ComboFix 07-06-13.3 - C:\Documents and Settings\Chris\Desktop\AntiVirus Tools\ComboFix.exe
"Chris" - 2007-07-11 22:31:11 - Service Pack 2 NTFS
((((((((((((((((((((((((( Files Created from 2007-06-12 to 2007-07-12 )))))))))))))))))))))))))))))))
2007-07-10 23:06 53,760 --a------ C:\WINDOWS\system32\vfwwdm32.dll
2007-07-03 22:31 374,752 --a------ C:\WINDOWS\system32\WUSBGXP.sys
2007-07-03 22:31 339,488 --a------ C:\WINDOWS\system32\WUSB20XP.sys
2007-07-03 22:31 245,376 --a------ C:\WINDOWS\system32\rt2500usb.sys
2007-07-03 22:31 20,747 --a------ C:\WINDOWS\system32\drivers\AegisP.sys
2007-07-03 22:31 <DIR> d-------- C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor
2007-06-30 18:03 24,576 --a------ C:\WINDOWS\system32\VundoFixSVC.exe
2007-06-28 21:53 <DIR> d--hs---- C:\WINDOWS\CSC
2007-06-25 23:37 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-06-25 22:11 178,688 --a------ C:\DOCUME~1\Colleen\gold.exe
2007-06-25 17:59 178,688 --a------ C:\DOCUME~1\Steph\gold.exe
2007-06-25 17:09 178,688 --a------ C:\WINDOWS\system32\gold.exe
2007-06-25 15:56 <DIR> d-------- C:\Program Files\SpeedFan
2007-06-25 15:41 <DIR> d--h----- C:\WINDOWS\system32\GroupPolicy
2007-06-25 11:36 1,448,219 ---hs---- C:\WINDOWS\system32\ghkmp.bak2
2007-06-24 23:35 6,409 ---hs---- C:\WINDOWS\system32\ghkmp.bak1
2007-06-24 14:08 3,968 --a------ C:\WINDOWS\system32\drivers\AvgArCln.sys
2007-06-24 13:23 <DIR> d-------- C:\Program Files\RogueRemover
2007-06-24 10:34 <DIR> d-------- C:\WINDOWS\system32\appmgmt
2007-06-24 10:27 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\MySpace
2007-06-24 10:26 786,432 --ah----- C:\DOCUME~1\ADMINI~1\NTUSER.DAT
2007-06-23 10:31 4,672 --a------ C:\WINDOWS\system32\petaccnj.exe
2007-06-23 09:22 30,220 --a------ C:\DOCUME~1\Steph\iop.exe
2007-06-22 19:54 4,672 --a------ C:\WINDOWS\system32\fpkjbpgm.exe
2007-06-22 19:53 1,242,081 --ahs---- C:\WINDOWS\system32\rtstv.bak2
2007-06-22 19:50 4,672 --a------ C:\WINDOWS\system32\exujklqs.exe
2007-06-21 20:07 7,386 --ahs---- C:\WINDOWS\system32\rtstv.ini2
2007-06-21 18:01 6,570 --ahs---- C:\WINDOWS\system32\rtstv.bak1
2007-06-19 17:58 <DIR> d-------- C:\!KillBox
2007-06-16 22:55 49,152 --a------ C:\WINDOWS\nircmd.exe
2007-06-15 20:49 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com
2007-06-15 20:48 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2007-06-15 20:48 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-06-15 20:48 <DIR> d-------- C:\DOCUME~1\Chris\APPLIC~1\SUPERAntiSpyware.com
2007-06-15 20:23 <DIR> d-------- C:\VundoFix Backups
2007-06-15 19:02 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-06-15 19:02 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab
2007-06-13 17:57 <DIR> d-------- C:\Program Files\NoAdware5.0
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-07-09 01:32:47 -------- d-----w C:\Program Files\MSN Messenger
2007-06-03 15:36:39 -------- d-----w C:\DOCUME~1\Chris\APPLIC~1\LimeWire
2007-06-01 04:06:55 -------- d-----w C:\Program Files\Audacity
2007-06-01 03:12:49 -------- d-----w C:\DOCUME~1\Chris\APPLIC~1\SonyEricsson
2007-06-01 03:12:41 -------- d-----w C:\Program Files\Sony Ericsson
2007-05-30 23:26:45 -------- d-----w C:\Program Files\MySpace
2007-05-26 20:33:28 -------- d-----w C:\Program Files\QuickTime
2007-05-20 01:56:28 -------- d-----w C:\DOCUME~1\Chris\APPLIC~1\uTorrent
2007-05-19 19:56:50 -------- d-----w C:\Program Files\TGTSoft
2007-05-16 15:12:02 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-05-15 23:38:28 -------- d-----w C:\Program Files\Google
2007-04-30 15:46:10 745,600 ----a-w C:\WINDOWS\system32\aswBoot.exe
2007-04-30 15:35:28 95,872 ----a-w C:\WINDOWS\system32\AVASTSS.scr
2007-04-25 14:21:15 144,896 ----a-w C:\WINDOWS\system32\schannel.dll
2007-04-18 16:12:23 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll
2007-04-17 02:47:36 33,624 ----a-w C:\WINDOWS\system32\wups.dll
2007-04-17 02:45:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-17 02:45:48 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-04-17 02:45:42 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-04-17 02:45:36 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-04-17 02:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-04-17 02:45:20 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-17 02:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
2007-04-17 02:44:20 271,224 ----a-w C:\WINDOWS\system32\mucltui.dll
2007-04-17 02:44:18 208,248 ----a-w C:\WINDOWS\system32\muweb.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}=C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-23 00:08]
{72853161-30C5-4D22-B7F9-0BBC1D38A37E}=C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 00:48]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll [2007-03-14 03:43]
{9030D464-4C02-4ABF-8ECC-5164760863C6}=C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2006-08-31 21:33]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-04-30 11:42]
"@"="" []
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]
"AudioDeck"="C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe" [2006-11-02 16:57]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 05:25]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 08:00]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"="C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL" [2006-10-27 00:48]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"="C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2006-12-20 13:55]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2007-05-30 08:29]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Driver]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Guard]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!AVG Anti-Spyware]
"C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
"C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
"C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
Contents of the 'Scheduled Tasks' folder
2007-06-30 20:16:03 C:\WINDOWS\tasks\AppleSoftwareUpdate.job
**************************************************************************
catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer,
http://www.gmer.netRootkit scan 2007-07-11 22:36:05
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-07-11 22:37:32
C:\ComboFix-quarantined-files.txt ... 2007-07-11 22:37
C:\ComboFix2.txt ... 2007-06-24 23:34
--- E O F ---