Ještě jsem nechal dojet ZoneAlarm....
Avenger:
Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\atjkhkwj
*******************
Script file located at: \??\C:\Program Files\qvhtmmct.txt
Script file opened successfully.
Script file read successfully
Backups directory opened successfully at C:\Avenger
*******************
Beginning to process script file:
Error: C:\WINDOWS\system32\systems.txt is a folder, not a file!
Deletion of file C:\WINDOWS\system32\systems.txt failed!
Could not process line:
C:\WINDOWS\system32\systems.txt
Status: 0xc00000ba
Error: C:\WINDOWS\system32\iifgfgf.dll is a folder, not a file!
Deletion of file C:\WINDOWS\system32\iifgfgf.dll failed!
Could not process line:
C:\WINDOWS\system32\iifgfgf.dll
Status: 0xc00000ba
Error: C:\WINDOWS\rundll16.exe is a folder, not a file!
Deletion of file C:\WINDOWS\rundll16.exe failed!
Could not process line:
C:\WINDOWS\rundll16.exe
Status: 0xc00000ba
Error: C:\WINDOWS\rundl132.dll is a folder, not a file!
Deletion of file C:\WINDOWS\rundl132.dll failed!
Could not process line:
C:\WINDOWS\rundl132.dll
Status: 0xc00000ba
Error: C:\WINDOWS\logo1_.exe is a folder, not a file!
Deletion of file C:\WINDOWS\logo1_.exe failed!
Could not process line:
C:\WINDOWS\logo1_.exe
Status: 0xc00000ba
File C:\WINDOWS\system32\drivers\fidbox.dat deleted successfully.
File C:\WINDOWS\R.COM not found!
Deletion of file C:\WINDOWS\R.COM failed!
Could not process line:
C:\WINDOWS\R.COM
Status: 0xc0000034
File C:\WINDOWS\system32\T.COM not found!
Deletion of file C:\WINDOWS\system32\T.COM failed!
Could not process line:
C:\WINDOWS\system32\T.COM
Status: 0xc0000034
File C:\WINDOWS\system32\drivers\fidbox2.dat deleted successfully.
Error: C:\WINDOWS\system32\vcmgcd32.dll is a folder, not a file!
Deletion of file C:\WINDOWS\system32\vcmgcd32.dll failed!
Could not process line:
C:\WINDOWS\system32\vcmgcd32.dll
Status: 0xc00000ba
Error: C:\WINDOWS\msdownld.tmp is a folder, not a file!
Deletion of file C:\WINDOWS\msdownld.tmp failed!
Could not process line:
C:\WINDOWS\msdownld.tmp
Status: 0xc00000ba
Completed script processing.
*******************
Finished! Terminate.
ComboFix:
ComboFix 07-11-08.1 - Administrator 2007-11-17 15:24:38.5 - NTFSx86 MINIMAL
Running from: D:\Downloads\scanvirů\ComboFix.exe
.
((((((((((((((((((((((((( Files Created from 2007-10-17 to 2007-11-17 )))))))))))))))))))))))))))))))
.
2007-11-17 15:18 213,280 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2007-11-17 15:18 1,824 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2007-11-17 13:58 <DIR> d-------- C:\Documents and Settings\LocalService\Plocha
2007-11-17 13:25 <DIR> d-------- C:\Documents and Settings\Administrator\DoctorWeb
2007-11-17 11:57 <DIR> d-a------ C:\WINDOWS\zts2.exe
2007-11-17 11:57 <DIR> d-a------ C:\WINDOWS\system32\vcmgcd32.dll
2007-11-17 11:57 <DIR> d-a------ C:\WINDOWS\system32\systems.txt
2007-11-17 11:57 <DIR> d-a------ C:\WINDOWS\system32\iifgfgf.dll
2007-11-17 11:57 <DIR> d-a------ C:\WINDOWS\rundll16.exe
2007-11-17 11:57 <DIR> d-a------ C:\WINDOWS\rundl132.dll
2007-11-17 11:57 <DIR> d-a------ C:\WINDOWS\logo1_.exe
2007-11-17 11:50 <DIR> d-------- C:\Program Files\CCleaner
2007-11-16 22:25 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-11-16 21:51 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-11-16 21:51 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\TuneUp Software
2007-11-16 21:51 <DIR> d-------- C:\Documents and Settings\Administrator\Data aplikací\TuneUp Software
2007-11-16 21:51 29,704 --a------ C:\WINDOWS\system32\uxtuneup.dll
2007-11-16 20:51 <DIR> d-------- C:\Documents and Settings\Administrator\Data aplikací\Talkback
2007-11-16 19:07 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\ATI
2007-11-16 17:03 <DIR> d-------- C:\Program Files\SystemRequirementsLab
2007-11-16 17:03 <DIR> d-------- C:\Documents and Settings\Administrator\SystemRequirementsLab
2007-11-11 22:25 <DIR> d-------- C:\Downloads
2007-11-11 19:30 3,727,720 --a------ C:\WINDOWS\system32\d3dx9_35.dll
2007-11-11 19:30 3,497,832 --a------ C:\WINDOWS\system32\d3dx9_34.dll
2007-11-11 19:30 1,358,192 --a------ C:\WINDOWS\system32\D3DCompiler_35.dll
2007-11-11 19:30 1,124,720 --a------ C:\WINDOWS\system32\D3DCompiler_34.dll
2007-11-11 19:30 444,776 --a------ C:\WINDOWS\system32\d3dx10_35.dll
2007-11-11 19:30 443,752 --a------ C:\WINDOWS\system32\d3dx10_34.dll
2007-11-11 19:15 <DIR> d-------- C:\Program Files\Electronic Arts
2007-11-08 23:44 20,480 --a------ C:\WINDOWS\system32\H@tKeysH@@k.DLL
2007-11-04 20:06 <DIR> d-------- C:\Program Files\directx
2007-11-04 19:49 <DIR> d-------- C:\Program Files\Deus Ex - Invisible War
2007-11-04 19:32 <DIR> d-------- C:\Program Files\Creative
2007-11-04 19:32 139,264 --a------ C:\WINDOWS\system32\eax.dll
2007-11-02 23:23 <DIR> d-------- C:\Documents and Settings\Administrator\Data aplikací\Miranda
2007-10-30 21:36 <DIR> d-------- C:\WINDOWS\Sun
2007-10-30 21:34 <DIR> d-------- C:\Program Files\Java
2007-10-30 21:32 <DIR> d-------- C:\Program Files\Common Files\Java
2007-10-29 00:03 <DIR> d-------- C:\Documents and Settings\Administrator\Data aplikací\DivX
2007-10-28 19:02 56 --a------ C:\WINDOWS\UninstallLightsmark2007.bat
2007-10-26 12:43 <DIR> d-------- C:\Documents and Settings\Administrator\Data aplikací\ICQ
2007-10-25 14:25 <DIR> d-------- C:\WINDOWS\system32\oodag
2007-10-25 14:21 <DIR> dr-h----- C:\Documents and Settings\Administrator\Data aplikací\SecuROM
2007-10-25 14:20 236,824 --a------ C:\WINDOWS\system32\xactengine2_3.dll
2007-10-25 14:20 62,744 --a------ C:\WINDOWS\system32\xinput1_2.dll
2007-10-25 14:07 <DIR> d-------- C:\Program Files\iolo
2007-10-25 14:07 1,212,416 --a------ C:\WINDOWS\system32\Incinerator.dll
2007-10-25 14:07 41,472 --a------ C:\WINDOWS\system32\iolobtdfg.exe
2007-10-22 17:09 512 --a------ C:\ScanSectorLog.dat
2007-10-22 17:06 <DIR> d-------- C:\WINDOWS\pss
2007-10-22 17:06 <DIR> d-------- C:\Documents and Settings\Administrator\Data aplikací\MailFrontier
2007-10-21 20:13 0 --a------ C:\WINDOWS\ativpsrm.bin
2007-10-21 16:28 <DIR> d-------- C:\Documents and Settings\Administrator\Data aplikací\Ulead Systems
2007-10-21 16:23 <DIR> d-------- C:\WINDOWS\system32\QuickTime
2007-10-21 16:23 <DIR> d-------- C:\Program Files\SmartSound Software
2007-10-21 16:23 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\SmartSound Software Inc
2007-10-21 16:23 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\QuickTime
2007-10-21 16:23 1,645,320 --------- C:\WINDOWS\system32\gdiplus.dll
2007-10-21 16:20 <DIR> d-------- C:\WINDOWS\Ulead.dat
2007-10-21 16:20 48,640 --a------ C:\WINDOWS\system32\INETWH32.DLL
2007-10-21 16:20 4,528 --a------ C:\WINDOWS\system32\SETBROWS.EXE
2007-10-21 16:19 <DIR> d-------- C:\WINDOWS\system32\windows media
2007-10-21 16:19 <DIR> d--h----- C:\WINDOWS\msdownld.tmp
2007-10-21 16:19 <DIR> d-------- C:\Program Files\Windows Media Components
2007-10-21 16:18 <DIR> d-------- C:\Program Files\Ulead Systems
2007-10-21 16:18 <DIR> d-------- C:\Program Files\Common Files\SONY Digital Images
2007-10-21 16:18 292,896 --a------ C:\WINDOWS\system32\drivers\USIUDF.sys
2007-10-21 16:17 401,462 --a------ C:\WINDOWS\msvcp60.dll
2007-10-21 16:17 278,581 --a------ C:\WINDOWS\msvcrt.dll
2007-10-21 16:17 57,344 --------- C:\WINDOWS\dvdrgn.exe
2007-10-20 14:42 4,212 ---h----- C:\WINDOWS\system32\zllictbl.dat
2007-10-20 14:41 <DIR> d-------- C:\WINDOWS\Internet Logs
2007-10-20 14:09 502,208 --a------ C:\WINDOWS\system32\drivers\amon.sys
2007-10-20 14:09 270,336 --a------ C:\WINDOWS\system32\imon.dll
2007-10-20 10:10 <DIR> d--h----- C:\WINDOWS\system32\GroupPolicy
2007-10-18 17:30 <DIR> d-------- C:\Documents and Settings\Administrator\Data aplikací\Moyea
2007-10-18 17:27 <DIR> d-------- C:\Documents and Settings\Administrator\Data aplikací\MoyeaFLV2Video
2007-10-17 21:45 <DIR> d-------- C:\Documents and Settings\Administrator\Data aplikací\MyPhoneExplorer
2007-10-17 21:43 38,016 --a------ C:\WINDOWS\system32\drivers\bthmodem.sys
2007-10-17 21:43 38,016 --a--c--- C:\WINDOWS\system32\dllcache\bthmodem.sys
2007-10-17 21:43 25,600 --a------ C:\WINDOWS\system32\drivers\hidbth.sys
2007-10-17 21:43 25,600 --a--c--- C:\WINDOWS\system32\dllcache\hidbth.sys
2007-10-17 21:43 14,848 --a------ C:\WINDOWS\system32\drivers\kbdhid.sys
2007-10-17 21:43 14,848 --a--c--- C:\WINDOWS\system32\dllcache\kbdhid.sys
2007-10-17 21:27 27,392 --a------ C:\WINDOWS\system32\drivers\ULCDRHlp.sys
2007-10-17 20:52 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\TVxb
2007-10-17 20:52 <DIR> d--h----- C:\Documents and Settings\All Users\Data aplikací\{7F1DE65E-F4E5-40C9-9A1C-0BE9EE39F681}
2007-10-17 20:27 <DIR> d-------- C:\Program Files\Skype
2007-10-17 20:27 <DIR> d-------- C:\Program Files\Common Files\Skype
2007-10-17 20:27 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\Skype
2007-10-17 20:27 <DIR> d-------- C:\Documents and Settings\Administrator\Data aplikací\Skype
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-17 14:21 63,476 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2007-11-17 14:21 3,320 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2007-11-16 20:51 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-11-16 20:04 --------- d---a-w C:\Documents and Settings\All Users\Data aplikací\TEMP
2007-11-16 19:36 --------- d-----w C:\Program Files\SpeedFan
2007-11-16 17:50 --------- d-----w C:\Program Files\ATI Technologies
2007-11-15 23:14 2,642,944 ----a-w C:\WINDOWS\system32\drivers\ati2mtag.sys
2007-11-15 22:39 364,544 ----a-w C:\WINDOWS\system32\ATIDEMGX.dll
2007-11-15 22:38 268,288 ----a-w C:\WINDOWS\system32\ati2dvag.dll
2007-11-15 22:31 307,200 ----a-w C:\WINDOWS\system32\atiiiexx.dll
2007-11-15 22:30 43,520 ----a-w C:\WINDOWS\system32\ati2edxx.dll
2007-11-15 22:30 26,112 ----a-w C:\WINDOWS\system32\Ati2mdxx.exe
2007-11-15 22:30 143,360 ----a-w C:\WINDOWS\system32\atipdlxx.dll
2007-11-15 22:30 122,880 ----a-w C:\WINDOWS\system32\Oemdspif.dll
2007-11-15 22:30 122,880 ----a-w C:\WINDOWS\system32\ati2evxx.dll
2007-11-15 22:28 53,248 ----a-w C:\WINDOWS\system32\ATIDDC.DLL
2007-11-15 22:28 495,616 ----a-w C:\WINDOWS\system32\ati2evxx.exe
2007-11-15 22:23 9,314,304 ----a-w C:\WINDOWS\system32\atioglx2.dll
2007-11-15 22:19 3,135,040 ----a-w C:\WINDOWS\system32\ati3duag.dll
2007-11-15 22:08 1,601,792 ----a-w C:\WINDOWS\system32\ativvaxx.dll
2007-11-15 21:54 5,435,392 ----a-w C:\WINDOWS\system32\atioglxx.dll
2007-11-15 21:54 376,832 ----a-w C:\WINDOWS\system32\atikvmag.dll
2007-11-15 21:52 17,408 ----a-w C:\WINDOWS\system32\atitvo32.dll
2007-11-15 21:51 49,152 ----a-w C:\WINDOWS\system32\drivers\ati2erec.dll
2007-11-15 21:50 176,128 ----a-w C:\WINDOWS\system32\atiok3x2.dll
2007-11-15 21:46 499,712 ----a-w C:\WINDOWS\system32\ati2cqag.dll
2007-11-15 15:39 593,920 ------w C:\WINDOWS\system32\ati2sgag.exe
2007-11-01 22:03 5,700 ----a-w C:\Documents and Settings\Administrator\FMCodec.dat
2007-10-25 13:21 108,144 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2007-10-21 15:24 --------- d-----w C:\Program Files\Common Files\Ulead Systems
2007-10-21 15:22 --------- d-----w C:\Program Files\Common Files\InstallShield
2007-10-21 15:22 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\Ulead Systems
2007-10-17 20:58 --------- d-----w C:\Program Files\WinFast
2007-10-16 20:33 --------- d-----w C:\Program Files\Common Files\Stardock
2007-10-15 18:20 --------- d-----w C:\Documents and Settings\Administrator\Data aplikací\vlc
2007-10-15 15:06 --------- d-----w C:\Program Files\Gigabyte
2007-10-15 15:05 15,600 ----a-w C:\WINDOWS\gdrv.sys
2007-10-14 19:45 --------- d-----w C:\Documents and Settings\Administrator\Data aplikací\atitray
2007-10-11 18:59 223,128 ----a-w C:\WINDOWS\system32\drivers\vaxscsi.sys
2007-10-11 16:54 --------- d-----w C:\Program Files\Lavalys
2007-10-11 16:36 86,016 ----a-w C:\WINDOWS\system32\OpenAL32.dll
2007-10-11 16:36 262,144 ----a-w C:\WINDOWS\system32\wrap_oal.dll
2007-10-11 16:23 --------- d-----w C:\Program Files\Alcohol Soft
2007-10-11 16:03 639,224 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2007-10-11 16:02 --------- d-----w C:\Documents and Settings\Administrator\Data aplikací\CyberLink
2007-10-10 12:35 --------- d-----w C:\Program Files\Alwil Software
2007-10-10 12:34 --------- d-----w C:\Program Files\Microsoft Works
2007-10-10 12:29 --------- d-----w C:\Program Files\Microsoft.NET
2007-10-05 07:13 --------- d-----w C:\Program Files\MSXML 4.0
2007-10-05 07:10 --------- d-----w C:\Program Files\Windows Media Connect 2
2007-10-05 06:50 --------- d-----w C:\Program Files\CyberLink
2007-10-05 06:50 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\CyberLink
2007-10-05 06:43 --------- d-----w C:\Program Files\Nero
2007-10-05 06:43 --------- d-----w C:\Program Files\Common Files\Ahead
2007-10-05 06:43 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\Nero
2007-10-05 06:43 --------- d-----w C:\Documents and Settings\Administrator\Data aplikací\Ahead
2007-10-05 06:40 --------- d-----w C:\Program Files\Common Files\Adobe
2007-10-05 06:34 --------- d-----w C:\Documents and Settings\Administrator\Data aplikací\ATI
2007-10-04 12:37 315,392 ----a-w C:\WINDOWS\HideWin.exe
2007-10-04 12:37 --------- d-----w C:\Program Files\Realtek
2007-10-04 12:37 --------- d-----w C:\Documents and Settings\Administrator\Data aplikací\InstallShield
2007-10-04 12:34 --------- d-----w C:\Program Files\Intel
2007-10-04 12:25 --------- d-----w C:\Program Files\microsoft frontpage
2007-09-11 09:17 81,920 ----a-w C:\WINDOWS\system32\frapsvid.dll
2007-08-21 06:18 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
.
((((((((((((((((((((((((((((( snapshot@2007-11-16_22.30.43.04 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-10-29 22:39:53 207,400 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\bases\sfdb.dat
+ 2007-11-17 14:21:49 427,320 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\bases\sfdb.dat
- 2007-10-29 22:40:00 6,395,627 ----a-w C:\WINDOWS\system32\ZoneLabs\spyware.dat
+ 2007-11-17 12:51:50 6,735,429 ----a-w C:\WINDOWS\system32\ZoneLabs\spyware.dat
- 2007-10-23 17:09:12 5,607,106 ----a-w C:\WINDOWS\system32\ZoneLabs\spyware0.dat
+ 2007-11-17 12:51:43 6,463,239 ----a-w C:\WINDOWS\system32\ZoneLabs\spyware0.dat
+ 2007-11-17 13:38:29 10,257,408 ----a-w C:\WINDOWS\system32\ZoneLabs\zlqrtdb.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2007-04-12 10:33 C:\WINDOWS\RTHDCPL.exe]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 19:24]
"EasyTuneV"="C:\Program Files\Gigabyte\ET5\ETcall.exe" [2007-04-26 14:50]
"WinFastDTV"="C:\Program Files\WinFast\WFDTV\DTVSchdl.exe" [2007-10-09 09:13]
"WinFast Schedule"="C:\Program Files\WinFast\WFDTV\WFWIZ.exe" [2007-10-01 09:10]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-17 14:49 C:\WINDOWS\system32\bthprops.cpl]
"nod32kui"="D:\Program Files\Eset\nod32kui.exe" [2007-10-20 14:09]
"ZoneAlarm Client"="D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-03-09 00:02]
"ATITool"="D:\Program Files\ATITool\ATITool.exe" [2006-12-08 16:23]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 12:35]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-17 14:49]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WB]
D:\Program Files\AlienGUIse\fastload.dll 2001-12-20 22:34 24576 D:\Program Files\AlienGUIse\fastload.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
"C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ioloDelayModule]
D:\Program Files\iolo\System Mechanic 6\delay.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Booster]
D:\Program Files\inKline Global\PC Booster\pcbooster.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\USIUDF_Eject_Monitor]
C:\Program Files\Common Files\Ulead Systems\DVD\USISrv.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"UleadBurningHelper"=2 (0x2)
"NMIndexingService"=3 (0x3)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"SMSystemAnalyzer"="D:\Program Files\iolo\System Mechanic 6\SMSystemAnalyzer.exe"
S1 ATITool;ATITool Overclocking Utility;C:\WINDOWS\system32\DRIVERS\ATITool.sys
S1 wfcxacap;WinFast TV PCI Audio Capture Driver;C:\WINDOWS\system32\DRIVERS\wfcxacap.sys
S2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe -k netsvcs
S2 wfcxatun;WinFast TV Analog Tuner Driver;C:\WINDOWS\system32\drivers\wfcxatun.sys
S2 WFCXVCAP;WinFast TV Video Capture Driver;C:\WINDOWS\system32\drivers\wfcxvcap.sys
S3 gdrv;gdrv;\??\C:\WINDOWS\gdrv.sys
S3 PSched;Plánovač paketů technologie QoS;C:\WINDOWS\system32\DRIVERS\psched.sys
S3 RivaTuner32;RivaTuner32;\??\D:\Program Files\RivaTuner v2.0 RC 16.1\RivaTuner32.sys
S3 wfcxdtun;WinFast DTV BDA Tuner/Demod Driver;C:\WINDOWS\system32\drivers\wfcxdtun.sys
S3 wfcxtcap;WinFast DTV BDA Transport Stream Capture Driver;C:\WINDOWS\system32\drivers\wfcxtcap.sys
S3 wfcxxbar;WinFast TV Crossbar Driver;C:\WINDOWS\system32\drivers\wfcxxbar.sys
S3 WFIOCTL;WFIOCTL;\??\C:\Program Files\WinFast\WFDTV\WFIOCTL.SYS
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
*Newly Created Service* - WFCXATUN
.
Contents of the 'Scheduled Tasks' folder
"2007-11-16 20:52:01 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- D:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe
.
**************************************************************************
catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-11-17 15:25:40
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-17 15:26:08
C:\ComboFix2.txt ... 2007-11-17 14:02
C:\ComboFix3.txt ... 2007-11-17 13:22
.
--- E O F ---