Combo Log
ComboFix 07-11-08.1 - DeBoss 2007-11-14 22:46:03.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.594 [GMT -4:00]
Running from: E:\Documents\Downloads\Programs\ComboFix.exe
* Created a new restore point
.
Unable to gain System Privileges
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Start Menu\Live Safety Center.lnk
C:\Documents and Settings\All Users\Start Menu\Online Security Guide.lnk
C:\Documents and Settings\DeBoss\Application Data\APPATC~1
C:\Documents and Settings\DeBoss\Application Data\CROSOF~1.NET
C:\Documents and Settings\DeBoss\Application Data\FunWebProducts
C:\Documents and Settings\DeBoss\Application Data\FunWebProducts\Data\DeBoss\avatar.dat
C:\Documents and Settings\DeBoss\Application Data\inst.exe
C:\Documents and Settings\DeBoss\Application Data\PPATCH~1
C:\Documents and Settings\DeBoss\Application Data\SSTEM3~1
C:\Documents and Settings\DeBoss\Application Data\YSTEM~1
C:\Documents and Settings\DeBoss\Desktop\Live Safety Center.lnk
C:\Documents and Settings\DeBoss\Desktop\Online Security Guide.lnk
C:\Documents and Settings\DeBoss\Favorites\Online Security Guide.lnk
C:\Program Files\Common Files\appatc~1
C:\Program Files\Common Files\appatc~1\A?pPatch\
C:\Program Files\Common Files\ppatch~1
C:\Program Files\Common Files\pppatc~1
C:\Program Files\Common Files\racle~1
C:\Program Files\internet explorer\msimg32.dll
C:\Program Files\outlook
C:\Program Files\pppatc~1
C:\Program Files\scurit~1
C:\WINDOWS\crosof~1.net
C:\WINDOWS\dobe~1
C:\WINDOWS\fnts~1
C:\WINDOWS\racle~1
C:\WINDOWS\sstem3~1
C:\WINDOWS\system32\app.exe
C:\WINDOWS\system32\cryptex.dll
C:\WINDOWS\system32\drivers\fgsszoca.dat
C:\WINDOWS\system32\drivers\szoxjqmt.dat
C:\WINDOWS\system32\f3PSSavr.scr
C:\WINDOWS\system32\install.exe
C:\WINDOWS\system32\ps.exe
C:\WINDOWS\system32\regedit.com
C:\WINDOWS\system32\txgquvrb.dllbox
C:\WINDOWS\system32\ymante~1
C:\WINDOWS\wr.txt
E:\Documents\ASEMBL~1
E:\Documents\CROSOF~1
E:\Documents\RACLE~1
E:\Documents\SEMBLY~1
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_DOMAINSERVICE
-------\LEGACY_YQKFOIWP
-------\yqkfoiwp
((((((((((((((((((((((((( Files Created from 2007-10-15 to 2007-11-15 )))))))))))))))))))))))))))))))
.
2007-11-14 22:44 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-11-14 15:33 85,056 --a------ C:\WINDOWS\system32\kkhgfyvv.dll
2007-11-14 15:27 79,424 --a------ C:\WINDOWS\system32\yhmadtny.dll
2007-11-14 05:58 d-------- C:\Documents and Settings\DeBoss\Application Data\BitDownload
2007-11-13 22:57 d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-11-13 22:56 d-------- C:\Program Files\SUPERAntiSpyware
2007-11-13 22:56 d-------- C:\Documents and Settings\DeBoss\Application Data\SUPERAntiSpyware.com
2007-11-13 15:25 85,056 --a------ C:\WINDOWS\system32\upsnpaym.dll
2007-11-13 15:23 27,776 --a------ C:\WINDOWS\Hotmail-Album-8057.zip
2007-11-13 06:00 27,776 --a------ C:\WINDOWS\Hotmail-Album-9902.zip
2007-11-13 06:00 27,776 --a------ C:\WINDOWS\Hotmail-Album-8790.zip
2007-11-13 00:59 111,853 ---hs---- C:\WINDOWS\system32\mlkkj.bak2
2007-11-13 00:59 27,776 --a------ C:\WINDOWS\Hotmail-Album-4038.zip
2007-11-12 20:59 d-------- C:\Program Files\Trend Micro
2007-11-12 20:19 d-------- C:\Documents and Settings\DeBoss\Application Data\ErrorKiller
2007-11-12 18:25 27,776 --a------ C:\WINDOWS\Hotmail-Album-6966.zip
2007-11-12 16:18 27,776 --a------ C:\WINDOWS\Hotmail-Album-7334.zip
2007-11-12 05:56 58,368 --a------ C:\ak.exe
2007-11-12 01:17 27,776 --a------ C:\WINDOWS\Hotmail-Album-8980.zip
2007-11-12 01:17 27,776 --a------ C:\WINDOWS\Hotmail-Album-8437.zip
2007-11-12 00:32 27,776 --a------ C:\WINDOWS\Hotmail-Album-7017.zip
2007-11-12 00:32 27,776 --a------ C:\WINDOWS\Hotmail-Album-2166.zip
2007-11-12 00:17 d-------- C:\Program Files\Spyware Terminator
2007-11-12 00:17 d-------- C:\Program Files\Crawler
2007-11-12 00:17 d-------- C:\Documents and Settings\DeBoss\Application Data\Spyware Terminator
2007-11-12 00:17 d-------- C:\Documents and Settings\All Users\Application Data\Spyware Terminator
2007-11-11 09:46 27,776 --a------ C:\WINDOWS\Hotmail-Album-5895.zip
2007-11-10 17:30 27,776 --a------ C:\WINDOWS\Hotmail-Album-2561.zip
2007-11-10 17:30 27,776 --a------ C:\WINDOWS\Hotmail-Album-0079.zip
2007-11-09 14:21 27,776 --a------ C:\WINDOWS\Hotmail-Album-1727.zip
2007-11-09 14:21 27,776 --a------ C:\WINDOWS\Hotmail-Album-1503.zip
2007-11-09 10:33 27,776 --a------ C:\WINDOWS\Hotmail-Album-8829.zip
2007-11-09 10:33 27,776 --a------ C:\WINDOWS\Hotmail-Album-0280.zip
2007-11-09 08:49 27,776 --a------ C:\WINDOWS\Hotmail-Album-4892.zip
2007-11-09 08:49 27,776 --a------ C:\WINDOWS\Hotmail-Album-3634.zip
2007-11-08 19:27 d-------- C:\Program Files\Dcads Games Collection
2007-11-08 19:27 80,105 --a------ C:\WINDOWS\system32\dcads-remove.exe
2007-11-08 19:27 40,731 --a------ C:\WINDOWS\system32\superiorads-uninst.exe
2007-11-08 17:25 27,776 --a------ C:\WINDOWS\Hotmail-Album-3710.zip
2007-11-08 15:07 27,776 --a------ C:\WINDOWS\Hotmail-Album-6974.zip
2007-11-08 06:24 27,776 --a------ C:\WINDOWS\Hotmail-Album-7384.zip
2007-11-08 06:10 27,776 --a------ C:\WINDOWS\Hotmail-Album-3010.zip
2007-11-07 15:12 27,776 --a------ C:\WINDOWS\Hotmail-Album-4832.zip
2007-11-07 13:47 27,776 --a------ C:\WINDOWS\Hotmail-Album-8493.zip
2007-11-06 15:42 27,776 --a------ C:\WINDOWS\Hotmail-Album-3126.zip
2007-11-05 17:38 27,776 --a------ C:\WINDOWS\Hotmail-Album-2842.zip
2007-11-05 17:10 27,776 --a------ C:\WINDOWS\Hotmail-Album-6204.zip
2007-11-05 13:52 d-------- C:\Program Files\Windows Live Toolbar
2007-11-05 10:06 27,776 --a------ C:\WINDOWS\Hotmail-Album-9154.zip
2007-11-05 10:06 27,776 --a------ C:\WINDOWS\Hotmail-Album-8422.zip
2007-11-05 05:55 27,776 --a------ C:\WINDOWS\Hotmail-Album-6750.zip
2007-11-05 00:11 27,776 --a------ C:\WINDOWS\Hotmail-Album-9002.zip
2007-11-04 23:15 783,224 --a------ C:\WINDOWS\system32\aswBoot.exe
2007-11-04 23:15 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr
2007-11-04 23:15 94,416 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2007-11-04 23:15 92,848 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2007-11-04 23:15 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2007-11-04 23:15 26,624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2007-11-04 23:15 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2007-11-04 23:13 27,776 --a------ C:\WINDOWS\Hotmail-Album-3291.zip
2007-11-04 19:20 27,776 --a------ C:\WINDOWS\Hotmail-Album-0782.zip
2007-11-04 14:40 27,776 --a------ C:\WINDOWS\Hotmail-Album-5876.zip
2007-11-04 14:40 27,776 --a------ C:\WINDOWS\Hotmail-Album-1034.zip
2007-11-04 12:20 27,776 --a------ C:\WINDOWS\Hotmail-Album-4838.zip
2007-11-04 00:13 27,776 --a------ C:\WINDOWS\Hotmail-Album-0038.zip
2007-11-03 20:42 27,776 --a------ C:\WINDOWS\Hotmail-Album-9532.zip
2007-11-03 19:49 27,776 --a------ C:\WINDOWS\Hotmail-Album-1822.zip
2007-11-03 15:06 27,776 --a------ C:\WINDOWS\Hotmail-Album-4785.zip
2007-11-02 17:03 27,776 --a------ C:\WINDOWS\Hotmail-Album-0378.zip
2007-11-02 15:04 27,776 --a------ C:\WINDOWS\Hotmail-Album-6901.zip
2007-11-01 20:59 27,776 --a------ C:\WINDOWS\Hotmail-Album-4806.zip
2007-11-01 18:01 27,776 --a------ C:\WINDOWS\Hotmail-Album-7299.zip
2007-11-01 17:08 27,776 --a------ C:\WINDOWS\Hotmail-Album-8731.zip
2007-11-01 16:48 27,776 --a------ C:\WINDOWS\Hotmail-Album-7386.zip
2007-11-01 15:09 27,776 --a------ C:\WINDOWS\Hotmail-Album-1832.zip
2007-10-31 21:49 27,776 --a------ C:\WINDOWS\Hotmail-Album-5831.zip
2007-10-31 16:23 27,776 --a------ C:\WINDOWS\Hotmail-Album-4462.zip
2007-10-31 16:22 27,776 --a------ C:\WINDOWS\Hotmail-Album-4489.zip
2007-10-24 09:47 61,532 --a------ C:\report.zip
2007-10-17 13:23 10,752 --a------ C:\WINDOWS\system32\WhoisCL.exe
2007-10-16 19:41 d-------- C:\Documents and Settings\Default User\Application Data\Gtek
2007-10-16 19:41 d-------- C:\Documents and Settings\Administrator\Application Data\Gtek
2007-10-16 19:40 d-------- C:\Program Files\Linksys EasyLink Advisor
2007-10-16 19:40 1,922,048 --a------ C:\WINDOWS\system32\gdql_lsa.dll
2007-10-16 19:40 135,168 --a------ C:\WINDOWS\system32\GoProto.dll
2007-10-16 19:40 28,672 --a------ C:\WINDOWS\system32\drivers\goprot51.sys
2007-10-16 19:40 6,977 --a------ C:\WINDOWS\system32\DDMI2.sys
2007-10-16 19:40 6,656 --a------ C:\WINDOWS\system32\DLPT2.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-15 02:21 --------- d-----w C:\Documents and Settings\DeBoss\Application Data\DMCache
2007-11-14 11:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-11-14 07:08 --------- d-----w C:\Documents and Settings\DeBoss\Application Data\MegauploadToolbar
2007-11-14 02:56 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-11-11 21:58 --------- d-----w C:\Documents and Settings\DeBoss\Application Data\LimeWire
2007-11-05 21:40 --------- d-----w C:\Program Files\MSN Messenger
2007-11-05 14:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2007-10-27 01:51 --------- d-----w C:\Documents and Settings\DeBoss\Application Data\Vso
2007-10-20 20:24 --------- d-----w C:\Documents and Settings\DeBoss\Application Data\axis title
2007-10-16 23:41 --------- d--ha-w C:\Documents and Settings\All Users\Application Data\GTek
2007-10-16 23:41 --------- d--h--w C:\Documents and Settings\DeBoss\Application Data\GTek
2007-10-14 21:08 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-10-10 23:34 --------- d-----w C:\Program Files\MegauploadToolbar
2007-10-10 21:27 --------- d-----w C:\Program Files\Hewlett-Packard
2007-10-05 22:32 --------- d-----w C:\Program Files\Common Files\Motive
2007-10-03 01:50 --------- d-----w C:\Program Files\GameSpy Arcade
2007-10-02 21:55 --------- d-----w C:\Program Files\Alwil Software
2007-10-01 22:55 5,693 ----a-w C:\Program Files\DOWNLOAD_INSTALL.LOG
2007-09-24 05:18 --------- d-----w C:\Documents and Settings\DeBoss\Application Data\CyberLink
2007-09-24 05:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\CyberLink
2007-09-24 05:07 --------- d-----w C:\Program Files\CyberLink
2007-09-21 02:16 --------- d-----w C:\Program Files\Winamp
2007-09-21 02:16 --------- d-----w C:\Program Files\Common Files\NSV
2007-09-18 13:27 --------- d-----w C:\Program Files\Common Files\Adobe
2007-09-18 13:06 --------- d-----w C:\Program Files\Common Files\Hewlett-Packard
2007-08-14 00:29 209 ----a-w C:\Documents and Settings\DeBoss\9546.bat
2007-08-13 20:52 209 ----a-w C:\Documents and Settings\DeBoss\2986.bat
2007-08-13 17:51 209 ----a-w C:\Documents and Settings\DeBoss\5871.bat
2007-08-09 20:13 209 ----a-w C:\Documents and Settings\DeBoss\3903.bat
2007-08-09 10:55 167 ----a-w C:\Documents and Settings\DeBoss\3641.bat
2007-08-09 03:09 167 ----a-w C:\Documents and Settings\DeBoss\8016.bat
2007-08-08 19:19 167 ----a-w C:\Documents and Settings\DeBoss\6582.bat
2007-08-08 19:14 167 ----a-w C:\Documents and Settings\DeBoss\8835.bat
2007-08-07 13:50 167 ----a-w C:\Documents and Settings\DeBoss\3436.bat
2007-08-06 23:20 167 ----a-w C:\Documents and Settings\DeBoss\1939.bat
2007-08-06 11:01 167 ----a-w C:\Documents and Settings\DeBoss\9507.bat
2007-08-06 03:19 167 ----a-w C:\Documents and Settings\DeBoss\1689.bat
2007-08-05 13:36 167 ----a-w C:\Documents and Settings\DeBoss\7231.bat
2007-08-04 21:13 167 ----a-w C:\Documents and Settings\DeBoss\3623.bat
2007-08-04 19:27 167 ----a-w C:\Documents and Settings\DeBoss\6217.bat
2007-08-04 14:51 167 ----a-w C:\Documents and Settings\DeBoss\9639.bat
2007-08-04 03:12 167 ----a-w C:\Documents and Settings\DeBoss\3754.bat
2007-08-03 21:20 167 ----a-w C:\Documents and Settings\DeBoss\2357.bat
2007-08-03 17:50 167 ----a-w C:\Documents and Settings\DeBoss\9928.bat
2007-08-03 16:40 167 ----a-w C:\Documents and Settings\DeBoss\2330.bat
2007-08-03 15:47 167 ----a-w C:\Documents and Settings\DeBoss\4398.bat
2007-08-03 12:33 167 ----a-w C:\Documents and Settings\DeBoss\9393.bat
2007-08-03 10:06 167 ----a-w C:\Documents and Settings\DeBoss\7758.bat
2007-08-03 03:04 167 ----a-w C:\Documents and Settings\DeBoss\3731.bat
2007-08-02 22:34 167 ----a-w C:\Documents and Settings\DeBoss\5641.bat
2007-08-01 14:46 167 ----a-w C:\Documents and Settings\DeBoss\5166.bat
2007-07-30 20:29 167 ----a-w C:\Documents and Settings\DeBoss\5568.bat
2007-07-30 12:05 167 ----a-w C:\Documents and Settings\DeBoss\9492.bat
2007-07-30 10:13 167 ----a-w C:\Documents and Settings\DeBoss\9322.bat
2007-07-29 14:16 167 ----a-w C:\Documents and Settings\DeBoss\8814.bat
2007-07-28 21:39 167 ----a-w C:\Documents and Settings\DeBoss\7855.bat
2007-07-28 18:33 167 ----a-w C:\Documents and Settings\DeBoss\1475.bat
2007-07-28 03:18 167 ----a-w C:\Documents and Settings\DeBoss\2014.bat
2007-07-17 21:51 47,360 ----a-w C:\Documents and Settings\DeBoss\Application Data\pcouffin.sys
2007-06-13 15:33 167 ----a-w C:\Documents and Settings\DeBoss\8564.bat
2007-06-12 20:28 167 ----a-w C:\Documents and Settings\DeBoss\6621.bat
2007-06-11 18:27 167 ----a-w C:\Documents and Settings\DeBoss\4796.bat
2007-06-11 02:46 167 ----a-w C:\Documents and Settings\DeBoss\8570.bat
2007-06-11 01:02 167 ----a-w C:\Documents and Settings\DeBoss\5511.bat
2007-06-10 16:54 167 ----a-w C:\Documents and Settings\DeBoss\5470.bat
2007-06-10 03:00 167 ----a-w C:\Documents and Settings\DeBoss\3341.bat
2007-06-09 15:48 167 ----a-w C:\Documents and Settings\DeBoss\4002.bat
2007-06-08 19:08 167 ----a-w C:\Documents and Settings\DeBoss\5180.bat
2007-06-08 02:11 167 ----a-w C:\Documents and Settings\DeBoss\6724.bat
2007-06-08 00:44 167 ----a-w C:\Documents and Settings\DeBoss\8228.bat
2007-06-07 15:44 167 ----a-w C:\Documents and Settings\DeBoss\8061.bat
2007-06-06 20:02 167 ----a-w C:\Documents and Settings\DeBoss\1540.bat
2007-06-05 21:40 167 ----a-w C:\Documents and Settings\DeBoss\5893.bat
2007-06-04 22:18 167 ----a-w C:\Documents and Settings\DeBoss\4485.bat
2007-06-04 22:03 167 ----a-w C:\Documents and Settings\DeBoss\5640.bat
2007-06-04 21:48 167 ----a-w C:\Documents and Settings\DeBoss\7344.bat
2007-06-04 21:33 167 ----a-w C:\Documents and Settings\DeBoss\1628.bat
2007-06-04 21:18 167 ----a-w C:\Documents and Settings\DeBoss\2763.bat
2007-06-04 17:41 167 ----a-w C:\Documents and Settings\DeBoss\2339.bat
2007-06-04 03:15 167 ----a-w C:\Documents and Settings\DeBoss\1545.bat
2007-06-03 22:27 167 ----a-w C:\Documents and Settings\DeBoss\9553.bat
2007-06-03 22:12 167 ----a-w C:\Documents and Settings\DeBoss\7465.bat
2007-06-03 21:57 167 ----a-w C:\Documents and Settings\DeBoss\9334.bat
2007-06-03 21:42 167 ----a-w C:\Documents and Settings\DeBoss\9836.bat
2007-06-03 21:27 167 ----a-w C:\Documents and Settings\DeBoss\1655.bat
2007-06-03 20:57 167 ----a-w C:\Documents and Settings\DeBoss\1350.bat
2007-06-03 20:42 167 ----a-w C:\Documents and Settings\DeBoss\3420.bat
2007-06-03 20:26 167 ----a-w C:\Documents and Settings\DeBoss\5934.bat
2007-06-03 18:47 167 ----a-w C:\Documents and Settings\DeBoss\3895.bat
2007-05-30 20:51 167 ----a-w C:\Documents and Settings\DeBoss\6439.bat
2007-05-30 14:54 167 ----a-w C:\Documents and Settings\DeBoss\2582.bat
2007-05-30 14:09 167 ----a-w C:\Documents and Settings\DeBoss\1216.bat
2007-05-30 14:00 167 ----a-w C:\Documents and Settings\DeBoss\9155.bat
2007-05-30 03:31 167 ----a-w C:\Documents and Settings\DeBoss\2322.bat
2007-05-30 01:44 167 ----a-w C:\Documents and Settings\DeBoss\1706.bat
2007-05-29 19:17 167 ----a-w C:\Documents and Settings\DeBoss\5021.bat
2007-05-28 21:41 167 ----a-w C:\Documents and Settings\DeBoss\9254.bat
2007-05-28 00:24 167 ----a-w C:\Documents and Settings\DeBoss\9740.bat
2007-05-27 19:28 167 ----a-w C:\Documents and Settings\DeBoss\7260.bat
2007-05-27 02:17 167 ----a-w C:\Documents and Settings\DeBoss\2799.bat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2004-08-10 08:04]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2004-10-27 19:21 C:\WINDOWS\system32\HdAShCut.exe]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2005-05-19 21:11]
"SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\smax4.exe" [2005-09-07 19:35]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-11-09 23:25]
"nwiz"="nwiz.exe" [2006-11-09 23:26 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-11-09 23:26]
"SMSERIAL"="sm56hlpr.exe" [2004-12-28 18:01 C:\WINDOWS\sm56hlpr.exe]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 04:47]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe" [2005-08-26 22:14]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-03-21 19:26]
"iTunesHelper"="P:\Program Files\iTunes\iTunesHelper.exe" [2006-02-23 15:45]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 15:40]
"Motive SmartBridge"="C:\PROGRA~1\TSTTQU~1\SMARTB~1\MotiveSB.exe" [2006-06-27 13:03]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 18:30]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2007-01-08 22:26]
"LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [2007-01-08 22:17]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-07-27 18:03]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 08:00]
"CursorXP"="P:\Program Files\CursorXP\CursorXP.exe" [2005-01-19 16:34]
"DrvMon.exe"="C:\WINDOWS\system32\DrvMon.exe" [2004-09-09 22:16]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-11-16 19:04]
"NVIDIA nTune"="P:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-04-04 14:20]
"BitDownload"="P:\Program Files\BitDownload\BitDownload.exe" []
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-06-20 22:36]
"IDMan"="D:\Program Files\Reget\IDMan.exe" [2006-11-19 06:05]
"EasyLinkAdvisor"="C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" [2006-10-30 11:01]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06]
C:\Documents and Settings\DeBoss\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-27 00:24:54]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
InterVideo WinCinema Manager.lnk - P:\Common\Bin\WinCinemaMgr.exe [2007-03-15 17:33:03]
PowerMenu.lnk - C:\Program Files\PowerMenu\PowerMenu.exe [2007-03-14 13:28:04]
TSTT Quick Assist.lnk - C:\Program Files\TSTT Quick Assist\bin\matcli.exe [2007-07-25 22:49:37]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoFileMenu"=1 (0x1)
"NoResolveTrack"=1 (0x1)
"NoChangeKeyboardNavigationIndicators"=0 (0x0)
"NoViewOnDrive"=0 (0x0)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{FBF23B40-E3F0-101B-8488-00AA003E56F8}"= C:\WINDOWS\system32\ieframe.dll [2007-08-20 06:04 6058496]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
P:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\wbsrv.dll 2005-12-06 21:16 176128 P:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\WbSrv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=wbsys.dll
R1 nvport;NVIDIA PORT IO Control Driver;\??\C:\WINDOWS\system32\Drivers\nvport.sys
R3 AEAudioService;AEAudio Service;C:\WINDOWS\system32\drivers\AEAudio.sys
S1 SysTool;SysTool Overclocking Utility;C:\WINDOWS\system32\DRIVERS\SysTool.sys
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{54d18298-e14b-11db-8145-812a2c4397e8}]
\Shell\AutoRun\command - H:\loader.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6bfd0b02-e6f2-11db-8169-c3b208b5aa2d}]
\Shell\AutoRun\command - setupSNK.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9dd8cad2-31a0-11dc-837a-b7bf559dc89d}]
\Shell\Auto\command - H:\boot.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL boot.exe
.
Contents of the 'Scheduled Tasks' folder
"2007-11-14 07:30:00 C:\WINDOWS\Tasks\ErrorKiller Scheduled Scan.job"
- C:\Program Files\ErrorKiller\ErrorKiller.exe
.
**************************************************************************
catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-11-14 23:02:27
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-14 23:04:43 - machine was rebooted
.
--- E O F ---