End of file - 8953 bytes
-- Files created between 2007-11-17 and 2007-12-17 -----------------------------
2007-12-17 15:23:35 60416 --a------ C:\WINDOWS\system32\drivers\ComboFix.sys
2007-12-17 14:46:52 0 d-------- C:\Program Files\Trend Micro
2007-12-14 10:44:46 0 d-------- C:\Program Files\iWin
2007-12-13 20:04:41 0 d------c- C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com
2007-12-13 20:04:06 0 d--h---c- C:\Documents and Settings\Administrator\NetHood
2007-12-13 20:04:06 0 dr-----c- C:\Documents and Settings\Administrator\My Documents
2007-12-13 20:04:06 0 d--h---c- C:\Documents and Settings\Administrator\Local Settings
2007-12-13 20:04:06 0 dr-----c- C:\Documents and Settings\Administrator\Favorites
2007-12-13 20:04:06 0 d------c- C:\Documents and Settings\Administrator\Desktop
2007-12-13 20:04:06 0 d--hs--c- C:\Documents and Settings\Administrator\Cookies
2007-12-13 20:04:06 0 dr-h---c- C:\Documents and Settings\Administrator\Application Data
2007-12-13 20:04:06 0 d------c- C:\Documents and Settings\Administrator\Application Data\You've Got Pictures Screensaver
2007-12-13 20:04:06 0 d------c- C:\Documents and Settings\Administrator\Application Data\Symantec
2007-12-13 20:04:06 0 d------c- C:\Documents and Settings\Administrator\Application Data\Sun
2007-12-13 20:04:06 0 d---s--c- C:\Documents and Settings\Administrator\Application Data\Microsoft
2007-12-13 20:04:06 0 d------c- C:\Documents and Settings\Administrator\Application Data\Identities
2007-12-13 20:04:06 0 d------c- C:\Documents and Settings\Administrator\Application Data\CyberLink
2007-12-13 20:04:06 0 d------c- C:\Documents and Settings\Administrator\Application Data\AOL
2007-12-13 20:04:05 0 d--h---c- C:\Documents and Settings\Administrator\Templates
2007-12-13 20:04:05 0 dr-----c- C:\Documents and Settings\Administrator\Start Menu
2007-12-13 20:04:05 0 dr-h---c- C:\Documents and Settings\Administrator\SendTo
2007-12-13 20:04:05 0 dr-h---c- C:\Documents and Settings\Administrator\Recent
2007-12-13 20:04:05 0 d--h---c- C:\Documents and Settings\Administrator\PrintHood
2007-12-13 20:04:05 1048576 --ah----- C:\Documents and Settings\Administrator\NTUSER.DAT
2007-12-13 16:20:59 0 d------c- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-12-13 16:19:45 0 d-------- C:\Program Files\SUPERAntiSpyware
2007-12-13 16:19:45 0 d-------- C:\Documents and Settings\Owner\Application Data\SUPERAntiSpyware.com
2007-12-13 16:18:57 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-12-12 20:13:58 0 d-------- C:\Program Files\Common Files\xing shared
2007-12-12 20:10:27 0 d-------- C:\Documents and Settings\Owner\Application Data\Real
2007-12-10 20:28:02 0 d-------- C:\WINDOWS\pss
2007-12-10 19:58:09 0 d-------- C:\Program Files\RogueRemover FREE
2007-12-10 19:34:52 0 d-------- C:\Documents and Settings\Owner\Application Data\Uniblue
2007-12-10 13:52:26 0 d-------- C:\Program Files\Windows Defender
2007-12-10 13:42:34 0 d-------- C:\Program Files\Microsoft Silverlight
2007-12-10 09:30:12 0 d-------- C:\Program Files\Alwil Software
2007-12-09 23:33:04 291328 --a------ C:\WINDOWS\system32\libcurl.dll <Not Verified; The cURL library,
http://curl.haxx.se/; The cURL library>
2007-12-08 18:36:29 237568 --a------ C:\Documents and Settings\LocalService\ntuser.dat
2007-12-06 17:57:41 0 d-------- C:\Program Files\Common Files\SupportSoft
2007-12-06 17:57:16 0 d-------- C:\Program Files\CHARTER
-- Find3M Report ---------------------------------------------------------------
2007-12-17 10:26:45 0 d-------- C:\Program Files\Common Files\Symantec Shared
2007-12-15 22:21:46 0 d-------- C:\Program Files\BigFix
2007-12-15 18:24:30 0 d-------- C:\Program Files\Common Files
2007-12-13 15:47:47 0 d-------- C:\Documents and Settings\Owner\Application Data\Identities
2007-12-12 20:13:38 0 d-------- C:\Program Files\Common Files\Real
2007-12-10 13:52:06 0 d-------- C:\Program Files\Microsoft AntiSpyware
2007-12-06 17:50:09 0 d--h----- C:\Program Files\InstallShield Installation Information
2007-11-13 09:57:06 0 d-------- C:\Program Files\Apple Software Update
2007-11-13 01:28:47 0 d-------- C:\Program Files\iTunes
2007-11-13 01:28:17 0 d-------- C:\Program Files\iPod
2007-11-13 01:25:30 0 d-------- C:\Program Files\QuickTime
2007-11-06 10:40:20 0 d-------- C:\Program Files\MMKids
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 20:42]
"SunKistEM"="C:\Program Files\Digital Media Reader\shwiconem.exe" [2004-03-11 16:18]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2004-01-29 20:13]
"msnappau"="C:\Program Files\MSN Apps\Updater\01.05.0000.1009\en-us\msnappau.exe" [2005-06-09 13:56]
"UserFaultCheck"="C:\WINDOWS\system32\dumprep 0 -u" []
"SoundMan"="SOUNDMAN.EXE" [2005-04-15 10:01 C:\WINDOWS\SOUNDMAN.EXE]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-02-16 22:11]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-10-19 20:16]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-11-02 18:36]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 07:00]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-12-12 20:12]
"combofix"="C:\WINDOWS\system32\cmd.exe" [2004-08-04 00:56]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE" [2005-01-04 11:50]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56]
"Uniblue RegistryBooster 2"="C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe" []
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2004-11-04 19:28:24]
HP Image Zone Fast Start.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2004-11-04 19:50:52]
Launchpad.lnk - C:\Program Files\IC Media Corp.\ICM532\Launchpad.exe [2004-12-26 12:12:08]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [2000-01-21 03:15:54]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
-- End of Deckard's System Scanner: finished at 2007-12-17 20:43:03 ------------