Desktop replaced with a black image stating my computer was severely infected with spyware. Constant warning balloons pop-up directing me to a PCsecurity.com page instructing me to download a program to "fix" my computer. I did not download anything from that page but popups are constant.
ComboFix 08-01-03.3 - Ally 2008-01-02 19:05:55.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.154 [GMT -6:00]
Running from: C:\Documents and Settings\Ally\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Ally\Application Data\ASKS~1
C:\Documents and Settings\Ally\My Documents\WNSXS~1
C:\Program Files\3721
C:\Program Files\3721\assist\asbar.dll
C:\Program Files\3721\helper.dll
C:\Program Files\Accoona
C:\Program Files\Accoona\ASearchAssist.dll
C:\Program Files\akl
C:\Program Files\akl\akl.dll
C:\Program Files\akl\akl.exe
C:\Program Files\akl\curlog.htm
C:\Program Files\akl\keylog.txt
C:\Program Files\akl\readme.txt
C:\Program Files\akl\uninstall.exe
C:\Program Files\akl\unsetup.dat
C:\Program Files\akl\unsetup.exe
C:\Program Files\amsys
C:\Program Files\amsys\awmsg.dat
C:\Program Files\amsys\guid.dat
C:\Program Files\amsys\ijl15.dll
C:\Program Files\amsys\mfc42.dll
C:\Program Files\amsys\msvcrt.dll
C:\Program Files\amsys\unins000.dat
C:\Program Files\amsys\unis000.exe
C:\Program Files\amsys\winam.dat
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe
C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe
C:\Program Files\e-zshopper
C:\Program Files\e-zshopper\BarLcher.dll
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HPQ\Default Settings\cpqset.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\p2pnetworks
C:\Program Files\p2pnetworks\amp2pl.exe
C:\Program Files\QdrDrive
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe
C:\Program Files\SealedMedia\sealmon.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Temporary
C:\Program Files\Temporary\wininstall.exe
C:\Program Files\WinAble
C:\Program Files\WinAble\winable .exe
C:\Program Files\WinAble\winable.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\WinPortrait\wpctrl.exe
C:\WINDOWS\764.exe
C:\WINDOWS\7search.dll
C:\WINDOWS\absolute key logger.lnk
C:\WINDOWS\aconti.exe
C:\WINDOWS\aconti.ini
C:\WINDOWS\aconti.log
C:\WINDOWS\aconti.sdb
C:\WINDOWS\acontidialer.txt
C:\WINDOWS\adbar.dll
C:\WINDOWS\b122.exe
C:\WINDOWS\cbinst$.exe
C:\WINDOWS\daxtime.dll
C:\WINDOWS\default.htm
C:\WINDOWS\dp0.dll
C:\WINDOWS\eventlowg.dll
C:\WINDOWS\fhfmm-Uninstaller.exe
C:\WINDOWS\fhfmm.exe
C:\WINDOWS\flt.dll
C:\WINDOWS\hcwprn.exe
C:\WINDOWS\hotporn.exe
C:\WINDOWS\ie_32.exe
C:\WINDOWS\iexplorr23.dll
C:\WINDOWS\jd2002.dll
C:\WINDOWS\kkcomp$.exe
C:\WINDOWS\kkcomp.dll
C:\WINDOWS\kkcomp.exe
C:\WINDOWS\kvnab$.exe
C:\WINDOWS\kvnab.dll
C:\WINDOWS\kvnab.exe
C:\WINDOWS\liqad$.exe
C:\WINDOWS\liqad.dll
C:\WINDOWS\liqad.exe
C:\WINDOWS\liqui-Uninstaller.exe
C:\WINDOWS\liqui.dll
C:\WINDOWS\liqui.exe
C:\WINDOWS\mrofinu11.exe
C:\WINDOWS\ngd.dll
C:\WINDOWS\pbar.dll
C:\WINDOWS\pbsysie.dll
C:\WINDOWS\settn.dll
C:\WINDOWS\spredirect.dll
C:\WINDOWS\system32\acbeg.ini
C:\WINDOWS\system32\acbeg.ini2
C:\WINDOWS\system32\ace16win.dll
C:\WINDOWS\system32\acespy
C:\WINDOWS\system32\acespy\__acelog.ndx
C:\WINDOWS\system32\acespy\systune.exe
C:\WINDOWS\system32\ctfmon.exe.tmp
C:\WINDOWS\system32\din.ip
C:\WINDOWS\system32\dpqaqlqx.bin
C:\WINDOWS\system32\drivers\blank.gif
C:\WINDOWS\system32\drivers\box_2.gif
C:\WINDOWS\system32\drivers\button_buynow.gif
C:\WINDOWS\system32\drivers\button_freescan.gif
C:\WINDOWS\system32\drivers\cell_bg.gif
C:\WINDOWS\system32\drivers\cell_footer.gif
C:\WINDOWS\system32\drivers\cell_header_block.gif
C:\WINDOWS\system32\drivers\cell_header_remove.gif
C:\WINDOWS\system32\drivers\cell_header_scan.gif
C:\WINDOWS\system32\drivers\detect.htm
C:\WINDOWS\system32\drivers\download_btn.jpg
C:\WINDOWS\system32\drivers\download_now_btn.gif
C:\WINDOWS\system32\drivers\footer_back.jpg
C:\WINDOWS\system32\drivers\header_1.gif
C:\WINDOWS\system32\drivers\header_2.gif
C:\WINDOWS\system32\drivers\header_3.gif
C:\WINDOWS\system32\drivers\header_4.gif
C:\WINDOWS\system32\drivers\header_red_bg.gif
C:\WINDOWS\system32\drivers\header_red_free_scan.gif
C:\WINDOWS\system32\drivers\header_red_free_scan_bg.gif
C:\WINDOWS\system32\drivers\header_red_protect_your_pc.gif
C:\WINDOWS\system32\drivers\infected.gif
C:\WINDOWS\system32\drivers\main_back.gif
C:\WINDOWS\system32\drivers\product_2_header.gif
C:\WINDOWS\system32\drivers\product_2_name_small.gif
C:\WINDOWS\system32\drivers\product_features.gif
C:\WINDOWS\system32\drivers\pt.htm
C:\WINDOWS\system32\drivers\rating.gif
C:\WINDOWS\system32\drivers\s_detect.htm
C:\WINDOWS\system32\drivers\screenshot.jpg
C:\WINDOWS\system32\drivers\sep_hor.gif
C:\WINDOWS\system32\drivers\sep_vert.gif
C:\WINDOWS\system32\drivers\shadow.jpg
C:\WINDOWS\system32\drivers\shadow_bg.gif
C:\WINDOWS\system32\drivers\spacer.gif
C:\WINDOWS\system32\drivers\star.gif
C:\WINDOWS\system32\drivers\star_gray.gif
C:\WINDOWS\system32\drivers\star_gray_small.gif
C:\WINDOWS\system32\drivers\star_small.gif
C:\WINDOWS\system32\drivers\style.css
C:\WINDOWS\system32\drivers\svchost.exe
C:\WINDOWS\system32\drivers\v.gif
C:\WINDOWS\system32\drivers\warning_icon.gif
C:\WINDOWS\system32\drivers\win_logo.gif
C:\WINDOWS\system32\drivers\x.gif
C:\WINDOWS\system32\egmulhxk.dll
C:\WINDOWS\system32\ESHOPEE.exe
C:\WINDOWS\system32\gebca.dll
C:\WINDOWS\system32\gebca.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\lpcywinp.exe
C:\WINDOWS\system32\mljjghh.dll
C:\WINDOWS\system32\msole32.exe
C:\WINDOWS\system32\NeroCheck.exe
C:\WINDOWS\system32\RCX69.tmp
C:\WINDOWS\system32\stfv.bin
C:\WINDOWS\system32\sznf.ascii
C:\WINDOWS\system32\vxddsk.exe
C:\WINDOWS\system32\wml.exe
C:\WINDOWS\system32\wtssu.exe
C:\WINDOWS\vxddsk.exe
C:\WINDOWS\wbeCheck.exe
C:\WINDOWS\wbeInst$.exe
C:\WINDOWS\wml.exe
C:\WINDOWS\xadbrk.dll
C:\WINDOWS\xadbrk.exe
C:\WINDOWS\xadbrk_.exe
C:\WINDOWS\xxxvideo.exe
.
((((((((((((((((((((((((( Files Created from 2007-12-03 to 2008-01-03 )))))))))))))))))))))))))))))))
.
2008-01-02 18:59 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-12-31 22:43 . 2007-12-31 22:43 <DIR> d-------- C:\Program Files\Lavasoft
2007-12-31 22:43 . 2007-12-31 22:43 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-12-31 22:42 . 2007-12-31 22:42 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-12-31 19:20 . 2007-12-31 19:20 <DIR> d-------- C:\Documents and Settings\Ally\Application Data\Symantec
2007-12-31 18:54 . 2007-12-31 19:06 <DIR> d-------- C:\Program Files\Norton 360
2007-12-31 18:51 . 2007-12-31 19:01 115,000 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-12-31 18:51 . 2007-12-31 19:01 48,776 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2007-12-31 18:51 . 2007-12-31 19:01 8,014 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2007-12-31 18:51 . 2007-12-31 19:01 806 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.INF
2007-12-31 18:47 . 2007-12-31 19:01 <DIR> d-------- C:\Program Files\Symantec
2007-12-31 18:47 . 2008-01-01 01:08 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Symantec
2007-12-31 18:46 . 2007-12-31 22:49 <DIR> d-------- C:\Program Files\Common Files\Symantec Shared
2007-12-31 00:53 . 2007-12-31 00:53 4 --a------ C:\WINDOWS\system32\jpewocmz.ini
2007-12-31 00:50 . 2007-12-31 00:50 8,711 --a------ C:\jwKw.exe
2007-12-31 00:49 . 2007-12-31 00:49 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2007-12-31 00:49 . 2007-12-31 00:49 1,409 --a------ C:\WINDOWS\QTFont.for
2007-12-31 00:27 . 2007-12-31 00:27 <DIR> d-------- C:\Documents and Settings\Ally\Application Data\Media Player Classic
2007-12-31 00:10 . 2007-12-31 00:10 <DIR> d-------- C:\Program Files\RcvSystem
2007-12-29 18:52 . 2007-12-29 18:52 230 --a------ C:\WINDOWS\system32\spupdsvc.inf
2007-12-29 18:30 . 2007-12-31 00:42 15,360 --a------ C:\WINDOWS\system32\ctfmon .exe
2007-12-29 18:03 . 2008-01-02 18:54 544,768 --a------ C:\WINDOWS\system32\drivers\svchost .exe
2007-12-29 18:03 . 2008-01-02 18:54 155,648 --a------ C:\WINDOWS\system32\NeroCheck .exe
2007-12-29 18:02 . 2008-01-02 18:52 155,648 --a------ C:\WINDOWS\system32\igfxtray .exe
2007-12-29 18:02 . 2008-01-02 18:52 118,784 --a------ C:\WINDOWS\system32\hkcmd .exe
2007-12-29 11:17 . 2008-01-02 18:54 380,928 --a------ C:\WINDOWS\mrofinu11.exe.tmp
2007-12-27 23:04 . 2007-06-28 18:55 77,824 --a------ C:\WINDOWS\system32\xvid.ax
2007-12-12 21:57 . 2007-12-12 21:57 <DIR> d-------- C:\Documents and Settings\P2 Critique User\Bluetooth Software
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-03 01:21 --------- d-----w C:\Program Files\WinPortrait
2008-01-03 01:21 --------- d-----w C:\Program Files\SealedMedia
2008-01-03 01:20 --------- d-----w C:\Program Files\QuickTime
2008-01-03 01:20 --------- d-----w C:\Program Files\iTunes
2007-11-29 20:13 --------- d-----w C:\Documents and Settings\Ally\Application Data\AdobeUM
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-10-29 22:43 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-27 23:40 222,720 ----a-w C:\WINDOWS\system32\wmasf.dll
.
----a-w 580,608 2008-01-03 00:53:51 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 580,608 2008-01-01 17:51:05 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 580,608 2008-01-01 06:54:05 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 580,608 2008-01-01 04:36:17 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 580,608 2008-01-01 00:41:16 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 580,608 2008-01-01 00:18:12 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 580,608 2007-12-31 06:41:42 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 580,608 2007-12-30 16:14:03 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 580,608 2007-12-30 04:55:58 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 580,608 2007-12-30 04:44:08 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 580,608 2007-12-30 00:29:41 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 580,608 2007-12-30 00:19:49 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe ----a-w 155,648 2008-01-03 00:54:23 C:\Program Files\Common Files\ScanSoft Shared\SSBkgdUpdate\SSBkgdupdate .exe ----a-w 49,152 2008-01-03 00:53:19 C:\Program Files\HP\HP Software Update\HPWuSchd2 .exe ----a-w 208,958 2008-01-03 00:52:43 C:\Program Files\HPQ\Default Settings\cpqset .exe ----a-w 499,712 2008-01-03 00:54:12 C:\Program Files\HPQ\HP Wireless Assistant\HP Wireless Assistant .exe ----a-w 229,952 2008-01-03 00:53:57 C:\Program Files\iTunes\iTunesHelper .exe ----a-w 83,608 2008-01-03 00:54:33 C:\Program Files\Java\jre1.6.0_01\bin\jusched .exe ----a-w 1,694,208 2008-01-03 01:54:03 C:\Program Files\Messenger\msmsgs .exe ----a-w 649,728 2008-01-03 00:52:28 C:\Program Files\QuickTime\qttask .exe ----a-w 649,728 2008-01-01 17:49:56 C:\Program Files\QuickTime\qttask .exe ----a-w 649,728 2008-01-01 06:53:54 C:\Program Files\QuickTime\qttask .exe ----a-w 649,728 2008-01-01 04:35:50 C:\Program Files\QuickTime\qttask .exe ----a-w 649,728 2008-01-01 00:41:05 C:\Program Files\QuickTime\qttask .exe ----a-w 649,728 2008-01-01 00:17:53 C:\Program Files\QuickTime\qttask .exe ----a-w 649,728 2007-12-30 16:13:40 C:\Program Files\QuickTime\qttask .exe ----a-w 649,728 2007-12-30 04:43:48 C:\Program Files\QuickTime\qttask .exe ----a-w 649,728 2007-12-30 00:59:13 C:\Program Files\QuickTime\qttask .exe ----a-w 649,728 2007-12-30 00:19:33 C:\Program Files\QuickTime\qttask .exe ----a-w 69,632 2008-01-03 00:54:27 C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4 .exe ----a-w 94,208 2008-01-03 00:53:09 C:\Program Files\SealedMedia\sealmon .exe ----a-w 688,218 2008-01-03 00:52:15 C:\Program Files\Synaptics\SynTP\SynTPEnh .exe ----a-w 98,394 2008-01-03 00:52:05 C:\Program Files\Synaptics\SynTP\SynTPLpr .exe ----a-w 204,288 2008-01-03 00:55:12 C:\Program Files\Windows Media Player\WMPNSCFG .exe ----a-w 694,008 2008-01-03 00:53:02 C:\Program Files\WinPortrait\wpctrl .exe ----a-w 208,952 2008-01-01 17:49:51 C:\WINDOWS\ime\IMJP8_1\IMJPMIG .EXE ----a-w 15,360 2007-12-31 06:42:33 C:\WINDOWS\system32\ctfmon .exe ----a-w 118,784 2008-01-03 00:52:32 C:\WINDOWS\system32\hkcmd .exe ----a-w 155,648 2008-01-03 00:52:30 C:\WINDOWS\system32\igfxtray .exe ----a-w 155,648 2008-01-03 00:54:40 C:\WINDOWS\system32\NeroCheck .exe ----a-w 544,768 2008-01-03 00:54:51 C:\WINDOWS\system32\drivers\svchost .exe ----a-w 455,168 2008-01-01 17:49:53 C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP .EXE
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3AE6082B-E0D3-446C-95CC-4EEB9D48CE46}]
2008-01-02 19:53 336384 --a------ C:\WINDOWS\system32\gebca.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2008-01-02 19:54 2226688]
"BackupNotify"="C:\Program Files\HP\Digital Imaging\bin\backupnotify.exe" [ ]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 06:00 15360]
"Windows Firewall"="C:\WINDOWS\System32\drivers\svchost.exe" [ ]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-04 06:00 208952]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 06:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 06:00 455168]
"DXDllRegExe"="dxdllreg.exe" []
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [ ]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [ ]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [ ]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [ ]
"Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" [ ]
"PivotSoftware"="C:\Program Files\WinPortrait\wpctrl.exe" [ ]
"sealmon"="C:\Program Files\SealedMedia\sealmon.exe" [ ]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [ ]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [ ]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [ ]
"DeadAIM"="C:\PROGRA~1\AIM\\DeadAIM.ocm" [2005-11-27 16:18 144896]
"hpWirelessAssistant"="C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [ ]
"SSBkgdUpdate"="C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [ ]
"OpwareSE4"="C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe" [ ]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [ ]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [ ]
"Windows Firewall"="C:\WINDOWS\System32\drivers\svchost.exe" [ ]
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe" [ ]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-07-17 19:54 116072]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 18:16:50]
BTTray.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2004-06-02 17:48:22]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2003-09-16 04:19:24]
HP Display LiteSaver Startup.lnk - C:\WINDOWS\HPLiteSaver.exe [2004-08-24 14:01:12]
[HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\windows]
"load"=C:\WINDOWS\system32\gebca.exe
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 C:\WINDOWS\system32\gebca
R1 pivot;pivot;C:\WINDOWS\system32\drivers\pivot.sys [2004-09-23 08:03]
S3 pivotmou;Pivot Mouse/Pointers Filter Driver;C:\WINDOWS\system32\drivers\pivotmou.sys [2004-09-23 08:03]
*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2007-12-09 19:02:35 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-02 19:53:35
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Windows Firewall = C:\WINDOWS\System32\drivers\svchost.exe?
scanning hidden files ...
C:\WINDOWS\system32\gebca.exe 339968 bytes executable
scan completed successfully
hidden files: 1
**************************************************************************
.
Completion time: 2008-01-02 20:00:06 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-03 01:59:54
.
2008-01-01 17:58:06 --- E O F ---