C:\WINDOWS\Downloaded Program Files\TriJinx.1.0.0.67\screens\hiscoresubmit.lua
C:\WINDOWS\Downloaded Program Files\TriJinx.1.0.0.67\screens\instructions.lua
C:\WINDOWS\Downloaded Program Files\TriJinx.1.0.0.67\screens\leveldesign.lua
C:\WINDOWS\Downloaded Program Files\TriJinx.1.0.0.67\screens\levelover.lua
C:\WINDOWS\Downloaded Program Files\TriJinx.1.0.0.67\screens\mainarcade.lua
C:\WINDOWS\Downloaded Program Files\TriJinx.1.0.0.67\screens\mainconfirm.lua
C:\WINDOWS\Downloaded Program Files\TriJinx.1.0.0.67\screens\maincontinue.lua
C:\WINDOWS\Downloaded Program Files\TriJinx.1.0.0.67\screens\maingames.lua
C:\WINDOWS\Downloaded Program Files\TriJinx.1.0.0.67\screens\mainpuzzle.lua
C:\WINDOWS\Downloaded Program Files\TriJinx.1.0.0.67\screens\maphelptip.lua
C:\WINDOWS\Downloaded Program Files\TriJinx.1.0.0.67\screens\options.lua
C:\WINDOWS\Downloaded Program Files\TriJinx.1.0.0.67\screens\pause.lua
C:\WINDOWS\Downloaded Program Files\TriJinx.1.0.0.67\screens\quitconfirm.lua
C:\WINDOWS\Downloaded Program Files\TriJinx.1.0.0.67\screens\start.lua
C:\WINDOWS\Downloaded Program Files\TriJinx.1.0.0.67\screens\storyplayer.lua
C:\WINDOWS\Downloaded Program Files\TriJinx.1.0.0.67\screens\style.lua
C:\WINDOWS\Downloaded Program Files\TriJinx.1.0.0.67\screens\upsell.lua
C:\WINDOWS\Downloaded Program Files\TriJinx.1.0.0.67\strings.xml
C:\WINDOWS\Downloaded Program Files\TriJinx.1.0.0.67\TriJinx.exe
C:\WINDOWS\Free Online Dating.ico
C:\WINDOWS\mgrs.exe
C:\WINDOWS\Spyware Remover.ico
C:\WINDOWS\system32\aeewmqhx.ini
C:\WINDOWS\system32\ajxtueuv.exe
C:\WINDOWS\system32\aunucdqg.ini
C:\WINDOWS\system32\bdixoukf.exe
C:\WINDOWS\system32\bszip.dll
C:\WINDOWS\system32\bvkwqowv.exe
C:\WINDOWS\system32\cbxvvuu.dll
C:\WINDOWS\system32\cqlmlbjp.exe
C:\WINDOWS\system32\dqavbrcy.exe
C:\WINDOWS\system32\drivers\blank.gif
C:\WINDOWS\system32\drivers\box_1.gif
C:\WINDOWS\system32\drivers\box_2.gif
C:\WINDOWS\system32\drivers\box_3.gif
C:\WINDOWS\system32\drivers\button_buynow.gif
C:\WINDOWS\system32\drivers\button_freescan.gif
C:\WINDOWS\system32\drivers\cell_bg.gif
C:\WINDOWS\system32\drivers\cell_footer.gif
C:\WINDOWS\system32\drivers\cell_header_block.gif
C:\WINDOWS\system32\drivers\cell_header_remove.gif
C:\WINDOWS\system32\drivers\cell_header_scan.gif
C:\WINDOWS\system32\drivers\detect.htm
C:\WINDOWS\system32\drivers\download_box.gif
C:\WINDOWS\system32\drivers\download_btn.jpg
C:\WINDOWS\system32\drivers\download_now_btn.gif
C:\WINDOWS\system32\drivers\footer_back.jpg
C:\WINDOWS\system32\drivers\header_1.gif
C:\WINDOWS\system32\drivers\header_2.gif
C:\WINDOWS\system32\drivers\header_3.gif
C:\WINDOWS\system32\drivers\header_4.gif
C:\WINDOWS\system32\drivers\header_red_bg.gif
C:\WINDOWS\system32\drivers\header_red_free_scan.gif
C:\WINDOWS\system32\drivers\header_red_free_scan_bg.gif
C:\WINDOWS\system32\drivers\header_red_protect_your_pc.gif
C:\WINDOWS\system32\drivers\infected.gif
C:\WINDOWS\system32\drivers\main_back.gif
C:\WINDOWS\system32\drivers\perfect_cleaner_box.jpg
C:\WINDOWS\system32\drivers\product_1_header.gif
C:\WINDOWS\system32\drivers\product_1_name_small.gif
C:\WINDOWS\system32\drivers\product_2_header.gif
C:\WINDOWS\system32\drivers\product_2_name_small.gif
C:\WINDOWS\system32\drivers\product_3_header.gif
C:\WINDOWS\system32\drivers\product_3_name_small.gif
C:\WINDOWS\system32\drivers\product_features.gif
C:\WINDOWS\system32\drivers\pt.htm
C:\WINDOWS\system32\drivers\rating.gif
C:\WINDOWS\system32\drivers\s_detect.htm
C:\WINDOWS\system32\drivers\screenshot.jpg
C:\WINDOWS\system32\drivers\sep_hor.gif
C:\WINDOWS\system32\drivers\sep_vert.gif
C:\WINDOWS\system32\drivers\shadow.jpg
C:\WINDOWS\system32\drivers\shadow_bg.gif
C:\WINDOWS\system32\drivers\spacer.gif
C:\WINDOWS\system32\drivers\spy_away_box.jpg
C:\WINDOWS\system32\drivers\star.gif
C:\WINDOWS\system32\drivers\star_gray.gif
C:\WINDOWS\system32\drivers\star_gray_small.gif
C:\WINDOWS\system32\drivers\star_small.gif
C:\WINDOWS\system32\drivers\style.css
C:\WINDOWS\system32\drivers\v.gif
C:\WINDOWS\system32\drivers\warning_icon.gif
C:\WINDOWS\system32\drivers\win_logo.gif
C:\WINDOWS\system32\drivers\x.gif
C:\WINDOWS\system32\drvdodr.dll
C:\WINDOWS\system32\drvlowr.dll
C:\WINDOWS\system32\duwffqbg.exe
C:\WINDOWS\system32\eehrjrft.exe
C:\WINDOWS\system32\eynbhoph.dll
C:\WINDOWS\system32\ffjacdcm.exe
C:\WINDOWS\system32\fuoirenp.exe
C:\WINDOWS\system32\fxqyaehx.dll
C:\WINDOWS\system32\gjjlm.bak1
C:\WINDOWS\system32\gjjlm.bak2
C:\WINDOWS\system32\gjjlm.ini
C:\WINDOWS\system32\gjjlm.ini2
C:\WINDOWS\system32\gjjlm.tmp
C:\WINDOWS\system32\gqdcunua.dll
C:\WINDOWS\system32\gyfrjtce.exe
C:\WINDOWS\system32\heifyabd.exe
C:\WINDOWS\system32\hjjsabxd.dll
C:\WINDOWS\system32\hpohbnye.ini
C:\WINDOWS\system32\hxlkslyh.dll
C:\WINDOWS\system32\hylsklxh.ini
C:\WINDOWS\system32\iwaqfspf.exe
C:\WINDOWS\system32\jlbmhkhn.exe
C:\WINDOWS\system32\kellvwcl.exe
C:\WINDOWS\system32\kldxqcqh.exe
C:\WINDOWS\system32\lidkfqkv
C:\WINDOWS\system32\lidkfqkv\bg1.gif
C:\WINDOWS\system32\lidkfqkv\bgtop.gif
C:\WINDOWS\system32\lidkfqkv\bottom1.gif
C:\WINDOWS\system32\lidkfqkv\essentials.gif
C:\WINDOWS\system32\lidkfqkv\icon1.ico
C:\WINDOWS\system32\lidkfqkv\install1.gif
C:\WINDOWS\system32\lidkfqkv\left1.gif
C:\WINDOWS\system32\lidkfqkv\li.gif
C:\WINDOWS\system32\lidkfqkv\lidkfqkv1.exe
C:\WINDOWS\system32\lidkfqkv\lidkfqkv2.exe
C:\WINDOWS\system32\lidkfqkv\lidkfqkv3.exe
C:\WINDOWS\system32\lidkfqkv\logo.gif
C:\WINDOWS\system32\lidkfqkv\main.htm
C:\WINDOWS\system32\lidkfqkv\mainframe.htm
C:\WINDOWS\system32\lidkfqkv\reinstall1.gif
C:\WINDOWS\system32\lidkfqkv\right1.gif
C:\WINDOWS\system32\lidkfqkv\s1.htm
C:\WINDOWS\system32\lidkfqkv\s2.htm
C:\WINDOWS\system32\lidkfqkv\s3.htm
C:\WINDOWS\system32\lidkfqkv\SMTop1.gif
C:\WINDOWS\system32\lidkfqkv\SMTop2.gif
C:\WINDOWS\system32\lidkfqkv\SMTop3.gif
C:\WINDOWS\system32\lidkfqkv\SMTop4.gif
C:\WINDOWS\system32\lidkfqkv\soft1_off.gif
C:\WINDOWS\system32\lidkfqkv\soft1_off_ext.gif
C:\WINDOWS\system32\lidkfqkv\soft1_on.gif
C:\WINDOWS\system32\lidkfqkv\soft1_on_ext.gif
C:\WINDOWS\system32\lidkfqkv\soft2_off.gif
C:\WINDOWS\system32\lidkfqkv\soft2_off_ext.gif
C:\WINDOWS\system32\lidkfqkv\soft2_on.gif
C:\WINDOWS\system32\lidkfqkv\soft2_on_ext.gif
C:\WINDOWS\system32\lidkfqkv\soft3_off.gif
C:\WINDOWS\system32\lidkfqkv\soft3_off_ext.gif
C:\WINDOWS\system32\lidkfqkv\soft3_on.gif
C:\WINDOWS\system32\lidkfqkv\soft3_on_ext.gif
C:\WINDOWS\system32\lidkfqkv\softbottom_off.gif
C:\WINDOWS\system32\lidkfqkv\softbottom_on.gif
C:\WINDOWS\system32\lidkfqkv\softleft_off.gif
C:\WINDOWS\system32\lidkfqkv\softleft_on.gif
C:\WINDOWS\system32\lidkfqkv\top1.gif
C:\WINDOWS\system32\lidkfqkv\top2.gif
C:\WINDOWS\system32\lidkfqkv\turnoff1.gif
C:\WINDOWS\system32\lidkfqkv\turnon1.gif
C:\WINDOWS\system32\lytfpseu.dll
C:\WINDOWS\system32\mljjg.dll
C:\WINDOWS\system32\myhaveio.exe
C:\WINDOWS\system32\orvunoce.exe
C:\WINDOWS\system32\oxujchmh.exe
C:\WINDOWS\system32\patqtsqn.exe
C:\WINDOWS\system32\qbvtkhxp.dllbox
C:\WINDOWS\system32\quruatlf.exe
C:\WINDOWS\system32\ryeyqtly.dll
C:\WINDOWS\system32\tccdhubu.exe
C:\WINDOWS\system32\tnmfvlnc.exe
C:\WINDOWS\system32\uespftyl.ini
C:\WINDOWS\system32\uhuuoabf.exe
C:\WINDOWS\system32\ulsifcbl.exe
C:\WINDOWS\system32\wiimffaq.exe
C:\WINDOWS\system32\winhab32.dll
C:\WINDOWS\system32\wqinuair.exe
C:\WINDOWS\system32\xheayqxf.ini
C:\WINDOWS\system32\xhqmweea.dll
C:\WINDOWS\system32\yaoxcpni.exe
C:\WINDOWS\system32\yctmnduj.exe
C:\WINDOWS\system32\yltqyeyr.ini
C:\WINDOWS\xpupdate.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_DOMAINSERVICE
-------\DomainService
((((((((((((((((((((((((( Files Created from 2007-10-02 to 2007-11-02 )))))))))))))))))))))))))))))))
.
2007-11-02 11:16 <DIR> d-------- C:\Program Files\MalwareAlarm
2007-11-02 11:16 33,792 --a------ C:\WINDOWS\system32\khfgfca.dll
2007-11-02 11:16 21,504 --a------ C:\WINDOWS\system32\aivskurq.dll
2007-11-02 11:15 <DIR> d-------- C:\Program Files\Vofdyzgg
2007-11-02 11:15 <DIR> d-------- C:\Program Files\rabktcby
2007-11-02 11:15 103,936 --a------ C:\WINDOWS\system32\drvlow.dll
2007-11-02 11:13 82,496 --a------ C:\WINDOWS\system32\icnqjijl.dll
2007-11-02 11:11 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-11-01 11:47 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2007-11-01 11:47 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2007-11-01 11:47 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-10-24 12:33 <DIR> d-------- C:\Program Files\E404 Helper
2007-10-24 11:10 36,352 --a------ C:\WINDOWS\system32\nnnoolk.dll
2007-10-19 16:07 34,304 --a------ C:\WINDOWS\system32\awttrro.dll
2007-10-19 15:29 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-10-18 08:23 340,032 --a------ C:\WINDOWS\system32\yfmbcgdr.dll
2007-10-18 08:23 340,032 --a------ C:\WINDOWS\system32\qbvtkhxp.dll
2007-10-16 14:41 19,456 --a------ C:\Program Files\ukr.exe
2007-10-16 14:37 <DIR> d-------- C:\WINDOWS\system32\mclsphlr
2007-10-16 14:36 94,208 --a------ C:\WINDOWS\system32\mclsp.dll
2007-10-16 14:36 90,112 --a------ C:\WINDOWS\system32\mcrtl32.dll
2007-10-16 14:36 32,768 --a------ C:\WINDOWS\system32\instlsp.exe
2007-10-16 14:36 11,264 --a------ C:\WINDOWS\system32\sporder.dll
2007-10-16 11:56 552 --a------ C:\WINDOWS\system32\d3d8caps.dat
2007-10-16 08:23 28,679 --------- C:\Program Files\c_setup.exe
2007-10-16 08:19 <DIR> d-------- C:\Program Files\Adsense Helper Object
2007-10-15 12:44 <DIR> d-------- C:\WINDOWS\system32\HouseCall 6.6
2007-10-15 12:44 <DIR> d-------- C:\Documents and Settings\Caty\Application Data\HouseCall 6.6
2007-10-12 14:40 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2007-10-12 14:39 <DIR> d-------- C:\Documents and Settings\Caty\.housecall6.6
2007-10-12 11:48 <DIR> d-------- C:\Program Files\Real
2007-10-10 11:29 9,728 --a------ C:\Program Files\hlpsrv.exe
2007-10-10 11:28 102,400 --a------ C:\WINDOWS\system32\drvdod.dll
2007-10-10 11:28 31,232 --a------ C:\WINDOWS\system32\efccdcd.dll
2007-10-10 10:30 147,456 --a------ C:\WINDOWS\AVUNTOOL.EXE
2007-10-10 03:54 582,656 --------- C:\WINDOWS\system32\dllcache\rpcrt4.dll
2007-10-03 10:55 <DIR> d-------- C:\Documents and Settings\Caty\Application Data\Alien Skin
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-02 15:33 --------- d-----w C:\Documents and Settings\Caty\Application Data\U3
2007-10-22 14:14 --------- d-----w C:\Documents and Settings\Caty\Application Data\AdobeUM
2007-10-17 21:15 --------- d-----w C:\Program Files\QuickTime
2007-10-16 19:36 --------- d-----w C:\Program Files\McAfee.com
2007-10-16 19:36 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee.com
2007-10-16 18:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee.com Personal Firewall
2007-09-28 21:01 --------- d-----w C:\Program Files\Apple Software Update
2007-09-28 21:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
2007-09-24 18:40 --------- d-----w C:\Program Files\A Tech Group
2007-08-21 06:15 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-08-21 06:15 683,520 ------w C:\WINDOWS\system32\dllcache\inetcomm.dll
2007-08-20 10:04 824,832 ----a-w C:\WINDOWS\system32\dllcache\wininet.dll
2007-08-20 10:04 671,232 ----a-w C:\WINDOWS\system32\dllcache\mstime.dll
2007-08-20 10:04 63,488 ------w C:\WINDOWS\system32\dllcache\icardie.dll
2007-08-20 10:04 6,058,496 ------w C:\WINDOWS\system32\dllcache\ieframe.dll
2007-08-20 10:04 52,224 ------w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-08-20 10:04 477,696 ----a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-08-20 10:04 459,264 ------w C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-08-20 10:04 44,544 ------w C:\WINDOWS\system32\dllcache\iernonce.dll
2007-08-20 10:04 384,512 ------w C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-08-20 10:04 383,488 ------w C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-08-20 10:04 3,584,512 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-08-20 10:04 27,648 ----a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-08-20 10:04 267,776 ------w C:\WINDOWS\system32\dllcache\iertutil.dll
2007-08-20 10:04 232,960 ------w C:\WINDOWS\system32\dllcache\webcheck.dll
2007-08-20 10:04 230,400 ------w C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-08-20 10:04 214,528 ----a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-08-20 10:04 193,024 ----a-w C:\WINDOWS\system32\dllcache\msrating.dll
2007-08-20 10:04 153,088 ------w C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-08-20 10:04 132,608 ----a-w C:\WINDOWS\system32\dllcache\extmgr.dll
2007-08-20 10:04 124,928 ------w C:\WINDOWS\system32\dllcache\advpack.dll
2007-08-20 10:04 105,984 ------w C:\WINDOWS\system32\dllcache\url.dll
2007-08-20 10:04 102,400 ------w C:\WINDOWS\system32\dllcache\occache.dll
2007-08-20 10:04 1,152,000 ----a-w C:\WINDOWS\system32\dllcache\urlmon.dll
2007-08-17 10:21 625,152 ------w C:\WINDOWS\system32\dllcache\iexplore.exe
2007-08-17 10:20 63,488 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-08-17 10:20 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-08-17 07:34 161,792 ------w C:\WINDOWS\system32\dllcache\ieakui.dll
2007-05-02 20:31:54 56 --sh--r C:\WINDOWS\system32\25414C4A3D.sys
2007-05-02 20:31:56 3,350 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0DFCFB5E-3974-3338-8F09-0B2552E546A8}]
2007-11-02 11:15 94208 --a------ C:\Program Files\Vofdyzgg\kilhykfu.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{226f2238-f367-4e92-a9ba-44c7eb18ad04}]
2007-11-02 11:13 82496 --a------ C:\WINDOWS\system32\icnqjijl.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3E4A0D7B-DD02-4A3F-A04C-0B3FF84AD935}]
2007-10-24 11:10 36352 --a------ C:\WINDOWS\system32\nnnoolk.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}]
2007-10-18 08:23 340032 --a------ C:\WINDOWS\system32\qbvtkhxp.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{11A69AE4-FBED-4832-A2BF-45AF82825583}"= C:\WINDOWS\system32\qbvtkhxp.dll [2007-10-18 08:23 340032]
[HKEY_CLASSES_ROOT\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-04-05 07:22]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-04-05 07:19]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2005-04-05 07:23]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 13:03]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-06-23 17:31]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-08-13 11:20]
"VSOCheckTask"="C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" [2005-07-08 19:18]
"OASClnt"="C:\Program Files\McAfee.com\VSO\oasclnt.exe" [2005-08-11 23:02]
"MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\mcagent.exe" [2005-09-22 19:29]
"MCUpdateExe"="C:\PROGRA~1\mcafee.com\agent\mcupdate.exe" [2006-01-11 13:05]
"MSKDetectorExe"="C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe" [2006-11-07 15:49]
"MSKAGENTEXE"="C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe" [2005-09-26 10:26]
"VirusScan Online"="C:\Program Files\McAfee.com\VSO\mcvsshld.exe" [2005-08-10 13:49]
"MPFExe"="C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe" [2005-11-11 18:00]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2005-01-12 14:54]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-02-16 23:11]
"YOP"="C:\PROGRA~1\Yahoo!\YOP\yop.exe" [2006-07-21 10:43]
"MPSExe"="c:\PROGRA~1\mcafee.com\mps\mscifapp.exe" [2005-07-26 14:49]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 06:00]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-07 10:39]
"MalwareAlarm"="C:\Program Files\MalwareAlarm\MalwareAlarm.exe" [2007-11-02 11:16]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-05-15 02:19:50]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2004-05-28 22:31:38]
HP Image Zone Fast Start.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2004-05-28 23:06:36]
QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2007-01-22 14:21:00]
Service Manager.lnk - C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2005-05-03 23:07:32]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{3E4A0D7B-DD02-4A3F-A04C-0B3FF84AD935}"= C:\WINDOWS\system32\nnnoolk.dll [2007-10-24 11:10 36352]
[HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="C:\\WINDOWS\\system32\\vvgeowbv.exe,C:\\WINDOWS\\system32\\userinit.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\nnnoolk]
nnnoolk.dll 2007-10-24 11:10 36352 C:\WINDOWS\system32\nnnoolk.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\qbvtkhxp]
qbvtkhxp.dll 2007-10-18 08:23 340032 C:\WINDOWS\system32\qbvtkhxp.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\mljjg.dll
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\LaunchU3.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{92c23592-de0e-11db-9c0d-001320ea09ff}]
\Shell\AutoRun\command - E:\LaunchU3.exe
.
Contents of the 'Scheduled Tasks' folder
"2007-11-01 17:18:00 C:\WINDOWS\Tasks\Disk Cleanup.job"
- C:\WINDOWS\system32\cleanmgr.exe
"2007-11-02 16:52:08 C:\WINDOWS\Tasks\McAfee.com Scan for Viruses - My Computer (MARIA-Caty).job"
- c:\program files\mcafee.com\vso\mcmnhdlr.exe
.
**************************************************************************
catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-11-02 11:53:36
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-02 11:56:51 - machine was rebooted
.
--- E O F ---