ATF cleaner found nothing
nolop log:
NoLop! Log by Skate_Punk_21
Fix running from: C:\Documents and Settings\Administrator\Desktop
[12/7/2007]
[10:36:48 PM]
---Infection Files Found/Removed---
NO INFECTION FILES FOUND - Cleaning Aborted.
---Listing AppData sub directories---
C:\Documents and Settings\Administrator\Application Data\Adobe
C:\Documents and Settings\Administrator\Application Data\Adobeum
C:\Documents and Settings\Administrator\Application Data\Arcsoft
C:\Documents and Settings\Administrator\Application Data\Avg7
C:\Documents and Settings\Administrator\Application Data\Google
C:\Documents and Settings\Administrator\Application Data\Help -- EMPTY Directory
C:\Documents and Settings\Administrator\Application Data\Hotsync
C:\Documents and Settings\Administrator\Application Data\Icaclient
C:\Documents and Settings\Administrator\Application Data\Identities
C:\Documents and Settings\Administrator\Application Data\Jasc Software Inc
C:\Documents and Settings\Administrator\Application Data\Leadertech
C:\Documents and Settings\Administrator\Application Data\Macromedia
C:\Documents and Settings\Administrator\Application Data\Microsoft
C:\Documents and Settings\Administrator\Application Data\Move Networks
C:\Documents and Settings\Administrator\Application Data\Mozilla
C:\Documents and Settings\Administrator\Application Data\Nero
C:\Documents and Settings\Administrator\Application Data\Smartftp
C:\Documents and Settings\Administrator\Application Data\Superantispyware.com
C:\Documents and Settings\Administrator\Application Data\Virtual Mechanics
C:\Documents and Settings\Administrator\Application Data\Windows Desktop Search
C:\Documents and Settings\All Users\Application Data\Adobe
C:\Documents and Settings\All Users\Application Data\Adobe Systems
C:\Documents and Settings\All Users\Application Data\Avg7
C:\Documents and Settings\All Users\Application Data\Grisoft
C:\Documents and Settings\All Users\Application Data\Hewlett-packard
C:\Documents and Settings\All Users\Application Data\Hotsync
C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
C:\Documents and Settings\All Users\Application Data\Lavasoft
C:\Documents and Settings\All Users\Application Data\Microsoft
C:\Documents and Settings\All Users\Application Data\Microsoft Help
C:\Documents and Settings\All Users\Application Data\Nero
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
C:\Documents and Settings\All Users\Application Data\Superantispyware.com
C:\Documents and Settings\All Users\Application Data\Symantec
C:\Documents and Settings\All Users\Application Data\Virtual Mechanics -- EMPTY Directory
C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
C:\Documents and Settings\Default User\Application Data\Microsoft
C:\Documents and Settings\Localservice\Application Data\Avg7 -- EMPTY Directory
C:\Documents and Settings\Localservice\Application Data\Microsoft
C:\Documents and Settings\Networkservice\Application Data\Microsoft
Combofix report is...
ComboFix 07-12-07.3 - Administrator 2007-12-07 22:46:40.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.491 [GMT -6:00]
Running from: C:\Documents and Settings\Administrator\Desktop\Dnloads\ComboFix.exe
Command switches used :: C:\Documents and Settings\Administrator\Desktop\Dnloads\CFScript.txt
* Created a new restore point
FILE
C:\WINDOWS\system32\ccfii.ini
C:\WINDOWS\system32\ccfii.ini2
C:\WINDOWS\system32\iifcc.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\ccfii.ini
C:\WINDOWS\system32\ccfii.ini2
C:\WINDOWS\system32\iifcc.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_DOMAINSERVICE
-------\DomainService
((((((((((((((((((((((((( Files Created from 2007-11-08 to 2007-12-08 )))))))))))))))))))))))))))))))
.
2007-12-07 22:36 . 2007-12-07 22:36 106 --a------ C:\delete.bat
2007-12-07 22:28 . 2007-12-07 22:28 2,508 --a------ C:\WINDOWS\system32\tmp.reg
2007-12-07 21:49 . 2007-12-07 21:49 74,304 --a------ C:\WINDOWS\system32\mfdivsva.exe
2007-12-07 13:33 . 2007-12-07 13:33 <DIR> d-------- C:\Deckard
2007-12-07 10:02 . 2007-12-07 10:02 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-12-07 07:16 . 2007-12-07 07:16 0 --a------ C:\WINDOWS\system32\CMMGR32.EXE
2007-12-07 07:04 . 2007-12-07 07:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-12-07 07:03 . 2007-12-07 15:22 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2007-12-07 07:03 . 2007-12-07 07:03 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com
2007-12-07 06:51 . 2007-12-07 06:51 <DIR> d-------- C:\Program Files\Trend Micro
2007-12-06 22:03 . 2007-12-06 22:03 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2007-12-06 22:03 . 2007-12-07 22:09 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\AVG7
2007-12-06 20:45 . 2007-12-06 21:14 <DIR> d-------- C:\Program Files\Mozilla Firefox(2)
2007-12-06 20:45 . 2007-12-06 20:45 0 --a------ C:\WINDOWS\nsreg.dat
2007-12-04 16:08 . 2007-12-04 18:41 310 --a------ C:\WINDOWS\wininit.ini
2007-12-04 13:42 . 2007-12-04 13:42 <DIR> d-------- C:\Program Files\Lavasoft
2007-12-04 13:42 . 2007-12-07 07:03 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-12-04 13:42 . 2007-12-04 13:42 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-12-04 13:33 . 2007-12-04 13:43 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-03 18:19 . 2007-12-03 18:19 <DIR> d-------- C:\Program Files\Kaspersky Lab
2007-12-03 18:19 . 2007-12-07 21:03 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-12-03 18:10 . 2007-12-03 18:10 <DIR> d-------- C:\KAV
2007-12-01 10:20 . 2007-12-06 22:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avg7
2007-12-01 03:00 . 2007-12-01 03:00 <DIR> d-------- C:\Program Files\MSXML 4.0
2007-11-30 21:18 . 2007-11-30 21:18 748 --a------ C:\WINDOWS\ST4UNST.000
2007-11-30 21:13 . 2007-11-30 21:20 55 --a------ C:\WINDOWS\xm.url
2007-11-30 11:02 . 2007-11-30 16:22 69 --a------ C:\WINDOWS\NeroDigital.ini
2007-11-30 10:09 . 2007-11-30 10:09 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Nero
2007-11-30 10:03 . 2007-11-30 10:03 <DIR> d-------- C:\Program Files\Nero
2007-11-30 10:02 . 2007-11-30 10:06 <DIR> d-------- C:\Program Files\Common Files\Nero
2007-11-30 10:02 . 2007-11-30 10:03 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Nero
2007-11-29 14:33 . 2006-10-04 08:06 1,197,294 -----c--- C:\WINDOWS\system32\dllcache\sysmain.sdb
2007-11-29 14:33 . 2006-10-04 08:06 764,868 -----c--- C:\WINDOWS\system32\dllcache\apph_sp.sdb
2007-11-29 14:33 . 2006-10-04 08:06 217,118 -----c--- C:\WINDOWS\system32\dllcache\apphelp.sdb
2007-11-29 14:32 . 2007-11-29 14:32 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2007-11-29 14:30 . 2007-11-29 14:30 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2007-11-29 14:30 . 2007-11-29 14:31 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2007-11-28 17:47 . 2007-11-28 17:47 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Move Networks
2007-11-28 12:34 . 2007-11-28 12:35 <DIR> d-------- C:\Program Files\TVAnts
2007-11-28 12:33 . 2007-11-28 12:33 <DIR> d-------- C:\WINDOWS\uninstall\Satellite TV for PC Elite
2007-11-28 12:33 . 2007-11-28 12:33 <DIR> d-------- C:\WINDOWS\uninstall
2007-11-28 12:33 . 2006-04-29 04:07 5,533,696 --a------ C:\WINDOWS\system32\OLD8A.tmp
2007-11-28 12:25 . 2007-11-28 12:25 <DIR> d-------- C:\Program Files\Google
2007-11-25 22:46 . 2007-11-15 18:46 83,288 --a------ C:\WINDOWS\system32\LMIRfsClientNP.dll
2007-11-25 22:46 . 2007-08-03 15:09 46,112 --a------ C:\WINDOWS\system32\drivers\LMIRfsDriver.sys
2007-11-25 22:46 . 2007-11-15 18:46 21,496 --a------ C:\WINDOWS\system32\LMIport.dll
2007-11-25 22:45 . 2007-12-07 06:40 <DIR> d-------- C:\Program Files\LogMeIn
2007-11-25 22:45 . 2007-11-15 18:46 87,352 --a------ C:\WINDOWS\system32\LMIinit.dll
2007-11-25 22:45 . 2007-11-25 22:45 1,024 --a------ C:\.rnd
2007-11-22 10:52 . 2007-11-22 10:52 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Jasc Software Inc
2007-11-22 10:51 . 2007-11-22 10:52 <DIR> d-------- C:\Program Files\Jasc Software Inc
2007-11-22 10:44 . 2003-08-11 10:13 344,064 -ra------ C:\WINDOWS\system32\msvcr70.dll
2007-11-22 10:44 . 2003-08-11 10:07 14,604 --a------ C:\WINDOWS\system32\drivers\pfc.sys
2007-11-19 17:20 . 2007-11-19 17:20 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
2007-11-19 17:17 . 2007-02-13 20:23 103,424 --a------ C:\WINDOWS\system32\hpzpnp.dll
2007-11-19 17:17 . 2006-09-01 14:29 30,208 --a------ C:\WINDOWS\system32\HPZIPT12.DLL
2007-11-19 17:17 . 2006-09-01 15:18 20,480 --a------ C:\WINDOWS\system32\HPZISN12.DLL
2007-11-19 16:58 . 2007-11-19 16:58 <DIR> d-------- C:\HP LJ 4x50 Series
2007-11-15 18:46 . 2007-11-15 18:46 23,736 --a------ C:\WINDOWS\system32\lmimirr.dll
2007-11-15 18:46 . 2007-11-15 18:46 10,040 --a------ C:\WINDOWS\system32\lmimirr2.dll
2007-11-15 15:25 . 2006-02-20 22:27 81,987 --a------ C:\WINDOWS\system32\AUCPLMNT.DLL
2007-11-15 15:21 . 2007-11-15 15:25 <DIR> d-------- C:\Program Files\Canon
2007-11-13 09:25 . 2007-11-30 12:46 73 --a------ C:\WINDOWS\webica.ini
2007-11-12 18:18 . 2007-11-12 18:18 7,680 --ahs---- C:\WINDOWS\Thumbs.db
2007-11-09 21:50 . 2007-11-09 21:50 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\SmartFTP
2007-11-09 21:49 . 2007-11-09 21:49 <DIR> d-------- C:\Program Files\SmartFTP Client 2.5 Setup Files
2007-11-09 21:49 . 2007-11-09 21:49 <DIR> d-------- C:\Program Files\SmartFTP Client
2007-11-09 21:39 . 2007-11-09 21:39 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Virtual Mechanics
2007-11-09 21:39 . 2007-11-09 21:39 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Virtual Mechanics
2007-11-09 21:38 . 2007-11-09 21:38 <DIR> d-------- C:\Program Files\Virtual Mechanics
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-07 04:02 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-04 02:39 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-04 00:18 --------- d-----w C:\Program Files\Symantec
2007-12-04 00:18 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-12-04 00:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2007-11-22 16:29 --------- d-----w C:\Program Files\Common Files\Adobe
2007-11-18 18:21 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-11-13 15:35 --------- d-----w C:\Documents and Settings\Administrator\Application Data\ICAClient
2007-11-07 21:21 --------- d-----w C:\Program Files\Common Files\Intel
2007-11-07 19:21 --------- d-----w C:\Program Files\Citrix
2007-11-07 18:08 --------- d-----w C:\Program Files\CounterPath
2007-11-04 16:58 --------- d-----w C:\Program Files\palmOne
2007-11-04 16:26 --------- d-----w C:\Program Files\Palm Inc
2007-11-04 16:17 16,694 ----a-w C:\WINDOWS\system32\drivers\PalmUSBD.sys
2007-11-04 04:51 --------- d-----w C:\Documents and Settings\Administrator\Application Data\AdobeUM
2007-11-04 04:31 --------- d-----w C:\Program Files\Stellar Phoenix Windows Data Recovery
2007-11-04 02:08 --------- d-----w C:\Program Files\Drive Rescue
2007-11-03 20:26 --------- d-----w C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-11-03 20:05 --------- d-----w C:\Program Files\Belkin
2007-11-03 18:50 --------- d-----w C:\Program Files\Common Files\Adobe Systems Shared
2007-11-03 18:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\Adobe Systems
2007-11-03 18:27 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Arcsoft
2007-11-03 18:08 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Windows Desktop Search
2007-11-03 18:06 --------- d-----w C:\Program Files\Windows Desktop Search
2007-11-03 18:01 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Leadertech
2007-11-03 16:58 --------- d-----w C:\Documents and Settings\All Users\Application Data\HotSync
2007-11-03 16:57 53,248 ----a-w C:\WINDOWS\PalmDevC.dll
2007-11-03 16:57 --------- d-----w C:\Program Files\Common Files\InstallShield
2007-11-03 16:57 --------- d-----w C:\Documents and Settings\Administrator\Application Data\HotSync
2007-11-02 23:19 --------- d-----w C:\Program Files\MXpie Patch
2007-11-02 23:18 --------- d-----w C:\Program Files\WinMX
2007-11-02 23:01 --------- d-----w C:\Program Files\Windows XP Home-Pro-2003 SP2 Crack
2007-11-02 22:27 23,600 ----a-w C:\WINDOWS\system32\drivers\TVICHW32.SYS
2007-11-02 22:01 --------- d-----w C:\Program Files\MSBuild
2007-11-02 22:01 --------- d-----w C:\Program Files\Microsoft Works
2007-11-02 21:15 --------- d-----w C:\Program Files\Sophos
2007-11-02 20:19 --------- d-----w C:\Program Files\TOSHIBA
2007-11-02 20:09 --------- d-----w C:\Program Files\SigmaTel
2007-11-02 17:53 --------- d-----w C:\Program Files\Intel
2007-11-02 17:30 --------- d-----w C:\Program Files\Synaptics
2007-11-02 06:31 --------- d-----w C:\Program Files\microsoft frontpage
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Groove Explorer Icon Overlay 1 (GFS Unread Stub)]
@={99FD978C-D287-4F50-827F-B2C658EDA8E7}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Groove Explorer Icon Overlay 2 (GFS Stub)]
@={AB5C5600-7E6E-4B06-9197-9ECEF74D31CC}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)]
@={920E6DB1-9907-4370-B3A0-BAFC03D81399}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Groove Explorer Icon Overlay 3 (GFS Folder)]
@={16F3DD56-1AF5-4347-846D-7C10C4192619}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Groove Explorer Icon Overlay 4 (GFS Unread Mark)]
@={2916C86E-86A6-43FE-8112-43ABE6BF8DCC}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Offline Files]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SmartFTP Drop]
@={EA5A76F7-8138-4B53-B0F5-ADCC730CAFBD}
[HKEY_CLASSES_ROOT\CLSID\{99FD978C-D287-4F50-827F-B2C658EDA8E7}]
2006-10-27 00:48 2210608 --a------ C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
[HKEY_CLASSES_ROOT\CLSID\{AB5C5600-7E6E-4B06-9197-9ECEF74D31CC}]
2006-10-27 00:48 2210608 --a------ C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
[HKEY_CLASSES_ROOT\CLSID\{920E6DB1-9907-4370-B3A0-BAFC03D81399}]
2006-10-27 00:48 2210608 --a------ C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
[HKEY_CLASSES_ROOT\CLSID\{16F3DD56-1AF5-4347-846D-7C10C4192619}]
2006-10-27 00:48 2210608 --a------ C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
[HKEY_CLASSES_ROOT\CLSID\{2916C86E-86A6-43FE-8112-43ABE6BF8DCC}]
2006-10-27 00:48 2210608 --a------ C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
[HKEY_CLASSES_ROOT\CLSID\{EA5A76F7-8138-4B53-B0F5-ADCC730CAFBD}]
2007-11-08 01:51 406840 --a------ C:\Program Files\SmartFTP Client\sfShellTools.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"eyeBeam SIP Client"="C:\Program Files\CounterPath\X-Lite\x-lite.exe" [2007-06-05 08:52]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe" [2007-08-03 12:51]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-02-27 11:39]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-04 00:56 C:\WINDOWS\system32\rundll32.exe]
"nwiz"="nwiz.exe" [2004-04-15 15:05 C:\WINDOWS\system32\nwiz.exe]
"00THotkey"="C:\WINDOWS\system32\
00THotkey.exe" [2003-04-15 20:01]
"000StTHK"="000StTHK.exe" [2001-06-23 20:28 C:\WINDOWS\system32\
000StTHK.exe]
"TFncKy"="TFncKy.exe" []
"TPSMain"="TPSMain.exe" [2003-09-25 10:19 C:\WINDOWS\system32\TPSMain.exe]
"SigmaTel StacMon"="C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe" [2003-08-03 16:01]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-11-02 15:05]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 00:47]
"Acrobat Assistant 7.0"="C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2006-01-12 20:52]
"UserFaultCheck"="C:\WINDOWS\system32\dumprep 0 -u" []
"LogMeIn GUI"="C:\Program Files\LogMeIn\x86\LogMeInSystray.exe" [2007-08-03 15:09]
"NeroFilterCheck"="C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 15:57]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-08-08 09:25]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-12-06 22:02]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-12-06 22:03]
C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 19:16:50]
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 20:24:54]
palmOne Registration.lnk - C:\Program Files\palmOne\register.exe [2004-11-10 12:36:44]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - C:\Program Files\Belkin\Bluetooth Software\BTTray.exe [2006-06-07 17:05:38]
HotSync Manager.lnk - C:\Program Files\palmOne\Hotsync.exe [2004-06-09 14:16:08]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2007-02-05 15:39 294400]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-02-27 11:39 282624 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
LMIinit.dll 2007-11-15 18:46 87352 C:\WINDOWS\system32\LMIinit.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"qrgnqleh"=rundll32.exe "C:\Program Files\qrgnqleh\klcnuvol.dll",Init
"rsfghcze"=regsvr32 /u "C:\Documents and Settings\All Users\Application Data\rsfghcze.dll"
"<NO NAME>"=
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
**************************************************************************
catchme 0.3.1318 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2007-12-07 22:54:18
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-07 22:56:45 - machine was rebooted
.
--- E O F ---
I will run HijackThis now, and report in another post