Here are the results of the scans
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 9:21:28 PM, on 8/24/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal
Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\WINDOWS\system32\Ati2evxx.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\Program Files\Norton AntiVirus\navapsvc.exe C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe C:\Program Files\Dell\QuickSet\quickset.exe C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\WINDOWS\stsystra.exe C:\DOCUME~1\xx\LOCALS~1\Temp\200782211158_mcinfo.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe C:\Program Files\DellSupport\DSAgnt.exe C:\Program Files\Webshots\WebshotsTray.exe C:\Program Files\Common Files\Teleca Shared\Generic.exe C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\WINDOWS\explorer.exe C:\WINDOWS\system32\notepad.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
O2 - BHO: MyWay Search Assistant BHO - {04079851-5845-4dea-848C-3ECD647AA554} - C:\Program Files\MyWay\SrchAstt\1.bin\MYSRCHAS.DLL O2 - BHO: myBar BHO - {0494D0D1-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll O3 - Toolbar: &SearchBar - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe O4 - HKLM\..\Run: [mmlucj] C:\WINDOWS\system32\severe.exe O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll" O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\WebshotsTray.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1188011293859O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cabO20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe
-- End of file - 8132 bytes
********************************* ROOTCHK-(22-08-07)-LOG, by ejvindh Fri 08/24/2007 21:16:47.60
The rootkits that are detected by this tool were not found.
********************************* ROOTCHK-LOG-end
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.netRootkit scan 2007-08-24 21:16:47 Windows 5.1.2600 Service Pack 2 scanning hidden processes ...
scanning hidden services & system hive ... [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\a347scsi\Config\jdgg40] "ujdew"=hex:20,02,00,00,2e,e4,69,91,fc,b9,38,73,aa,ac,44,ee,fd,6d,62,5c,6e,.. "ljej40"=hex:61,e8,a8,de,15,f0,52,9a,b5,31,75,28,fa,84,ba,f4,5a,54,e1,cb,64,..
scanning hidden registry entries ... [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E9F81423-211E-46B6-9AE0-38568BC5CF6F}] "DisplayName"="Alcohol 120(Trial Version)"
scanning hidden files ...
hidden processes: 0 hidden files: 0
ComboFix 07-08-17.2 - "xx" 2007-08-24 21:18:08.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.136 [GMT -7:00]
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\autorun.inf
((((((((((((((((((((((((( Files Created from 2007-07-25 to 2007-08-25 )))))))))))))))))))))))))))))))
2007-08-24 21:17 51,200 --a------ C:\WINDOWS\nircmd.exe 2007-08-24 19:32 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys 2007-08-24 18:13 <DIR> d----c--- C:\DOCUME~1\xx\APPLIC~1\SUPERAntiSpyware.com 2007-08-24 18:13 <DIR> d----c--- C:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com 2007-08-24 18:13 <DIR> d-------- C:\Program Files\SUPERAntiSpyware 2007-08-24 18:08 <DIR> d-------- C:\Program Files\CCleaner 2007-08-24 17:37 <DIR> d-------- C:\Program Files\Trend Micro 2007-08-24 17:02 524,288 --ah----- C:\DOCUME~1\ADMINI~1\NTUSER.DAT 2007-08-24 15:18 <DIR> d----c--- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab 2007-08-24 15:18 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab 2007-08-23 13:56 5,248 --a------ C:\WINDOWS\system32\drivers\a347scsi.sys 2007-08-23 13:56 160,640 --a------ C:\WINDOWS\system32\drivers\a347bus.sys 2007-08-23 13:56 <DIR> d-------- C:\Program Files\Alcohol Soft 2007-08-23 13:39 494,796 --a------ C:\WINDOWS\system32\Daily 6 Bikini.scr 2007-08-23 13:27 414,558 --a------ C:\WINDOWS\CAlogoscreensaver.exe 2007-08-23 13:27 108,456 --a------ C:\WINDOWS\CAlogoscreensaver.scr 2007-08-23 13:26 571,455 --a------ C:\WINDOWS\WRX - STREET.exe 2007-08-23 13:26 409,292 --a------ C:\WINDOWS\WRX - TECH.exe 2007-08-23 13:26 40,960 --a------ C:\WINDOWS\WRX - TECH.dll 2007-08-23 13:26 40,960 --a------ C:\WINDOWS\WRX - STREET.dll 2007-08-23 13:26 40,960 --a------ C:\WINDOWS\Bmw Z4 Autumn.dll 2007-08-23 13:26 305,092 --a------ C:\WINDOWS\Bmw Z4 Autumn.scr 2007-08-23 13:26 260,116 --a------ C:\WINDOWS\WRX - TECH.scr 2007-08-23 13:26 260,116 --a------ C:\WINDOWS\WRX - STREET.scr 2007-08-23 13:26 18,192 --a------ C:\WINDOWS\WRX - TECH.dat 2007-08-23 13:26 18,192 --a------ C:\WINDOWS\WRX - STREET.dat 2007-08-23 13:26 18,192 --a------ C:\WINDOWS\Bmw Z4 Autumn.dat 2007-08-23 13:26 1,092,971 --a------ C:\WINDOWS\Bmw Z4 Autumn.exe 2007-08-23 13:24 412,160 --a------ C:\WINDOWS\system32\Montana.scr 2007-08-23 13:24 29,184 --a------ C:\WINDOWS\system32\sstunins.exe 2007-08-23 13:21 497,152 --a------ C:\WINDOWS\system32\Naomi Campbell Semi-Nude.scr 2007-08-23 13:16 584,704 --a------ C:\WINDOWS\system32\TLC Screen Saver.scr 2007-08-23 13:16 283,648 --a------ C:\WINDOWS\system32\uninstall.exe 2007-08-23 13:16 149,504 --a------ C:\WINDOWS\system32\Mpegdll.dll 2007-08-23 13:12 1,036,337 --a------ C:\WINDOWS\watrfall.scr 2007-08-23 13:12 <DIR> d-------- C:\WINDOWS\un 2007-08-23 13:11 400,896 --a------ C:\WINDOWS\system32\Tigers.scr 2007-08-23 13:11 29,184 --a------ C:\WINDOWS\system32\sstunst2.exe 2007-08-23 13:06 94,208 --a------ C:\WINDOWS\system32\ScrUnZip.dll 2007-08-23 13:06 129,536 --a------ C:\WINDOWS\system32\IJL15.dll 2007-08-23 13:05 979,774 --a------ C:\WINDOWS\system32\Hotties.exe 2007-08-23 13:05 905,853 --a------ C:\WINDOWS\Hotties.scr 2007-08-23 13:05 <DIR> d-------- C:\Program Files\MyWay 2007-08-23 12:53 7,680 --a------ C:\WINDOWS\system32\drivers\vidstub.sys 2007-08-23 12:53 <DIR> d-------- C:\Program Files\Stardock 2007-08-23 12:53 <DIR> d-------- C:\Program Files\Common Files\Stardock 2007-08-23 11:39 <DIR> d-a--c--- C:\Temp\installtemped 2007-08-23 11:39 <DIR> d----c--- C:\Temp 2007-08-23 11:14 <DIR> d--h----- C:\WINDOWS\PIF 2007-08-23 11:09 <DIR> d----c--- C:\DOCUME~1\xx\APPLIC~1\Symantec 2007-08-23 11:05 10,344 --a------ C:\WINDOWS\system32\drivers\symlcbrd.sys 2007-08-23 11:05 <DIR> d-------- C:\Program Files\Norton AntiVirus 2007-08-23 11:04 48,776 --a------ C:\WINDOWS\system32\S32EVNT1.DLL 2007-08-23 11:04 115,000 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS 2007-08-23 11:04 <DIR> d----c--- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec 2007-08-23 11:04 <DIR> d-------- C:\Program Files\Symantec 2007-08-23 11:03 <DIR> d-------- C:\Program Files\Common Files\Symantec Shared 2007-08-22 12:24 <DIR> d-------- C:\Program Files\VirtualDJ 2007-08-22 12:00 <DIR> d----c--- C:\DOCUME~1\xx\APPLIC~1\TuneUp Software 2007-08-22 12:00 <DIR> d-------- C:\Program Files\TuneUp Utilities 2006 2007-08-22 12:00 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard 2007-08-21 19:00 86,016 -ra------ C:\WINDOWS\system32\mdmxsdk.dll 2007-08-21 19:00 718,464 -ra------ C:\WINDOWS\system32\drivers\HSF_CNXT.sys 2007-08-21 19:00 201,600 -ra------ C:\WINDOWS\system32\drivers\HSFHWAZL.sys 2007-08-21 19:00 12,544 -ra------ C:\WINDOWS\system32\drivers\mdmxsdk.sys 2007-08-21 19:00 110,592 -ra------ C:\WINDOWS\system32\uci32101.dll 2007-08-21 19:00 1,035,008 -ra------ C:\WINDOWS\system32\drivers\HSF_DPV.sys 2007-08-21 19:00 <DIR> d-------- C:\Program Files\CONEXANT 2007-08-21 18:54 23,600 --a------ C:\WINDOWS\system32\drivers\TVICHW32.SYS 2007-08-21 15:06 89,360 --a------ C:\WINDOWS\system32\VB5DB.DLL 2007-08-21 15:03 41,728 --a------ C:\WINDOWS\system32\drivers\sfng32.sys 2007-08-21 15:03 <DIR> d-------- C:\Program Files\Intel Desktop Board 2007-08-20 19:50 43,352 --a------ C:\WINDOWS\system32\wups2.dll 2007-08-20 19:50 <DIR> d-------- C:\WINDOWS\system32\SoftwareDistribution 2007-08-20 19:02 46,816 --a------ C:\WINDOWS\system32\qq3.exe 2007-08-20 18:23 666 --a------ C:\WINDOWS\speed.reg 2007-08-20 18:10 <DIR> d-------- C:\Program Files\Intel 2007-08-20 17:33 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe 2007-08-20 17:33 145,920 --a------ C:\WINDOWS\system32\drivers\Hdaudio.sys 2007-08-20 17:33 138,752 --a------ C:\WINDOWS\system32\drivers\Hdaudbus.sys 2007-08-20 17:30 <DIR> d-------- C:\Program Files\DIFX 2007-08-20 16:43 94,299 --a------ C:\WINDOWS\system32\SynTPAPI.dll 2007-08-20 16:43 82,014 --a------ C:\WINDOWS\system32\SynCOM.dll 2007-08-20 16:43 81,920 --a------ C:\WINDOWS\system32\SynTPCo2.dll 2007-08-20 16:43 69,723 --a------ C:\WINDOWS\system32\SynTPFcs.dll 2007-08-20 16:43 191,872 --a------ C:\WINDOWS\system32\drivers\SynTP.sys 2007-08-20 16:43 114,688 --a------ C:\WINDOWS\system32\SynCtrl.dll 2007-08-20 16:43 <DIR> d-------- C:\Program Files\Synaptics 2007-08-20 16:38 <DIR> d----c--- C:\DOCUME~1\xx\APPLIC~1\ATI 2007-08-20 16:31 <DIR> d-------- C:\Program Files\ATI Technologies 2007-08-20 16:29 <DIR> d----c--- C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink 2007-08-20 15:11 <DIR> d-------- C:\WINDOWS\system32\ReinstallBackups 2007-08-20 14:45 <DIR> d----c--- C:\DOCUME~1\xx\APPLIC~1\GTek 2007-08-20 14:45 <DIR> d----c--- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Gtek 2007-08-20 14:45 <DIR> d-------- C:\Program Files\DellSupport 2007-08-20 14:40 <DIR> d-------- C:\Program Files\Digital Line Detect 2007-08-20 14:15 <DIR> d-------- C:\Program Files\Dell 2007-08-20 14:14 16,128 --a------ C:\WINDOWS\system32\drivers\APPDRV.SYS 2007-08-20 14:14 <DIR> d----c--- C:\DOCUME~1\xx\APPLIC~1\InstallShield 2007-08-19 10:59 <DIR> d----c--- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo! Companion
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-08-24 16:16 806 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.INF 2007-08-24 16:16 8014 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.CAT 2007-08-21 17:08 509 --a------ C:\WINDOWS\system32\drivers\sthdae.log 2007-08-21 15:06 --------- d--h----- C:\Program Files\InstallShield Installation Information 2007-08-20 18:24 5 --a------ C:\WINDOWS\system32\drivers\DELL_XPS_MM061 .MRK 2007-08-20 18:24 5 --a------ C:\WINDOWS\system32\drivers\1028_DELL_XPS_MM061 .MRK 2007-08-09 19:17 163644 --a------ C:\WINDOWS\system32\drivers\secdrv.sys 2007-07-30 19:19 92504 --a------ C:\WINDOWS\system32\cdm.dll 2007-07-30 19:19 549720 --a------ C:\WINDOWS\system32\wuapi.dll 2007-07-30 19:19 53080 --a------ C:\WINDOWS\system32\wuauclt.exe 2007-07-30 19:19 325976 --a------ C:\WINDOWS\system32\wucltui.dll 2007-07-30 19:19 203096 --a------ C:\WINDOWS\system32\wuweb.dll 2007-07-30 19:19 1712984 --a------ C:\WINDOWS\system32\wuaueng.dll 2007-07-30 19:18 33624 --a------ C:\WINDOWS\system32\wups.dll 2007-06-12 11:47 2722 --a------ C:\WINDOWS\pchealth\helpctr\PackageStore\SkuStore.bin 2007-06-12 11:46 8972 --a------ C:\WINDOWS\pchealth\helpctr\Config\Cntstore.bin 2007-05-31 09:31 0 -rahsc--- C:\MSDOS.SYS 2007-05-31 09:31 0 -rahsc--- C:\IO.SYS 2007-05-31 09:31 0 --a--c--- C:\CONFIG.SYS 2007-05-31 09:31 0 --a--c--- C:\AUTOEXEC.BAT
((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 16:40] "DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-04-26 08:04] "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-08-13 22:44] "Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2005-10-26 16:17] "Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2007-02-20 12:29] "ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 17:41] "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 12:48] "SigmatelSysTrayApp"="stsystra.exe" [2005-11-16 15:35 C:\WINDOWS\stsystra.exe] "mmlucj"="C:\WINDOWS\system32\severe.exe" [] "ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-22 22:19] "Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 18:30] "!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 02:25]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-08-04 01:06] "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-06-01 13:32] "DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 12:09]
C:\Documents and Settings\xx\Start Menu\Programs\Startup\ Webshots.lnk - C:\Program Files\Webshots\WebshotsTray.exe [2007-07-26 02:25:45]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] "{A93A4625-6216-499C-B360-BBD0A7C0D479}"= C:\Program Files\Common Files\Microsoft Shared\MSINFO\QQGS1.dll [2007-08-20 19:02 240747] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
*Newly Created Service* - AVGASCLN
Contents of the 'Scheduled Tasks' folder 2007-08-22 19:00:42 C:\WINDOWS\Tasks\1-Click Maintenance.job - C:\Program Files\TuneUp Utilities 2006\SystemOptimizer.exe 2007-08-25 03:01:05 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - xx.job - C:\PROGRA~1\NORTON~1\Navw32.exe
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.netRootkit scan 2007-08-24 21:19:49 Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully hidden files: 0
**************************************************************************
Completion time: 2007-08-24 21:20:28 C:\ComboFix-quarantined-files.txt ... 2007-08-24 21:20
--- E O F ---
|