ComboFix 08-03-04.3 - Owner 2008-03-05 15:53:46.2 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2861 [GMT 10:00] Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe [color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color] . ((((((((((((((((((((((((( Files Created from 2008-02-05 to 2008-03-05 ))))))))))))))))))))))))))))))) . 2008-03-03 18:47 . 2008-03-03 18:47 d-------- C:\Program Files\Common Files\EasyInfo 2008-03-03 07:46 . 2008-03-03 07:46 d-------- C:\Deckard 2008-03-02 20:11 . 2008-03-02 20:11 d-------- C:\Documents and Settings\All Users\Application Data\Messenger Plus! 2008-03-02 20:02 . 2008-03-02 20:02 d-------- C:\Program Files\Messenger Plus! Live 2008-03-01 18:21 . 2008-03-01 18:21 d-------- C:\_OTMoveIt 2008-02-27 23:02 . 2008-02-27 23:02 d-------- C:\Program Files\SystemRequirementsLab 2008-02-26 21:24 . 2008-02-26 21:24 d-------- C:\Program Files\Trend Micro 2008-02-26 21:11 . 2008-03-01 18:23 d-------- C:\Program Files\SUPERAntiSpyware 2008-02-26 21:11 . 2008-02-26 21:11 d-------- C:\Documents and Settings\Owner\Application Data\SUPERAntiSpyware.com 2008-02-26 21:11 . 2008-02-26 21:11 d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com 2008-02-26 20:28 . 2008-02-26 20:28 d-------- C:\Program Files\Lavasoft 2008-02-26 20:28 . 2008-02-26 20:29 d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft 2008-02-26 17:31 . 2007-04-09 13:23 28,040 --a------ C:\WINDOWS\system32\mdimon.dll 2008-02-26 17:31 . 2008-02-26 17:31 376 --a------ C:\WINDOWS\ODBC.INI 2008-02-26 17:30 . 2008-02-26 17:30 d-------- C:\WINDOWS\SHELLNEW 2008-02-26 17:29 . 2008-02-26 17:29 d-------- C:\Program Files\Microsoft.NET 2008-02-26 17:27 . 2008-02-26 17:27 dr-h----- C:\MSOCache 2008-02-25 16:36 . 2008-02-25 16:37 d-------- C:\Documents and Settings\Owner\Application Data\AVG7 2008-02-25 16:35 . 2008-02-25 16:35 d-------- C:\Documents and Settings\LocalService\Application Data\AVG7 2008-02-25 16:35 . 2008-02-25 16:35 d-------- C:\Documents and Settings\All Users\Application Data\Grisoft 2008-02-25 16:35 . 2008-02-25 16:37 d-------- C:\Documents and Settings\All Users\Application Data\avg7 2008-02-21 21:33 . 2008-02-21 21:33 d-------- C:\Program Files\VSO 2008-02-21 21:33 . 2008-02-21 22:15 d-------- C:\Documents and Settings\Owner\Application Data\Vso 2008-02-21 21:33 . 2006-09-29 11:24 217,127 --a------ C:\WINDOWS\system32\drv43260.dll 2008-02-21 21:33 . 2006-09-29 11:25 208,935 --a------ C:\WINDOWS\system32\drv33260.dll 2008-02-21 21:33 . 2006-09-29 11:26 176,165 --a------ C:\WINDOWS\system32\drv23260.dll 2008-02-21 21:33 . 2008-02-21 21:33 47,360 --a------ C:\WINDOWS\system32\drivers\pcouffin.sys 2008-02-21 21:33 . 2008-02-21 21:33 47,360 --a------ C:\Documents and Settings\Owner\Application Data\pcouffin.sys 2008-02-21 21:33 . 2008-02-25 16:41 43,800 --a------ C:\WINDOWS\system32\scvhost 2008-02-21 20:43 . 2004-09-10 13:50 34,820 --a------ C:\WINDOWS\system32\ffdshow.reg 2008-02-21 20:06 . 2003-03-18 22:20 1,060,864 --a------ C:\WINDOWS\system32\MFC71.DLL 2008-02-21 20:06 . 2003-03-18 21:14 499,712 --a------ C:\WINDOWS\system32\MSVCP71.DLL 2008-02-21 20:06 . 2003-03-30 20:08 372,736 --a------ C:\WINDOWS\system32\xvid.ax 2008-02-21 19:52 . 2008-02-21 20:06 d-------- C:\Program Files\Cucusoft 2008-02-21 19:52 . 2004-10-12 14:40 2,255,360 --a------ C:\WINDOWS\system32\libavcodec.dll 2008-02-21 19:52 . 2004-10-12 14:46 1,761,280 --a------ C:\WINDOWS\system32\ffdshow.ax 2008-02-21 19:52 . 2004-10-05 16:16 395,776 --a------ C:\WINDOWS\system32\libmplayer.dll 2008-02-21 19:52 . 2004-10-12 14:42 262,144 --a------ C:\WINDOWS\system32\TomsMoComp_ff.dll 2008-02-21 19:52 . 2003-04-03 00:17 172,032 --a------ C:\WINDOWS\system32\ac3filter.ax 2008-02-21 19:52 . 2004-10-04 01:50 112,640 --a------ C:\WINDOWS\system32\libmpeg2_ff.dll 2008-02-20 17:17 . 2008-02-20 17:17 d-------- C:\Program Files\Java 2008-02-20 17:17 . 2007-12-14 01:59 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl 2008-02-20 17:15 . 2008-02-20 17:17 d-------- C:\Program Files\LimeWire 2008-02-20 17:15 . 2008-02-20 17:15 d-------- C:\Program Files\Common Files\Java 2008-02-20 17:13 . 2008-02-21 20:05 d-------- C:\Documents and Settings\Owner\.limewire 2008-02-20 16:10 . 2004-08-04 00:56 90,624 --a------ C:\WINDOWS\system32\kswdmcap.ax 2008-02-20 08:10 . 2008-02-20 08:10 d-------- C:\Documents and Settings\Owner\Application Data\CD-LabelPrint 2008-02-20 08:10 . 2008-03-04 07:49 d-------- C:\Documents and Settings\Owner\Application Data\Canon 2008-02-20 08:08 . 2008-02-20 08:09 d-------- C:\Program Files\Canon 2008-02-19 21:29 . 2008-02-19 21:29 98,304 --a------ C:\WINDOWS\system32CmdLineExt.dll 2008-02-19 21:22 . 2008-02-28 17:54 54,156 --ah----- C:\WINDOWS\QTFont.qfn 2008-02-19 21:22 . 2008-02-19 21:22 1,409 --a------ C:\WINDOWS\QTFont.for 2008-02-19 20:20 . 2008-02-19 20:20 d-------- C:\Documents and Settings\All Users\Application Data\LightScribe 2008-02-19 18:58 . 2008-02-19 18:58 d-------- C:\Program Files\Easy CD & DVD Cover Creator 2008-02-19 18:53 . 2008-02-19 18:53 d-------- C:\Documents and Settings\Owner\Application Data\Acoustica 2008-02-19 18:53 . 2003-02-24 18:17 299,552 --a------ C:\WINDOWS\wmsysprx.prx 2008-02-18 08:15 . 2008-02-18 08:15 d-------- C:\Program Files\MSXML 4.0 2008-02-17 20:59 . 2008-02-17 20:59 d-------- C:\Documents and Settings\All Users\Application Data\Adobe Systems 2008-02-17 20:57 . 2008-02-17 20:57 82,432 --a------ C:\WINDOWS\system32\msxml4r.dll 2008-02-17 20:57 . 2008-02-17 20:57 20,016 --------- C:\WINDOWS\system32\drivers\pxhelp20.sys 2008-02-15 17:33 . 2008-02-15 17:33 d-------- C:\Program Files\uTorrent 2008-02-15 17:33 . 2008-02-21 21:58 d-------- C:\Documents and Settings\Owner\Application Data\uTorrent 2008-02-15 16:53 . 2004-08-04 00:56 159,232 --a------ C:\WINDOWS\system32\ptpusd.dll 2008-02-15 16:53 . 2001-08-17 22:36 5,632 --a------ C:\WINDOWS\system32\ptpusb.dll 2008-02-15 16:44 . 2008-02-15 16:44 d-------- C:\Documents and Settings\Owner\Application Data\Media Player Classic 2008-02-15 16:41 . 2008-02-15 16:41 d-------- C:\Program Files\K-Lite Codec Pack 2008-02-15 16:32 . 2008-02-15 16:32 d-------- C:\Program Files\VideoLAN 2008-02-15 16:20 . 2008-02-15 16:20 d-------- C:\Program Files\Windows Media Connect 2 2008-02-15 16:19 . 2008-02-15 16:20 d-------- C:\WINDOWS\system32\drivers\UMDF 2008-02-15 16:19 . 2008-02-15 16:19 d-------- C:\e776921f33af7c4e7c56b91f95e5d02a 2008-02-11 17:16 . 2008-02-28 17:54 116 --a------ C:\WINDOWS\NeroDigital.ini 2008-02-11 17:12 . 2008-02-11 17:12 d-------- C:\Program Files\Common Files\Nero 2008-02-11 17:12 . 2008-02-19 20:20 d-------- C:\Program Files\Common Files\LightScribe 2008-02-11 17:11 . 2008-02-11 17:11 d-------- C:\Program Files\Common Files\Ahead 2008-02-11 17:11 . 2008-02-11 17:11 d-------- C:\Program Files\Ahead 2008-02-11 17:11 . 2004-07-26 17:16 1,568,768 --------- C:\WINDOWS\system32\ImagX7.dll 2008-02-11 17:11 . 2004-07-26 17:16 476,320 --------- C:\WINDOWS\system32\ImagXpr7.dll 2008-02-11 17:11 . 2004-07-26 17:16 471,040 --------- C:\WINDOWS\system32\ImagXRA7.dll 2008-02-11 17:11 . 2004-07-09 09:43 364,544 --------- C:\WINDOWS\system32\TwnLib4.dll 2008-02-11 17:11 . 2004-07-26 17:16 262,144 --------- C:\WINDOWS\system32\ImagXR7.dll 2008-02-11 17:11 . 2006-01-12 16:40 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe 2008-02-11 17:11 . 2000-06-26 11:45 106,496 --a------ C:\WINDOWS\system32\TwnLib20.dll 2008-02-08 16:07 . 2004-08-03 22:58 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys 2008-02-08 16:07 . 2004-08-03 22:58 15,104 --a--c--- C:\WINDOWS\system32\dllcache\usbscan.sys 2008-02-07 21:13 . 2008-02-20 17:38 43,520 --a------ C:\WINDOWS\system32\CmdLineExt03.dll 2008-02-07 17:24 . 2008-02-07 17:24 d-------- C:\Program Files\Sierra 2008-02-05 20:48 . 2008-02-05 20:48 d--h----- C:\WINDOWS\system32\CanonIJ Uninstaller Information 2008-02-05 20:48 . 2008-02-05 20:48 d--h----- C:\Program Files\CanonBJ 2008-02-05 20:48 . 2008-02-05 20:48 d--h----- C:\Documents and Settings\All Users\Application Data\CanonBJ 2008-02-05 20:48 . 2006-07-20 15:51 1,298,432 --a------ C:\WINDOWS\system32\CNCC960.DLL 2008-02-05 20:48 . 2006-09-13 05:00 197,632 --a------ C:\WINDOWS\system32\CNMLM8C.DLL 2008-02-05 20:48 . 2006-05-26 10:55 139,264 --a------ C:\WINDOWS\system32\CNCL960.DLL 2008-02-05 20:48 . 2006-06-29 14:29 106,496 --a------ C:\WINDOWS\system32\cnco960.dll 2008-02-05 20:48 . 2006-07-20 15:51 57,344 --a------ C:\WINDOWS\system32\CNCI960.DLL 2008-02-05 16:33 . 2004-08-03 23:01 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys 2008-02-05 16:33 . 2004-08-03 23:01 25,856 --a--c--- C:\WINDOWS\system32\dllcache\usbprint.sys . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-03-03 07:57 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys 2008-03-03 07:57 107,832 ----a-w C:\WINDOWS\system32\PnkBstrB.exe 2008-02-29 08:57 --------- d-----w C:\Program Files\Steam 2008-02-29 08:16 --------- d--h--w C:\Program Files\InstallShield Installation Information 2008-02-29 08:06 --------- d-----w C:\Program Files\EA GAMES 2008-02-28 07:55 --------- d-----w C:\Documents and Settings\Owner\Application Data\Apple Computer 2008-02-26 11:11 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard 2008-02-26 08:00 --------- d-----w C:\Program Files\Common Files\Adobe 2008-02-25 06:13 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP 2008-02-07 22:04 --------- d-----w C:\Program Files\Common Files\InstallShield 2008-02-03 07:27 --------- d-----w C:\Program Files\Google 2008-02-03 06:27 --------- d-----w C:\Program Files\iTunes 2008-02-03 06:26 --------- d-----w C:\Program Files\QuickTime 2008-02-03 06:26 --------- d-----w C:\Program Files\iPod 2008-02-03 06:26 --------- d-----w C:\Program Files\Common Files\Apple 2008-02-03 06:26 --------- d-----w C:\Program Files\Bonjour 2008-02-03 06:26 --------- d-----w C:\Program Files\Apple Software Update 2008-02-03 06:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer 2008-02-03 06:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple 2008-02-02 07:27 107,888 ----a-w C:\WINDOWS\system32\CmdLineExt.dll 2008-02-02 07:27 --------- d--h--r C:\Documents and Settings\Owner\Application Data\SecuROM 2008-02-02 07:08 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller 2008-02-02 07:08 --------- d-----w C:\Program Files\Windows Live 2008-02-02 07:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller 2008-02-02 06:37 --------- d-----w C:\Documents and Settings\Owner\Application Data\InstallShield Installation Information 2008-02-02 06:29 --------- d-----w C:\Program Files\Unreal Tournament 3 2008-02-02 06:29 --------- d-----w C:\Program Files\AGEIA Technologies 2008-02-02 06:15 --------- d-----w C:\Program Files\id Software 2008-02-02 06:09 --------- d-----w C:\Program Files\Common Files\Adobe Systems Shared 2008-02-02 06:09 --------- d-----w C:\Documents and Settings\All Users\Application Data\Macrovision 2008-02-02 06:04 22,328 ----a-w C:\Documents and Settings\Owner\Application Data\PnkBstrK.sys 2008-02-02 06:03 669,184 ----a-w C:\WINDOWS\system32\pbsvc.exe 2008-02-02 06:03 66,872 ----a-w C:\WINDOWS\system32\PnkBstrA.exe 2008-02-02 06:00 --------- d-----w C:\Program Files\Stardock 2008-02-02 05:55 --------- d-----w C:\Program Files\Electronic Arts 2008-02-02 05:42 --------- d-----w C:\Program Files\Activision 2008-02-02 05:39 --------- d-----w C:\Program Files\D-Tools 2008-02-02 02:22 --------- d-----w C:\Program Files\Attansic 2008-02-02 02:20 --------- d-----w C:\Program Files\Realtek 2008-02-02 02:09 315,392 ----a-w C:\WINDOWS\HideWin.exe 2008-02-02 02:02 --------- d-----w C:\Program Files\Intel 2008-02-02 01:56 --------- d-----w C:\Program Files\microsoft frontpage 2008-01-31 17:21 245,408 ----a-w C:\WINDOWS\system32\unicows.dll 2008-01-10 03:16 159,839 ----a-w C:\WINDOWS\system32\xvidvfw.dll 2008-01-10 03:15 755,027 ----a-w C:\WINDOWS\system32\xvidcore.dll 2007-12-24 03:49 7,680 ----a-w C:\WINDOWS\system32\ff_vfw.dll 2007-12-14 01:32 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe 2007-12-07 02:21 824,832 ----a-w C:\WINDOWS\system32\wininet.dll 2006-06-23 06:48 32,768 ----a-r C:\WINDOWS\inf\UpdateUSB.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-02-28 22:00 15360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RTHDCPL"="RTHDCPL.EXE" [2007-03-21 16:49 16126464 C:\WINDOWS\RTHDCPL.exe] "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 01:41 8523776] "nwiz"="nwiz.exe" [2007-12-05 01:41 1626112 C:\WINDOWS\system32\nwiz.exe] "NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-12-05 01:41 81920] "AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-02-25 16:35 579072] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-02-25 16:35 219136] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv] C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\wbsrv.dll 2005-12-20 22:57 176128 C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\WbSrv.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=wbsys.dll [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^Adobe Gamma.lnk] path=C:\Documents and Settings\Owner\Start Menu\Programs\Startup\Adobe Gamma.lnk backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader] --a------ 2007-03-09 11:09 63712 C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] --a------ 2008-01-15 03:22 267048 C:\Program Files\iTunes\iTunesHelper.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel] --a------ 2007-08-23 17:36 455968 C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] --a------ 2006-01-12 16:40 155648 C:\WINDOWS\system32\NeroCheck.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] --a------ 2008-01-10 15:27 385024 C:\Program Files\QuickTime\qttask.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] --a------ 2007-12-14 03:42 144784 C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg] --a------ 2008-02-13 15:49 68856 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"= "C:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\CrysisDedicatedServer.exe"= "C:\\WINDOWS\\system32\\PnkBstrA.exe"= "C:\\WINDOWS\\system32\\PnkBstrB.exe"= "C:\\Program Files\\id Software\\Enemy Territory - QUAKE Wars\\etqw.exe"= "C:\\Program Files\\id Software\\Enemy Territory - QUAKE Wars\\etqwded.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "C:\\Program Files\\Unreal Tournament 3\\Binaries\\UT3.exe"= "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"= "C:\\Program Files\\Bonjour\\mDNSResponder.exe"= "C:\\Program Files\\iTunes\\iTunes.exe"= "C:\\Program Files\\Steam\\steamapps\\danmac57\\counter-strike source\\hl2.exe"= "C:\\Program Files\\uTorrent\\uTorrent.exe"= "C:\\Program Files\\LimeWire\\LimeWire.exe"= "C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"= "C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"= "C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"= "C:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"= R0 d344bus;d344bus;C:\WINDOWS\system32\DRIVERS\d344bus.sys [2003-12-27 20:42] R0 d344prt;d344prt;C:\WINDOWS\system32\Drivers\d344prt.sys [2003-12-27 02:38] R3 AtcL001;NDIS Miniport Driver for Attansic L1 Gigabit Ethernet Controller;C:\WINDOWS\system32\DRIVERS\atl01_xp.sys [2007-03-15 16:12] [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}] "C:\Program Files\Common Files\LightScribe\LSRunOnce.exe" . Contents of the 'Scheduled Tasks' folder "2008-02-13 21:21:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job" - C:\Program Files\Apple Software Update\SoftwareUpdate.exe . ************************************************************************** catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-03-05 15:55:19 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- PROCESS: C:\WINDOWS\explorer.exe [6.00.2900.3156] -> C:\Program Files\Stardock\Object Desktop\WindowBlinds\tray.dll . Completion time: 2008-03-05 15:55:35 ComboFix-quarantined-files.txt 2008-03-05 05:55:33 ComboFix2.txt 2008-03-04 22:19:24 . 2008-02-26 22:04:39 --- E O F ---