ComboFix 07-12-28.1 - Sys 2007-12-29 20:12:23.4 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.189 [GMT 0:00] Running from: C:\Documents and Settings\Sys\Desktop\Emma's PC Drivers\Virus Removal\ComboFix.exe . ((((((((((((((((((((((((( Files Created from 2007-11-28 to 2007-12-29 ))))))))))))))))))))))))))))))) . 2007-12-29 18:30 . 2007-12-29 18:30 d-------- C:\Documents and Settings\Sys\Application Data\Grisoft 2007-12-29 18:29 . 2007-12-29 18:29 d-------- C:\Documents and Settings\All Users\Application Data\Grisoft 2007-12-29 18:29 . 2007-05-30 12:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys 2007-12-29 14:40 . 2007-12-29 16:37 d-------- C:\Program Files\EsetOnlineScanner 2007-12-29 11:24 . 2007-12-29 11:24 d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com 2007-12-29 11:23 . 2007-12-29 14:31 d-------- C:\Program Files\SUPERAntiSpyware 2007-12-29 11:23 . 2007-12-29 11:23 d-------- C:\Documents and Settings\Sys\Application Data\SUPERAntiSpyware.com 2007-12-29 11:20 . 2007-12-29 11:20 d-------- C:\Program Files\Common Files\Wise Installation Wizard 2007-12-29 11:15 . 2007-12-29 11:15 d-------- C:\Program Files\CCleaner 2007-12-28 20:47 . 2007-12-28 20:47 d-------- C:\Program Files\Trend Micro 2007-12-21 00:05 . 2007-12-21 21:36 d-------- C:\Program Files\STOPzilla! 2007-12-21 00:05 . 2007-12-21 00:05 d-------- C:\Program Files\Common Files\iS3 2007-12-21 00:05 . 2007-12-29 20:16 d-------- C:\Documents and Settings\All Users\Application Data\STOPzilla! 2007-12-20 23:14 . 2007-12-20 23:14 15,360 --a------ C:\WINDOWS\system32\ctfmon .exe 2007-12-20 23:13 . 2007-12-28 22:03 155,648 --a------ C:\WINDOWS\system32\NeroCheck .exe 2007-12-20 23:13 . 2007-12-28 22:03 24,576 --a------ C:\WINDOWS\system32\FirstReboot .exe 2007-12-20 22:58 . 2007-12-29 16:18 d-------- C:\WINDOWS\system32\daSgo18 2007-12-20 22:58 . 2007-12-20 22:58 134 --a------ C:\n.bat . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2007-12-29 20:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kontiki 2007-12-29 15:33 --------- d-----w C:\Program Files\QuickTime 2007-12-29 14:30 --------- d-----w C:\Documents and Settings\Sys\Application Data\OpenOffice.org2 2007-12-28 23:05 --------- d-----w C:\Program Files\SymNetDrv 2007-12-28 23:05 --------- d-----w C:\Program Files\Kontiki 2007-12-28 23:05 --------- d-----w C:\Program Files\iTunes 2007-12-28 23:05 --------- d-----w C:\Program Files\Common Files\Symantec Shared 2007-12-27 10:44 10 ----a-w C:\Program Files\.autoreg 2007-12-22 21:27 --------- d-----w C:\Program Files\LimeWire 2007-12-22 16:22 --------- d--h--w C:\Program Files\InstallShield Installation Information 2007-12-22 15:51 --------- d-----w C:\Program Files\Symantec 2007-12-22 12:43 --------- d-----w C:\Program Files\Norton AntiVirus 2007-11-19 21:38 --------- d-----w C:\Program Files\OpenOffice.org 2.3 2007-11-14 20:25 --------- d-----w C:\Documents and Settings\Sys\Application Data\Media Player Classic 2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys 2007-11-02 23:03 --------- d-----w C:\Program Files\Channel4 2007-11-02 23:02 --------- d-----w C:\Documents and Settings\All Users\Application Data\Channel4 2007-10-29 22:43 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll 2007-10-29 18:23 --------- d-----w C:\Program Files\Java 2007-10-27 17:40 222,720 ----a-w C:\WINDOWS\system32\wmasf.dll 2007-10-05 10:11 225,280 ----a-r C:\WINDOWS\system32\SZBase5.dll 2007-10-04 22:12 107,888 ----a-w C:\WINDOWS\system32\CmdLineExt.dll 2007-10-04 21:40 442,368 ----a-w C:\WINDOWS\system32\vp6vfw.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56] "BitTorrent"="C:\Program Files\BitTorrent\bittorrent.exe" [] "SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="RUNDLL32.exe" [2004-08-04 00:56 C:\WINDOWS\system32\rundll32.exe] "SoundFusion"="RunDll32 hercplgs.cpl" [] "NvMediaCenter"="RUNDLL32.exe" [2004-08-04 00:56 C:\WINDOWS\system32\rundll32.exe] "Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [] "!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 09:25] C:\Documents and Settings\Sys\Start Menu\Programs\Startup\ OpenOffice.org 2.3.lnk - C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe [2007-08-17 22:57:56] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^LUMIX Simple Viewer.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\LUMIX Simple Viewer.lnk backup=C:\WINDOWS\pss\LUMIX Simple Viewer.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\4oD] C:\Program Files\Kontiki\KHost.exe -all [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz] nwiz.exe /install R0 hpt3xx;hpt3xx;C:\WINDOWS\system32\DRIVERS\hpt3xx.sys [2002-01-30 14:05] R0 hptpro;hptpro;C:\WINDOWS\system32\DRIVERS\hptpro.sys [2002-01-21 13:20] R3 hercspud;Hercules (R) WDM Audio Driver;C:\WINDOWS\system32\drivers\hercspud.sys [2003-01-10 08:21] R3 hercwdm;Hercules (R) WDM Interface Driver;C:\WINDOWS\system32\drivers\hercwdm.sys [2003-01-10 08:21] R3 NPDriver;Norton Unerase Protection Driver;C:\WINDOWS\system32\Drivers\NPDRIVER.SYS [2002-08-14 05:03] R3 V0090VID;Creative WebCam Vista Plus;C:\WINDOWS\system32\DRIVERS\V0090Vid.sys [2005-04-14 00:00] S3 USBCamera;DigitalCam Pro Still Camera Device;C:\WINDOWS\system32\Drivers\Bulk536.sys [] *Newly Created Service* - AVG_ANTI-SPYWARE_DRIVER *Newly Created Service* - AVG_ANTI-SPYWARE_GUARD . Contents of the 'Scheduled Tasks' folder "2006-12-18 23:30:20 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer - Sys.job" - C:\PROGRA~1\NORTON~1\NAVW32.EXEh/task: "2007-12-28 20:00:00 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer.job" - C:\PROGRA~1\NORTON~1\Navw32.exeh/task: "2007-12-29 18:36:26 C:\WINDOWS\Tasks\Symantec NetDetect.job" - C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE . ************************************************************************** catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net Rootkit scan 2007-12-29 20:16:33 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2007-12-29 20:17:54 . 2007-12-12 23:21:02 --- E O F ---