ComboFix 07-12-07.3 - Admin 2007-12-07 23:55:44.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.464 [GMT 1:00]
Running from: C:\Documents and Settings\Admin\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2007-11-07 to 2007-12-07 )))))))))))))))))))))))))))))))
.
2007-12-07 01:46 . 2007-12-07 01:46 <DIR> d-------- C:\Documents and Settings\Admin\Application Data\Grisoft
2007-12-07 01:46 . 2007-05-30 13:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-12-06 12:14 . 2007-12-06 12:14 <DIR> d-------- C:\Program Files\RegSupreme
2007-12-06 12:14 . 2007-12-06 12:14 23 --a------ C:\WINDOWS\system32\cdbffe_g.ocx
2007-12-06 12:14 . 2007-12-06 12:14 23 --ahs---- C:\WINDOWS\system32\afecbdcd6_g.dll
2007-12-06 12:05 . 2007-12-06 12:05 <DIR> d-------- C:\Program Files\CCleaner
2007-11-29 02:24 . 2007-11-29 02:24 <DIR> d-------- C:\Program Files\SDC udvikling
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-07 22:00 5,225 ----a-w C:\Program Files\hijackthis.log
2007-12-07 00:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-07 00:08 --------- d-----w C:\Program Files\SUPERAntiSpyware
2007-12-04 09:37 --------- d-----w C:\Program Files\Java
2007-11-27 15:11 --------- d-----w C:\Documents and Settings\Admin\Application Data\AVG7
2007-10-10 10:26 --------- d-----w C:\Program Files\PhotoFiltre
2007-10-08 12:27 --------- d-----w C:\Program Files\Picasa2
2005-05-23 20:35 218,112 ----a-w C:\Program Files\HJTrenamed.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 13:00]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" []
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-07-05 10:08]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 13:56]
"High Definition Audio Property Page Shortcut"="HDAudPropShortcut.exe" [2004-03-17 15:10 C:\WINDOWS\system32\Hdaudpropshortcut.exe]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-11-30 21:10]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 02:06]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe" [2007-11-07 11:24]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-09-28 02:17]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Printkey2000.lnk - C:\Program Files\PrintKey2000\Printkey2000.exe [2007-09-26 22:49:26]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL 2007-06-22 10:03 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Hurtigstart.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Hurtigstart.lnk
backup=C:\WINDOWS\pss\Adobe Reader Hurtigstart.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG7_CC]
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
2004-11-02 20:24 32768 --a------ C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
2007-07-05 10:08 1318912 --a------ C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
R2 FPMANAGER;Intel Front Panel Manager Service;"C:\Program Files\Intel\Intel Front Panel Manager\FPManager.exe"
R3 Cap7134;AVerMedia Capture;C:\WINDOWS\system32\DRIVERS\Cap7134.sys
R3 PhTVTune;Cap7134 TVTuner;C:\WINDOWS\system32\DRIVERS\PhTVTune.sys
R3 Slazldrv;SmartLink AMR_PCI Driver;C:\WINDOWS\system32\DRIVERS\slazldrv.sys
S3 FlexBios;FlexBIOS Service;\??\C:\WINDOWS\System32\Drivers\FlexBios.sys
S3 Invoker;Flash5 Invoker Service;\??\C:\WINDOWS\System32\Drivers\Invoker.sys
*Newly Created Service* - PROCEXP90
.
**************************************************************************
catchme 0.3.1318 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-12-07 23:57:56
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-07 23:58:25
.
--- E O F ---