:24 --------- d-----w C:\Documents and Settings\DEMIL\Application Data\Fast Torrent
2007-09-06 12:13 --------- d-----w C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-09-04 07:49 --------- d-----w C:\Documents and Settings\DEMIL\Application Data\Simply Super Software
2007-08-31 08:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\Poke Slow Loud Upload
2007-08-31 07:00 110,592 ----a-w C:\WINDOWS\system32\avgfwafu.dll
2007-08-28 13:16 --------- d-----w C:\Documents and Settings\LocalService\Application Data\AVG7
2007-08-28 13:16 --------- d-----w C:\Documents and Settings\LocalService\Application Data\AVG7
2007-08-28 13:16 --------- d-----w C:\Documents and Settings\LocalService\Application Data\AVG7
2007-08-27 08:05 --------- d-----w C:\Documents and Settings\All Users\Application Data\CA
2007-08-21 06:15 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-08-05 13:14 66,872 ----a-w C:\WINDOWS\system32\PnkBstrA.exe
2007-07-30 09:19 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-07-30 09:19 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-07-30 09:19 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-07-30 09:19 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
2007-07-30 09:19 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-07-30 09:19 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-07-30 09:19 1,712,984 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-07-30 09:18 33,624 ----a-w C:\WINDOWS\system32\wups.dll
2006-09-19 22:00 94,080 ----a-w C:\Documents and Settings\DEMIL\Application Data\ezplay.sys
2006-09-19 22:00 81,920 ----a-w C:\Documents and Settings\DEMIL\Application Data\ezpinst.exe
2006-07-31 06:10 47,360 ----a-w C:\Documents and Settings\DEMIL\Application Data\pcouffin.sys
2006-07-01 03:38 9,648 ----a-w C:\Program Files\autoexec.cfg
2006-07-01 03:38 0 ----a-w C:\Program Files\BanList.txt
2006-07-01 03:26 164 ----a-w C:\Program Files\display.cfg
2006-06-27 10:10 4,456 ----a-w C:\Program Files\INSTALL.LOG
2004-08-12 06:31 927,731,226 ----a-w C:\Program Files\game.rez
2004-08-12 03:58 1,814,528 ----a-w C:\Program Files\Lithtech.exe
2004-08-09 00:23 3,916 ----a-w C:\Program Files\ReadMe.txt
2004-06-28 01:22 7,668 ----a-w C:\Program Files\EULA.txt
2004-06-18 05:27 588 ----a-w C:\Program Files\Installer.ini
2004-06-17 02:01 2,260,992 ----a-w C:\Program Files\WWIISniper.exe
2003-10-14 04:35 134 ----a-w C:\Program Files\Support Website.url
2003-10-14 04:28 125 ----a-w C:\Program Files\Jarhead Games Website.url
2003-10-14 04:27 124 ----a-w C:\Program Files\Groove Games Website.url
2003-08-27 04:19 36,963 ----a-r C:\Program Files\Common Files\SM1updtr.dll
2003-08-08 05:35 61,440 ----a-w C:\Program Files\SndDrv.dll
2003-08-08 05:31 405,504 ----a-w C:\Program Files\Server.dll
2003-08-08 05:29 45,056 ----a-w C:\Program Files\ltmsg.dll
2003-08-08 04:56 491,520 ----a-w C:\Program Files\ServerDir.dll
2003-08-08 04:49 102,162 ----a-w C:\Program Files\Engine.rez
2001-09-28 07:00 164,864 ----a-w C:\Program Files\UNWISE.EXE
2007-02-01 09:11:51 478,295 --sh--w C:\WINDOWS\repair\bwevsr.bak1
2007-02-02 23:50:11 479,526 --sh--w C:\WINDOWS\repair\bwevsr.bak2
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}]
2007-10-19 06:20 340032 --a------ C:\WINDOWS\system32\mmkmsqyr.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{11A69AE4-FBED-4832-A2BF-45AF82825583}"= C:\WINDOWS\system32\mmkmsqyr.dll [2007-10-19 06:20 340032]
[HKEY_CLASSES_ROOT\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{11A69AE4-FBED-4832-A2BF-45AF82825583}"= C:\WINDOWS\system32\mmkmsqyr.dll [2007-10-19 06:20 340032]
[HKEY_CLASSES_ROOT\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2006-10-22 11:22]
"nwiz"="nwiz.exe" [2006-10-22 11:22 C:\WINDOWS\system32\nwiz.exe]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 17:07 C:\WINDOWS\system32\HdAShCut.exe]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2005-11-09 08:00]
"PWRISOVM.EXE"="C:\Program Files\PowerISO\PWRISOVM.EXE" [2006-06-06 00:06]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-09-01 13:49]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-09-05 10:28]
"RTHDCPL"="RTHDCPL.EXE" [2005-07-13 12:37 C:\WINDOWS\RTHDCPL.EXE]
"NvMediaCenter"="C:\WINDOWS\System32\NvMcTray.dll" [2006-10-22 11:22]
"RoxioDragToDisc"="C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe" [2005-03-08 21:13]
"SM1BG"="C:\WINDOWS\SM1BG.EXE" [2003-08-27 14:20]
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-08-03 23:51]
"eTrustPPAP"="C:\Program Files\CA\eTrust Internet Security Suite\eTrust PestPatrol Anti-Spyware\PPActiveDetection.exe" [2007-10-19 18:32]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" []
"CaISSDT"="C:\Program Files\CA\eTrust Internet Security Suite\caissdt.exe" [2006-04-21 14:42]
"CaAvTray"="C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVTray.exe" [2007-10-06 12:52]
"CAVRID"="C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVRID.exe" [2007-10-06 12:52]
"BDMCon"="C:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe" [2007-04-02 16:48]
"BDAgent"="C:\Program Files\Softwin\BitDefender10\bdagent.exe" [2007-03-26 15:49]
"NeroFilterCheck"="C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 15:57]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-09-20 09:51]
"TrojanScanner"="C:\Program Files\Trojan Remover\Trjscan.exe" [2007-08-29 20:30]
"!1_pgaccount"="C:\Program Files\ProcessGuard\pgaccount.exe" [2006-08-09 14:56]
"QOELOADER"="C:\Program Files\CA\eTrust EZ Armor\eTrust Anti-Spam\QSP-2.1.215.14\QOELoader.exe" [2007-10-19 18:26]
"NI.UGA6P_0001_N119M1510"="C:\DOCUME~1\DEMIL\LOCALS~1\Temp\qrjatydi.exe " [2007-10-21 19:40]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 11:54]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe" [2007-09-20 15:35]
"!1_ProcessGuard_Startup"="C:\Program Files\ProcessGuard\procguard.exe" [2006-08-09 16:22]
"Oiua"="C:\DOCUME~1\DEMIL\MYDOCU~1\SKS~1\wuaclt.exe" []
"Yjlan"="C:\Documents and Settings\DEMIL\My Documents\?racle\s?chost.exe" []
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"WindowsUpd"=0000
"SysUpd"=0000
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 21:05:26]
AutoCAD Startup Accelerator.lnk - C:\Program Files\Common Files\Autodesk Shared\acstart16.exe [2004-02-25 10:35:22]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 23:05:56]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explor er]
"NoInstrumentation"=0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mmkmsqyr]
mmkmsqyr.dll 2007-10-19 06:20 340032 C:\WINDOWS\system32\mmkmsqyr.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\qomnonn]
qomnonn.dll 2007-10-19 18:46 35840 C:\WINDOWS\system32\qomnonn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\rsvewb]
C:\WINDOWS\repair\rsvewb.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\xxywxyv]
xxywxyv.dll 2007-10-16 19:06 35840 C:\WINDOWS\system32\xxywxyv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\zvnmznou]
zvnmznou.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=sockspy.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\vtstr.dll
"Notification Packages"= :\WINDOWS\system32\srrstr.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxs ervice"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcore service"
R1 Cinemsup;Cinemsup;C:\WINDOWS\system32\drivers\Cinemsup.sys
R1 DVDVRRdr_xp;DVDVRRdr_xp;C:\WINDOWS\system32\drivers\DVDVRRdr_xp.sys
R1 LUMDriver;LUMDriver;\??\C:\WINDOWS\system32\drivers\LUMDriver.sys
R1 UDFReadr;UDFReadr;C:\WINDOWS\system32\drivers\UDFReadr.sys
R2 DCSPGSRV;DiamondCS ProcessGuard Service v3.410;"C:\Program Files\ProcessGuard\dcsuserprot.exe"
R2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3;C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
R2 procguard;procguard;\??\C:\WINDOWS\system32\drivers\procguard.sys
R3 GcKernel;Microsoft SideWinder Value Add - Filter Driver;C:\WINDOWS\system32\DRIVERS\GcKernel.sys
R3 HIDSwvd;Microsoft SideWinder Virtual HID Device Mini-Driver;C:\WINDOWS\system32\DRIVERS\HIDSwvd.sys
S3 GVCplDrv;GVCplDrv;C:\WINDOWS\system32\drivers\GVCplDrv.sys
S3 hamachi_oem;PlayLinc Adapter;C:\WINDOWS\system32\DRIVERS\gan_adapter.sys
S3 UWProSys;Process monitor.;\??\C:\Program Files\CyberDefender\AntiSpyware\uwprosys.sys
*Newly Created Service* - SHAREDACCESS
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CDA5FDF6-4F7A-BF04-B2A4-2D5FC81BB618}]
C:\Documents and Settings\DEMIL\Application Data\spooler.exe s
.
Contents of the 'Scheduled Tasks' folder
"2007-10-21 09:01:38 C:\WINDOWS\Tasks\AA3AF759916D6799.job"
.
**************************************************************************
catchme 0.3.1232 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-10-21 19:39:43
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-10-21 19:43:57 - machine was rebooted
.
--- E O F ---