Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Infected with PCsecuritylab ...Please Help


  • Please log in to reply

#1
AllyDani

AllyDani

    New Member

  • Member
  • Pip
  • 1 posts
Please help me get rid of this thing. Infected with "pcsecuritylab"

Desktop replaced with a black image stating my computer was severely infected with spyware. Constant warning balloons pop-up directing me to a PCsecurity.com page instructing me to download a program to "fix" my computer. I did not download anything from that page but popups are constant.

ComboFix 08-01-03.3 - Ally 2008-01-02 19:05:55.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.154 [GMT -6:00]
Running from: C:\Documents and Settings\Ally\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Ally\Application Data\ASKS~1
C:\Documents and Settings\Ally\My Documents\WNSXS~1
C:\Program Files\3721
C:\Program Files\3721\assist\asbar.dll
C:\Program Files\3721\helper.dll
C:\Program Files\Accoona
C:\Program Files\Accoona\ASearchAssist.dll
C:\Program Files\akl
C:\Program Files\akl\akl.dll
C:\Program Files\akl\akl.exe
C:\Program Files\akl\curlog.htm
C:\Program Files\akl\keylog.txt
C:\Program Files\akl\readme.txt
C:\Program Files\akl\uninstall.exe
C:\Program Files\akl\unsetup.dat
C:\Program Files\akl\unsetup.exe
C:\Program Files\amsys
C:\Program Files\amsys\awmsg.dat
C:\Program Files\amsys\guid.dat
C:\Program Files\amsys\ijl15.dll
C:\Program Files\amsys\mfc42.dll
C:\Program Files\amsys\msvcrt.dll
C:\Program Files\amsys\unins000.dat
C:\Program Files\amsys\unis000.exe
C:\Program Files\amsys\winam.dat
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe
C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe
C:\Program Files\e-zshopper
C:\Program Files\e-zshopper\BarLcher.dll
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HPQ\Default Settings\cpqset.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\p2pnetworks
C:\Program Files\p2pnetworks\amp2pl.exe
C:\Program Files\QdrDrive
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe
C:\Program Files\SealedMedia\sealmon.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Temporary
C:\Program Files\Temporary\wininstall.exe
C:\Program Files\WinAble
C:\Program Files\WinAble\winable .exe
C:\Program Files\WinAble\winable.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\WinPortrait\wpctrl.exe
C:\WINDOWS\764.exe
C:\WINDOWS\7search.dll
C:\WINDOWS\absolute key logger.lnk
C:\WINDOWS\aconti.exe
C:\WINDOWS\aconti.ini
C:\WINDOWS\aconti.log
C:\WINDOWS\aconti.sdb
C:\WINDOWS\acontidialer.txt
C:\WINDOWS\adbar.dll
C:\WINDOWS\b122.exe
C:\WINDOWS\cbinst$.exe
C:\WINDOWS\daxtime.dll
C:\WINDOWS\default.htm
C:\WINDOWS\dp0.dll
C:\WINDOWS\eventlowg.dll
C:\WINDOWS\fhfmm-Uninstaller.exe
C:\WINDOWS\fhfmm.exe
C:\WINDOWS\flt.dll
C:\WINDOWS\hcwprn.exe
C:\WINDOWS\hotporn.exe
C:\WINDOWS\ie_32.exe
C:\WINDOWS\iexplorr23.dll
C:\WINDOWS\jd2002.dll
C:\WINDOWS\kkcomp$.exe
C:\WINDOWS\kkcomp.dll
C:\WINDOWS\kkcomp.exe
C:\WINDOWS\kvnab$.exe
C:\WINDOWS\kvnab.dll
C:\WINDOWS\kvnab.exe
C:\WINDOWS\liqad$.exe
C:\WINDOWS\liqad.dll
C:\WINDOWS\liqad.exe
C:\WINDOWS\liqui-Uninstaller.exe
C:\WINDOWS\liqui.dll
C:\WINDOWS\liqui.exe
C:\WINDOWS\mrofinu11.exe
C:\WINDOWS\ngd.dll
C:\WINDOWS\pbar.dll
C:\WINDOWS\pbsysie.dll
C:\WINDOWS\settn.dll
C:\WINDOWS\spredirect.dll
C:\WINDOWS\system32\acbeg.ini
C:\WINDOWS\system32\acbeg.ini2
C:\WINDOWS\system32\ace16win.dll
C:\WINDOWS\system32\acespy
C:\WINDOWS\system32\acespy\__acelog.ndx
C:\WINDOWS\system32\acespy\systune.exe
C:\WINDOWS\system32\ctfmon.exe.tmp
C:\WINDOWS\system32\din.ip
C:\WINDOWS\system32\dpqaqlqx.bin
C:\WINDOWS\system32\drivers\blank.gif
C:\WINDOWS\system32\drivers\box_2.gif
C:\WINDOWS\system32\drivers\button_buynow.gif
C:\WINDOWS\system32\drivers\button_freescan.gif
C:\WINDOWS\system32\drivers\cell_bg.gif
C:\WINDOWS\system32\drivers\cell_footer.gif
C:\WINDOWS\system32\drivers\cell_header_block.gif
C:\WINDOWS\system32\drivers\cell_header_remove.gif
C:\WINDOWS\system32\drivers\cell_header_scan.gif
C:\WINDOWS\system32\drivers\detect.htm
C:\WINDOWS\system32\drivers\download_btn.jpg
C:\WINDOWS\system32\drivers\download_now_btn.gif
C:\WINDOWS\system32\drivers\footer_back.jpg
C:\WINDOWS\system32\drivers\header_1.gif
C:\WINDOWS\system32\drivers\header_2.gif
C:\WINDOWS\system32\drivers\header_3.gif
C:\WINDOWS\system32\drivers\header_4.gif
C:\WINDOWS\system32\drivers\header_red_bg.gif
C:\WINDOWS\system32\drivers\header_red_free_scan.gif
C:\WINDOWS\system32\drivers\header_red_free_scan_bg.gif
C:\WINDOWS\system32\drivers\header_red_protect_your_pc.gif
C:\WINDOWS\system32\drivers\infected.gif
C:\WINDOWS\system32\drivers\main_back.gif
C:\WINDOWS\system32\drivers\product_2_header.gif
C:\WINDOWS\system32\drivers\product_2_name_small.gif
C:\WINDOWS\system32\drivers\product_features.gif
C:\WINDOWS\system32\drivers\pt.htm
C:\WINDOWS\system32\drivers\rating.gif
C:\WINDOWS\system32\drivers\s_detect.htm
C:\WINDOWS\system32\drivers\screenshot.jpg
C:\WINDOWS\system32\drivers\sep_hor.gif
C:\WINDOWS\system32\drivers\sep_vert.gif
C:\WINDOWS\system32\drivers\shadow.jpg
C:\WINDOWS\system32\drivers\shadow_bg.gif
C:\WINDOWS\system32\drivers\spacer.gif
C:\WINDOWS\system32\drivers\star.gif
C:\WINDOWS\system32\drivers\star_gray.gif
C:\WINDOWS\system32\drivers\star_gray_small.gif
C:\WINDOWS\system32\drivers\star_small.gif
C:\WINDOWS\system32\drivers\style.css
C:\WINDOWS\system32\drivers\svchost.exe
C:\WINDOWS\system32\drivers\v.gif
C:\WINDOWS\system32\drivers\warning_icon.gif
C:\WINDOWS\system32\drivers\win_logo.gif
C:\WINDOWS\system32\drivers\x.gif
C:\WINDOWS\system32\egmulhxk.dll
C:\WINDOWS\system32\ESHOPEE.exe
C:\WINDOWS\system32\gebca.dll
C:\WINDOWS\system32\gebca.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\lpcywinp.exe
C:\WINDOWS\system32\mljjghh.dll
C:\WINDOWS\system32\msole32.exe
C:\WINDOWS\system32\NeroCheck.exe
C:\WINDOWS\system32\RCX69.tmp
C:\WINDOWS\system32\stfv.bin
C:\WINDOWS\system32\sznf.ascii
C:\WINDOWS\system32\vxddsk.exe
C:\WINDOWS\system32\wml.exe
C:\WINDOWS\system32\wtssu.exe
C:\WINDOWS\vxddsk.exe
C:\WINDOWS\wbeCheck.exe
C:\WINDOWS\wbeInst$.exe
C:\WINDOWS\wml.exe
C:\WINDOWS\xadbrk.dll
C:\WINDOWS\xadbrk.exe
C:\WINDOWS\xadbrk_.exe
C:\WINDOWS\xxxvideo.exe

.
((((((((((((((((((((((((( Files Created from 2007-12-03 to 2008-01-03 )))))))))))))))))))))))))))))))
.

2008-01-02 18:59 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-12-31 22:43 . 2007-12-31 22:43 <DIR> d-------- C:\Program Files\Lavasoft
2007-12-31 22:43 . 2007-12-31 22:43 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-12-31 22:42 . 2007-12-31 22:42 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-12-31 19:20 . 2007-12-31 19:20 <DIR> d-------- C:\Documents and Settings\Ally\Application Data\Symantec
2007-12-31 18:54 . 2007-12-31 19:06 <DIR> d-------- C:\Program Files\Norton 360
2007-12-31 18:51 . 2007-12-31 19:01 115,000 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-12-31 18:51 . 2007-12-31 19:01 48,776 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2007-12-31 18:51 . 2007-12-31 19:01 8,014 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2007-12-31 18:51 . 2007-12-31 19:01 806 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.INF
2007-12-31 18:47 . 2007-12-31 19:01 <DIR> d-------- C:\Program Files\Symantec
2007-12-31 18:47 . 2008-01-01 01:08 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Symantec
2007-12-31 18:46 . 2007-12-31 22:49 <DIR> d-------- C:\Program Files\Common Files\Symantec Shared
2007-12-31 00:53 . 2007-12-31 00:53 4 --a------ C:\WINDOWS\system32\jpewocmz.ini
2007-12-31 00:50 . 2007-12-31 00:50 8,711 --a------ C:\jwKw.exe
2007-12-31 00:49 . 2007-12-31 00:49 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2007-12-31 00:49 . 2007-12-31 00:49 1,409 --a------ C:\WINDOWS\QTFont.for
2007-12-31 00:27 . 2007-12-31 00:27 <DIR> d-------- C:\Documents and Settings\Ally\Application Data\Media Player Classic
2007-12-31 00:10 . 2007-12-31 00:10 <DIR> d-------- C:\Program Files\RcvSystem
2007-12-29 18:52 . 2007-12-29 18:52 230 --a------ C:\WINDOWS\system32\spupdsvc.inf
2007-12-29 18:30 . 2007-12-31 00:42 15,360 --a------ C:\WINDOWS\system32\ctfmon .exe
2007-12-29 18:03 . 2008-01-02 18:54 544,768 --a------ C:\WINDOWS\system32\drivers\svchost .exe
2007-12-29 18:03 . 2008-01-02 18:54 155,648 --a------ C:\WINDOWS\system32\NeroCheck .exe
2007-12-29 18:02 . 2008-01-02 18:52 155,648 --a------ C:\WINDOWS\system32\igfxtray .exe
2007-12-29 18:02 . 2008-01-02 18:52 118,784 --a------ C:\WINDOWS\system32\hkcmd .exe
2007-12-29 11:17 . 2008-01-02 18:54 380,928 --a------ C:\WINDOWS\mrofinu11.exe.tmp
2007-12-27 23:04 . 2007-06-28 18:55 77,824 --a------ C:\WINDOWS\system32\xvid.ax
2007-12-12 21:57 . 2007-12-12 21:57 <DIR> d-------- C:\Documents and Settings\P2 Critique User\Bluetooth Software

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-03 01:21 --------- d-----w C:\Program Files\WinPortrait
2008-01-03 01:21 --------- d-----w C:\Program Files\SealedMedia
2008-01-03 01:20 --------- d-----w C:\Program Files\QuickTime
2008-01-03 01:20 --------- d-----w C:\Program Files\iTunes
2007-11-29 20:13 --------- d-----w C:\Documents and Settings\Ally\Application Data\AdobeUM
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-10-29 22:43 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-27 23:40 222,720 ----a-w C:\WINDOWS\system32\wmasf.dll
.
----a-w		   580,608 2008-01-03 00:53:51  C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM			.exe
----a-w		   580,608 2008-01-01 17:51:05  C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM		   .exe
----a-w		   580,608 2008-01-01 06:54:05  C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM		  .exe
----a-w		   580,608 2008-01-01 04:36:17  C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM		 .exe
----a-w		   580,608 2008-01-01 00:41:16  C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM		.exe
----a-w		   580,608 2008-01-01 00:18:12  C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM	   .exe
----a-w		   580,608 2007-12-31 06:41:42  C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM	  .exe
----a-w		   580,608 2007-12-30 16:14:03  C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM	 .exe
----a-w		   580,608 2007-12-30 04:55:58  C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM	.exe
----a-w		   580,608 2007-12-30 04:44:08  C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM   .exe
----a-w		   580,608 2007-12-30 00:29:41  C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM  .exe
----a-w		   580,608 2007-12-30 00:19:49  C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe
----a-w		   155,648 2008-01-03 00:54:23  C:\Program Files\Common Files\ScanSoft Shared\SSBkgdUpdate\SSBkgdupdate .exe
----a-w			49,152 2008-01-03 00:53:19  C:\Program Files\HP\HP Software Update\HPWuSchd2 .exe
----a-w		   208,958 2008-01-03 00:52:43  C:\Program Files\HPQ\Default Settings\cpqset .exe
----a-w		   499,712 2008-01-03 00:54:12  C:\Program Files\HPQ\HP Wireless Assistant\HP Wireless Assistant .exe
----a-w		   229,952 2008-01-03 00:53:57  C:\Program Files\iTunes\iTunesHelper .exe
----a-w			83,608 2008-01-03 00:54:33  C:\Program Files\Java\jre1.6.0_01\bin\jusched .exe
----a-w		 1,694,208 2008-01-03 01:54:03  C:\Program Files\Messenger\msmsgs .exe
----a-w		   649,728 2008-01-03 00:52:28  C:\Program Files\QuickTime\qttask		  .exe
----a-w		   649,728 2008-01-01 17:49:56  C:\Program Files\QuickTime\qttask		 .exe
----a-w		   649,728 2008-01-01 06:53:54  C:\Program Files\QuickTime\qttask		.exe
----a-w		   649,728 2008-01-01 04:35:50  C:\Program Files\QuickTime\qttask	   .exe
----a-w		   649,728 2008-01-01 00:41:05  C:\Program Files\QuickTime\qttask	  .exe
----a-w		   649,728 2008-01-01 00:17:53  C:\Program Files\QuickTime\qttask	 .exe
----a-w		   649,728 2007-12-30 16:13:40  C:\Program Files\QuickTime\qttask	.exe
----a-w		   649,728 2007-12-30 04:43:48  C:\Program Files\QuickTime\qttask   .exe
----a-w		   649,728 2007-12-30 00:59:13  C:\Program Files\QuickTime\qttask  .exe
----a-w		   649,728 2007-12-30 00:19:33  C:\Program Files\QuickTime\qttask .exe
----a-w			69,632 2008-01-03 00:54:27  C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4 .exe
----a-w			94,208 2008-01-03 00:53:09  C:\Program Files\SealedMedia\sealmon .exe
----a-w		   688,218 2008-01-03 00:52:15  C:\Program Files\Synaptics\SynTP\SynTPEnh .exe
----a-w			98,394 2008-01-03 00:52:05  C:\Program Files\Synaptics\SynTP\SynTPLpr .exe
----a-w		   204,288 2008-01-03 00:55:12  C:\Program Files\Windows Media Player\WMPNSCFG .exe
----a-w		   694,008 2008-01-03 00:53:02  C:\Program Files\WinPortrait\wpctrl .exe
----a-w		   208,952 2008-01-01 17:49:51  C:\WINDOWS\ime\IMJP8_1\IMJPMIG .EXE
----a-w			15,360 2007-12-31 06:42:33  C:\WINDOWS\system32\ctfmon .exe
----a-w		   118,784 2008-01-03 00:52:32  C:\WINDOWS\system32\hkcmd .exe
----a-w		   155,648 2008-01-03 00:52:30  C:\WINDOWS\system32\igfxtray .exe
----a-w		   155,648 2008-01-03 00:54:40  C:\WINDOWS\system32\NeroCheck .exe
----a-w		   544,768 2008-01-03 00:54:51  C:\WINDOWS\system32\drivers\svchost .exe
----a-w		   455,168 2008-01-01 17:49:53  C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP .EXE


-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3AE6082B-E0D3-446C-95CC-4EEB9D48CE46}]
2008-01-02 19:53 336384 --a------ C:\WINDOWS\system32\gebca.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2008-01-02 19:54 2226688]
"BackupNotify"="C:\Program Files\HP\Digital Imaging\bin\backupnotify.exe" [ ]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 06:00 15360]
"Windows Firewall"="C:\WINDOWS\System32\drivers\svchost.exe" [ ]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-04 06:00 208952]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 06:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 06:00 455168]
"DXDllRegExe"="dxdllreg.exe" []
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [ ]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [ ]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [ ]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [ ]
"Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" [ ]
"PivotSoftware"="C:\Program Files\WinPortrait\wpctrl.exe" [ ]
"sealmon"="C:\Program Files\SealedMedia\sealmon.exe" [ ]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [ ]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [ ]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [ ]
"DeadAIM"="C:\PROGRA~1\AIM\\DeadAIM.ocm" [2005-11-27 16:18 144896]
"hpWirelessAssistant"="C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [ ]
"SSBkgdUpdate"="C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [ ]
"OpwareSE4"="C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe" [ ]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [ ]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [ ]
"Windows Firewall"="C:\WINDOWS\System32\drivers\svchost.exe" [ ]
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe" [ ]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-07-17 19:54 116072]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 18:16:50]
BTTray.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2004-06-02 17:48:22]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2003-09-16 04:19:24]
HP Display LiteSaver Startup.lnk - C:\WINDOWS\HPLiteSaver.exe [2004-08-24 14:01:12]

[HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\windows]
"load"=C:\WINDOWS\system32\gebca.exe

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 C:\WINDOWS\system32\gebca

R1 pivot;pivot;C:\WINDOWS\system32\drivers\pivot.sys [2004-09-23 08:03]
S3 pivotmou;Pivot Mouse/Pointers Filter Driver;C:\WINDOWS\system32\drivers\pivotmou.sys [2004-09-23 08:03]

*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2007-12-09 19:02:35 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-02 19:53:35
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Windows Firewall = C:\WINDOWS\System32\drivers\svchost.exe?

scanning hidden files ...

C:\WINDOWS\system32\gebca.exe 339968 bytes executable

scan completed successfully
hidden files: 1

**************************************************************************
.
Completion time: 2008-01-02 20:00:06 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-03 01:59:54
.
2008-01-01 17:58:06 --- E O F ---
  • 0

Advertisements







Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP