and the second part…
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-07-22 18:09 --------- d-------- C:\Program Files\Winamp
2007-07-22 18:08 --------- d–h----- C:\Program Files\InstallShield Installation Information
2007-07-22 18:08 --------- d-------- C:\Program Files\CyberLink
2007-07-22 18:08 --------- d-------- C:\Program Files\Common Files\InstallShield
2007-07-22 18:07 --------- d-------- C:\Program Files\Prolific Publishing, Inc
2007-07-22 17:50 47399 --a------ C:\WINDOWS\BricoPackUninst.cmd
2007-07-22 17:50 218624 --a------ C:\WINDOWS\system32\uxtheme.dll
2007-07-22 17:50 218624 --a------ C:\WINDOWS\system32\dllcache\uxtheme.dll
2007-07-22 17:50 2165 --a------ C:\WINDOWS\BricoPackFoldersDelete.cmd
2007-07-22 17:44 --------- d-------- C:\Program Files\Speed Disk
2007-07-22 17:44 --------- d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\Symantec
2007-07-22 17:43 --------- d-------- C:\Program Files\Symantec
2007-07-22 17:43 --------- d-------- C:\Program Files\Norton Utilities
2007-07-22 17:43 --------- d-------- C:\Program Files\Common Files\Symantec Shared
2007-07-22 17:41 --------- d-------- C:\Program Files\Common Files\ACD Systems
2007-07-22 17:36 --------- d-------- C:\Program Files\Microsoft ActiveSync
2007-07-22 17:26 2722 --a------ C:\WINDOWS\pchealth\helpctr\PackageStore\SkuStore.bin
2007-07-22 17:15 8972 --a------ C:\WINDOWS\pchealth\helpctr\Config\Cntstore.bin
2007-07-22 16:54 0 -rahs---- C:\MSDOS.SYS
2007-07-22 16:54 0 -rahs---- C:\IO.SYS
2007-07-22 16:54 0 --a------ C:\CONFIG.SYS
2007-07-22 16:54 0 --a------ C:\AUTOEXEC.BAT
2007-07-22 16:54 --------- d-------- C:\Program Files\microsoft frontpage
2007-07-22 16:52 --------- d–h----- C:\Program Files\WindowsUpdate
2007-07-22 16:51 --------- d-------- C:\Program Files\Movie Maker
2007-07-22 16:51 --------- d-------- C:\Program Files\Common Files\MSSoap
2007-07-22 16:50 --------- d-------- C:\Program Files\Online Services
2007-07-22 16:50 --------- d-------- C:\Program Files\MSN Gaming Zone
2007-07-22 16:50 --------- d-------- C:\Program Files\Messenger
2007-07-22 16:49 --------- d-------- C:\Program Files\Windows NT
2007-07-22 16:45 --------- d-------- C:\Program Files\Common Files\SpeechEngines
2007-07-22 16:45 --------- d-------- C:\Program Files\Common Files\ODBC
2007-05-25 15:22 24000 --a------ C:\WINDOWS\system32\lmimirr.dll
2007-05-25 15:22 10304 --a------ C:\WINDOWS\system32\lmimirr2.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
Note empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“IgfxTray”=“C:\WINDOWS\system32\igfxtray.exe” [2006-09-13 11:54]
“SoundMan”=“SOUNDMAN.EXE” [2005-02-23 17:13 C:\WINDOWS\SOUNDMAN.EXE]
“HP Software Update”=“C:\Program Files\HP\HP Software Update\HPWuSchd2.exe” [2005-12-15 11:18]
“LogMeIn GUI”=“C:\Program Files\LogMeIn\x86\LogMeInSystray.exe” [2007-04-17 14:03]
“SunJavaUpdateSched”=“C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe” [2004-09-28 20:26]
“avast!”=“C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe” [2007-07-28 05:03]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“Skype”=“C:\Program Files\Skype\Phone\Skype.exe” [2007-06-08 15:18]
“MSMSGS”=“C:\Program Files\Messenger\msmsgs.exe” [2004-08-04 01:06]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2005-12-15 11:40:44]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
“NoActiveDesktop”=1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
LMIinit.dll 2007-05-25 15:22 63040 C:\WINDOWS\system32\LMIinit.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Norton System Doctor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Norton System Doctor.lnk
backup=C:\WINDOWS\pss\Norton System Doctor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
“C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe”
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
C:\Program Files\Winamp\winampa.exe
R2 LMIInfo;LogMeIn Kernel Information Provider;??\C:\Program Files\LogMeIn\x86\RaInfo.sys
R2 LMIRfsDriver;LogMeIn Remote File System Driver;??\C:\WINDOWS\system32\drivers\LMIRfsDriver.sys
R3 lmimirr;lmimirr;C:\WINDOWS\system32\DRIVERS\lmimirr.sys
R3 NPDriver;Norton Unerase Protection Driver;??\C:\WINDOWS\system32\Drivers\NPDRIVER.SYS
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-23 11:43:26
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
Completion time: 2007-08-23 11:44:05
--- E O F ---
after he run Cure It but he didn’t find virus :-\