Here's the ComboFix log, but the online scan still wouldn't work.
The popups have stopped, but the notification of counterfeited software is still there.
ComboFix 07-12-09.1 - Windswept 2007-12-14 15:38:06.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.162 [GMT -8:00]
Running from: C:\Documents and Settings\Windswept\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Windswept\Desktop\CFscript.txt
* Created a new restore point
FILE
C:\WINDOWS\hg173.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\hg173.exe
.
((((((((((((((((((((((((( Files Created from 2007-11-14 to 2007-12-14 )))))))))))))))))))))))))))))))
.
2007-12-12 19:04 . 2007-12-12 19:04 <DIR> d-------- C:\Documents and Settings\Windswept\DoctorWeb
2007-12-10 14:59 . 2007-12-10 14:59 <DIR> d-------- C:\Deckard
2007-12-10 14:57 . 2007-12-10 14:57 <DIR> d-------- C:\Program Files\Trend Micro
2007-11-28 15:57 . 2007-11-28 15:57 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Rabio
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-14 23:14 --------- d-----w C:\Program Files\Java
2007-12-14 06:22 --------- d-----w C:\Program Files\Trillian
2007-12-08 05:36 --------- d-----w C:\Program Files\SUPERAntiSpyware
2007-12-04 14:56 93,264 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
2007-12-04 14:55 94,544 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
2007-12-04 14:53 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
2007-12-04 14:51 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
2007-12-04 14:49 26,624 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2006-04-01 19:05 905 -c--a-w C:\Program Files\layout.bin
2006-04-01 19:05 512 -c--a-w C:\Program Files\data2.cab
2006-04-01 19:05 22,633 -c--a-w C:\Program Files\data1.hdr
2006-04-01 19:04 956,377 -c--a-w C:\Program Files\data1.cab
2006-04-01 19:04 500 -c--a-w C:\Program Files\setup.ini
2006-04-01 19:04 392,330 -c--a-w C:\Program Files\setup.boot
2006-04-01 19:04 186,838 -c--a-w C:\Program Files\setup.inx
2006-02-07 20:57 1,864 -c--a-w C:\Program Files\readme.txt
2004-01-22 01:39 292,711 -c--a-w C:\Program Files\setup.skin
2002-12-05 21:16 418,296 -c--a-w C:\Program Files\engine32.cab
2002-12-02 22:33 107,512 -c--a-w C:\Program Files\setup.exe
1999-07-07 00:00 6 -csh--r C:\WINDOWS\@
[email protected]
2004-06-20 00:50 56 --sh--r C:\WINDOWS\SYSTEM32\3030672BD7.sys
2004-06-29 04:50 2,516 -csha-w C:\WINDOWS\SYSTEM32\KGyGaAvL.sys
.
(((((((((((((((((((((((((((((
[email protected]_19.15.28.71 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-10-29 22:35:13 1,287,680 ----a-w C:\WINDOWS\$hf_mig$\KB941568\SP2QFE\quartz.dll
+ 2007-03-06 01:22:36 14,048 ----a-w C:\WINDOWS\$hf_mig$\KB941568\spmsg.dll
+ 2007-03-06 01:22:41 213,216 ----a-w C:\WINDOWS\$hf_mig$\KB941568\spuninst.exe
+ 2007-03-06 01:22:34 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB941568\update\spcustom.dll
+ 2007-03-06 01:22:59 716,000 ----a-w C:\WINDOWS\$hf_mig$\KB941568\update\update.exe
+ 2007-03-06 01:23:51 371,424 ----a-w C:\WINDOWS\$hf_mig$\KB941568\update\updspapi.dll
+ 2007-11-13 11:02:46 60,416 ----a-w C:\WINDOWS\$hf_mig$\KB942763\SP2QFE\tzchange.exe
+ 2007-03-06 01:22:36 14,048 ----a-w C:\WINDOWS\$hf_mig$\KB942763\spmsg.dll
+ 2007-03-06 01:22:41 213,216 ----a-w C:\WINDOWS\$hf_mig$\KB942763\spuninst.exe
+ 2007-03-06 01:22:34 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB942763\update\spcustom.dll
+ 2007-03-06 01:22:59 716,000 ----a-w C:\WINDOWS\$hf_mig$\KB942763\update\update.exe
+ 2007-03-06 01:23:51 371,424 ----a-w C:\WINDOWS\$hf_mig$\KB942763\update\updspapi.dll
+ 2007-11-14 07:18:03 450,560 ----a-w C:\WINDOWS\$hf_mig$\KB942840\SP2QFE\jscript.dll
+ 2007-03-06 01:22:36 14,048 ----a-w C:\WINDOWS\$hf_mig$\KB942840\spmsg.dll
+ 2007-03-06 01:22:41 213,216 ----a-w C:\WINDOWS\$hf_mig$\KB942840\spuninst.exe
+ 2007-03-06 01:22:34 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB942840\update\spcustom.dll
+ 2007-03-06 01:22:59 716,000 ----a-w C:\WINDOWS\$hf_mig$\KB942840\update\update.exe
+ 2007-03-06 01:23:51 371,424 ----a-w C:\WINDOWS\$hf_mig$\KB942840\update\updspapi.dll
+ 2007-11-13 08:47:45 20,480 ----a-w C:\WINDOWS\$hf_mig$\KB944653\SP2QFE\secdrv.sys
+ 2007-03-06 01:22:36 14,048 ----a-w C:\WINDOWS\$hf_mig$\KB944653\spmsg.dll
+ 2007-03-06 01:22:41 213,216 ----a-w C:\WINDOWS\$hf_mig$\KB944653\spuninst.exe
+ 2007-03-06 01:22:34 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB944653\update\spcustom.dll
+ 2007-03-06 01:22:59 716,000 ----a-w C:\WINDOWS\$hf_mig$\KB944653\update\update.exe
+ 2007-03-06 01:23:51 371,424 ----a-w C:\WINDOWS\$hf_mig$\KB944653\update\updspapi.dll
- 2007-08-22 12:55:28 1,022,976 ----a-w C:\WINDOWS\SYSTEM32\browseui.dll
+ 2007-10-11 05:57:29 1,024,000 ----a-w C:\WINDOWS\SYSTEM32\browseui.dll
- 2007-08-22 12:55:29 151,040 ----a-w C:\WINDOWS\SYSTEM32\cdfview.dll
+ 2007-10-11 05:57:29 151,040 ----a-w C:\WINDOWS\SYSTEM32\cdfview.dll
- 2007-08-22 12:55:30 1,054,208 ----a-w C:\WINDOWS\SYSTEM32\danim.dll
+ 2007-10-11 05:57:30 1,054,208 ----a-w C:\WINDOWS\SYSTEM32\danim.dll
- 2007-08-22 12:55:28 1,022,976 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\browseui.dll
+ 2007-10-11 05:57:29 1,024,000 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\browseui.dll
- 2007-08-22 12:55:29 151,040 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\cdfview.dll
+ 2007-10-11 05:57:29 151,040 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\cdfview.dll
- 2007-08-22 12:55:30 1,054,208 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\danim.dll
+ 2007-10-11 05:57:30 1,054,208 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\danim.dll
- 2007-08-22 12:55:30 357,888 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\dxtmsft.dll
+ 2007-10-11 05:57:30 357,888 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\dxtmsft.dll
- 2007-08-22 12:55:31 205,824 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\dxtrans.dll
+ 2007-10-11 05:57:30 205,824 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\dxtrans.dll
- 2007-08-22 12:55:31 55,808 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\extmgr.dll
+ 2007-10-11 05:57:30 55,808 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\extmgr.dll
- 2007-08-21 10:19:39 18,432 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\iedw.exe
+ 2007-10-10 10:48:23 18,432 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\iedw.exe
- 2007-08-22 12:55:32 251,904 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\iepeers.dll
+ 2007-10-11 05:57:31 251,904 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\iepeers.dll
- 2007-08-22 12:55:32 96,256 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\inseng.dll
+ 2007-10-11 05:57:31 96,256 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\inseng.dll
- 2006-05-18 05:24:25 450,560 -c----w C:\WINDOWS\SYSTEM32\DLLCACHE\jscript.dll
+ 2007-11-14 07:26:56 450,560 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\jscript.dll
- 2007-08-22 12:55:32 16,384 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\jsproxy.dll
+ 2007-10-11 05:57:31 16,384 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\jsproxy.dll
- 2007-08-22 12:55:36 3,064,832 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\mshtml.dll
+ 2007-10-30 09:55:21 3,065,856 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\mshtml.dll
- 2007-08-22 12:55:37 449,024 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\mshtmled.dll
+ 2007-10-11 05:57:36 449,024 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\mshtmled.dll
- 2007-08-22 12:55:37 146,432 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\msrating.dll
+ 2007-10-11 05:57:36 146,432 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\msrating.dll
- 2007-08-22 12:55:38 532,480 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\mstime.dll
+ 2007-10-11 05:57:37 532,480 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\mstime.dll
- 2007-08-22 12:55:38 39,424 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\pngfilt.dll
+ 2007-10-11 05:57:37 39,424 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\pngfilt.dll
+ 2007-10-29 22:43:03 1,287,680 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\quartz.dll
- 2007-08-22 12:55:40 1,498,112 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\shdocvw.dll
+ 2007-10-11 05:57:39 1,498,112 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\shdocvw.dll
- 2007-08-22 12:55:41 474,112 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\shlwapi.dll
+ 2007-10-11 05:57:40 474,112 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\shlwapi.dll
- 2007-08-22 12:55:43 617,984 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\urlmon.dll
+ 2007-10-11 05:57:40 617,984 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\urlmon.dll
- 2007-08-22 12:55:44 665,600 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\wininet.dll
+ 2007-10-11 05:57:41 666,112 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\wininet.dll
- 2006-10-19 05:47:18 222,208 -c--a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wmasf.dll
+ 2007-10-28 01:40:30 222,720 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wmasf.dll
- 2007-08-22 12:55:30 357,888 ----a-w C:\WINDOWS\SYSTEM32\dxtmsft.dll
+ 2007-10-11 05:57:30 357,888 ----a-w C:\WINDOWS\SYSTEM32\dxtmsft.dll
- 2007-08-22 12:55:31 205,824 ----a-w C:\WINDOWS\SYSTEM32\dxtrans.dll
+ 2007-10-11 05:57:30 205,824 ----a-w C:\WINDOWS\SYSTEM32\dxtrans.dll
- 2007-08-22 12:55:31 55,808 ----a-w C:\WINDOWS\SYSTEM32\extmgr.dll
+ 2007-10-11 05:57:30 55,808 ----a-w C:\WINDOWS\SYSTEM32\extmgr.dll
- 2007-08-22 12:55:32 251,904 ----a-w C:\WINDOWS\SYSTEM32\iepeers.dll
+ 2007-10-11 05:57:31 251,904 ----a-w C:\WINDOWS\SYSTEM32\iepeers.dll
- 2007-08-22 12:55:32 96,256 ----a-w C:\WINDOWS\SYSTEM32\inseng.dll
+ 2007-10-11 05:57:31 96,256 ----a-w C:\WINDOWS\SYSTEM32\inseng.dll
- 2006-05-18 05:24:25 450,560 ----a-w C:\WINDOWS\SYSTEM32\jscript.dll
+ 2007-11-14 07:26:56 450,560 ----a-w C:\WINDOWS\SYSTEM32\jscript.dll
- 2007-08-22 12:55:32 16,384 ----a-w C:\WINDOWS\SYSTEM32\jsproxy.dll
+ 2007-10-11 05:57:31 16,384 ----a-w C:\WINDOWS\SYSTEM32\jsproxy.dll
- 2007-11-02 07:12:57 18,238,072 ----a-w C:\WINDOWS\SYSTEM32\MRT.exe
+ 2007-12-02 23:00:05 18,684,536 ----a-w C:\WINDOWS\SYSTEM32\MRT.exe
- 2007-08-22 12:55:36 3,064,832 ----a-w C:\WINDOWS\SYSTEM32\mshtml.dll
+ 2007-10-30 09:55:21 3,065,856 ----a-w C:\WINDOWS\SYSTEM32\mshtml.dll
- 2007-08-22 12:55:37 449,024 ----a-w C:\WINDOWS\SYSTEM32\mshtmled.dll
+ 2007-10-11 05:57:36 449,024 ----a-w C:\WINDOWS\SYSTEM32\mshtmled.dll
- 2007-08-22 12:55:37 146,432 ----a-w C:\WINDOWS\SYSTEM32\msrating.dll
+ 2007-10-11 05:57:36 146,432 ----a-w C:\WINDOWS\SYSTEM32\msrating.dll
- 2007-08-22 12:55:38 532,480 ----a-w C:\WINDOWS\SYSTEM32\mstime.dll
+ 2007-10-11 05:57:37 532,480 ----a-w C:\WINDOWS\SYSTEM32\mstime.dll
- 2007-12-06 02:39:59 68,924 ----a-w C:\WINDOWS\SYSTEM32\PERFC009.DAT
+ 2007-12-11 16:01:20 68,924 ----a-w C:\WINDOWS\SYSTEM32\PERFC009.DAT
- 2007-12-06 02:39:59 418,062 ----a-w C:\WINDOWS\SYSTEM32\PERFH009.DAT
+ 2007-12-11 16:01:21 418,062 ----a-w C:\WINDOWS\SYSTEM32\PERFH009.DAT
- 2007-08-22 12:55:38 39,424 ----a-w C:\WINDOWS\SYSTEM32\pngfilt.dll
+ 2007-10-11 05:57:37 39,424 ----a-w C:\WINDOWS\SYSTEM32\pngfilt.dll
- 2005-08-30 03:54:26 1,287,168 ----a-w C:\WINDOWS\SYSTEM32\quartz.dll
+ 2007-10-29 22:43:03 1,287,680 ----a-w C:\WINDOWS\SYSTEM32\quartz.dll
- 2007-08-22 12:55:40 1,498,112 ----a-w C:\WINDOWS\SYSTEM32\shdocvw.dll
+ 2007-10-11 05:57:39 1,498,112 ----a-w C:\WINDOWS\SYSTEM32\shdocvw.dll
- 2007-08-22 12:55:41 474,112 ----a-w C:\WINDOWS\SYSTEM32\shlwapi.dll
+ 2007-10-11 05:57:40 474,112 ----a-w C:\WINDOWS\SYSTEM32\shlwapi.dll
- 2007-12-11 03:11:57 13,721 ----a-w C:\WINDOWS\SYSTEM32\tablet.dat
+ 2007-12-14 23:44:32 13,721 ----a-w C:\WINDOWS\SYSTEM32\tablet.dat
- 2007-07-18 12:42:22 60,416 ------w C:\WINDOWS\SYSTEM32\tzchange.exe
+ 2007-11-13 11:31:11 60,416 ------w C:\WINDOWS\SYSTEM32\tzchange.exe
- 2007-08-22 12:55:43 617,984 ----a-w C:\WINDOWS\SYSTEM32\urlmon.dll
+ 2007-10-11 05:57:40 617,984 ----a-w C:\WINDOWS\SYSTEM32\urlmon.dll
- 2007-08-22 12:55:44 665,600 ----a-w C:\WINDOWS\SYSTEM32\wininet.dll
+ 2007-10-11 05:57:41 666,112 ----a-w C:\WINDOWS\SYSTEM32\wininet.dll
- 2006-10-19 05:47:18 222,208 ----a-w C:\WINDOWS\SYSTEM32\wmasf.dll
+ 2007-10-28 01:40:30 222,720 ----a-w C:\WINDOWS\SYSTEM32\wmasf.dll
- 2007-12-11 03:11:46 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_544.dat
+ 2007-12-14 23:44:21 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_544.dat
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-05-23 09:12]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2003-08-15 09:38]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2003-08-15 09:37]
"DwlClient"="C:\Program Files\Common Files\Dell\EUSW\Support.exe" [2004-05-27 20:05]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 05:00]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 02:59 C:\WINDOWS\BCMSMMSG.exe]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
backup=C:\WINDOWS\pss\America Online 9.0 Tray Icon.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^LVF.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\LVF.lnk
backup=C:\WINDOWS\pss\LVF.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Works Calendar Reminders.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Works Calendar Reminders.lnk
backup=C:\WINDOWS\pss\Microsoft Works Calendar Reminders.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^TabUserW.exe.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\TabUserW.exe.lnk
backup=C:\WINDOWS\pss\TabUserW.exe.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Windswept^Start Menu^Programs^Startup^TA_Start.lnk]
path=C:\Documents and Settings\Windswept\Start Menu\Programs\Startup\TA_Start.lnk
backup=C:\WINDOWS\pss\TA_Start.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCMSMMSG]
BCMSMMSG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DadApp]
2003-03-07 09:36 209800 --a--c--- C:\Program Files\Dell\AccessDirect\dadapp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDSentry]
2003-08-13 07:27 28672 --a------ C:\WINDOWS\System32\DSentry.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Genuine]
rundll32.exe C:\WINDOWS\system32\xlgsbtml.dll,realset
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LWBMOUSE]
2002-05-24 04:54 357376 --a--c--- C:\Program Files\Tech\Wheel Mouse\5.0\MOUSE32A.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealPlayer]
C:\Program Files\Real\RealPlayer\realplay.exe /RunUPGToolCommandReBoot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
2003-10-31 18:42 32768 --a--c--- C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
C:\Program Files\Windows Media Player\WMPNSCFG.exe
R0 PenClass;Pen Class;C:\WINDOWS\system32\Drivers\PenClass.sys
S3 IR500;IR500;C:\WINDOWS\system32\DRIVERS\IR500.sys
S3 PortRst;PortRst;C:\WINDOWS\system32\DRIVERS\PortRst.sys
S3 StMp3Rec;Player Recovery Device Control Driver;C:\WINDOWS\system32\Drivers\StMp3Rec.sys
S3 usbprint;Microsoft USB PRINTER Class;C:\WINDOWS\system32\DRIVERS\usbprint.sys
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{969B3B70-8765-11D5-9809-0050BACBF861}]
rundll32.exe advpack.dll,LaunchINFSection C:\Program Files\CyberLink\MP3PowerEncoder\Cyber.inf,PerUserStub
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.3156]
-> C:\DOCUME~1\WINDSW~1\LOCALS~1\Temp\igbsvlec.dll
.
**************************************************************************
catchme 0.3.1331 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-12-14 15:45:25
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-14 15:49:13 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-12-04 21:20
C:\ComboFix2.txt ... 2007-12-11 15:18
C:\ComboFix3.txt ... 2007-12-10 19:16
.
--- E O F ---