Been a busy Saturday, hope you are having a great weekend.
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 18:57 2008-02-09
+ Scan result:
:mozilla.142:F:\Documents and Settings\Jody Powell\Application Data\Mozilla\Firefox\Profiles\nlfsa4s2.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.185:F:\Documents and Settings\Jody Powell\Application Data\Mozilla\Firefox\Profiles\nlfsa4s2.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
F:\Documents and Settings\Jody Powell\Cookies\
[email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.127:F:\Documents and Settings\Jody Powell\Application Data\Mozilla\Firefox\Profiles\nlfsa4s2.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.128:F:\Documents and Settings\Jody Powell\Application Data\Mozilla\Firefox\Profiles\nlfsa4s2.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.118:F:\Documents and Settings\Jody Powell\Application Data\Mozilla\Firefox\Profiles\nlfsa4s2.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.119:F:\Documents and Settings\Jody Powell\Application Data\Mozilla\Firefox\Profiles\nlfsa4s2.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.120:F:\Documents and Settings\Jody Powell\Application Data\Mozilla\Firefox\Profiles\nlfsa4s2.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.121:F:\Documents and Settings\Jody Powell\Application Data\Mozilla\Firefox\Profiles\nlfsa4s2.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.122:F:\Documents and Settings\Jody Powell\Application Data\Mozilla\Firefox\Profiles\nlfsa4s2.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.123:F:\Documents and Settings\Jody Powell\Application Data\Mozilla\Firefox\Profiles\nlfsa4s2.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.388:F:\Documents and Settings\Jody Powell\Application Data\Mozilla\Firefox\Profiles\nlfsa4s2.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
:mozilla.154:F:\Documents and Settings\Jody Powell\Application Data\Mozilla\Firefox\Profiles\nlfsa4s2.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.159:F:\Documents and Settings\Jody Powell\Application Data\Mozilla\Firefox\Profiles\nlfsa4s2.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.160:F:\Documents and Settings\Jody Powell\Application Data\Mozilla\Firefox\Profiles\nlfsa4s2.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.100:F:\Documents and Settings\Jody Powell\Application Data\Mozilla\Firefox\Profiles\nlfsa4s2.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.102:F:\Documents and Settings\Jody Powell\Application Data\Mozilla\Firefox\Profiles\nlfsa4s2.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.103:F:\Documents and Settings\Jody Powell\Application Data\Mozilla\Firefox\Profiles\nlfsa4s2.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.104:F:\Documents and Settings\Jody Powell\Application Data\Mozilla\Firefox\Profiles\nlfsa4s2.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.97:F:\Documents and Settings\Jody Powell\Application Data\Mozilla\Firefox\Profiles\nlfsa4s2.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.98:F:\Documents and Settings\Jody Powell\Application Data\Mozilla\Firefox\Profiles\nlfsa4s2.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.99:F:\Documents and Settings\Jody Powell\Application Data\Mozilla\Firefox\Profiles\nlfsa4s2.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.750:F:\Documents and Settings\Jody Powell\Application Data\Mozilla\Firefox\Profiles\nlfsa4s2.default\cookies.txt -> TrackingCookie.Connextra : Cleaned.
:mozilla.751:F:\Documents and Settings\Jody Powell\Application Data\Mozilla\Firefox\Profiles\nlfsa4s2.default\cookies.txt -> TrackingCookie.Connextra : Cleaned.
:mozilla.752:F:\Documents and Settings\Jody Powell\Application Data\Mozilla\Firefox\Profiles\nlfsa4s2.default\cookies.txt -> TrackingCookie.Connextra : Cleaned.
:mozilla.39:F:\Documents and Settings\Jody Powell\Application Data\Mozilla\Firefox\Profiles\nlfsa4s2.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.157:F:\Documents and Settings\Jody Powell\Application Data\Mozilla\Firefox\Profiles\nlfsa4s2.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.158:F:\Documents and Settings\Jody Powell\Application Data\Mozilla\Firefox\Profiles\nlfsa4s2.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.300:F:\Documents and Settings\Jody Powell\Application Data\Mozilla\Firefox\Profiles\nlfsa4s2.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.386:F:\Documents and Settings\Jody Powell\Application Data\Mozilla\Firefox\Profiles\nlfsa4s2.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.387:F:\Documents and Settings\Jody Powell\Application Data\Mozilla\Firefox\Profiles\nlfsa4s2.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.237:F:\Documents and Settings\Jody Powell\Application Data\Mozilla\Firefox\Profiles\nlfsa4s2.default\cookies.txt -> TrackingCookie.Netflame : Cleaned.
:mozilla.238:F:\Documents and Settings\Jody Powell\Application Data\Mozilla\Firefox\Profiles\nlfsa4s2.default\cookies.txt -> TrackingCookie.Netflame : Cleaned.
:mozilla.239:F:\Documents and Settings\Jody Powell\Application Data\Mozilla\Firefox\Profiles\nlfsa4s2.default\cookies.txt -> TrackingCookie.Netflame : Cleaned.
F:\Documents and Settings\Jody Powell\Cookies\
[email protected][1].txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.178:F:\Documents and Settings\Jody Powell\Application Data\Mozilla\Firefox\Profiles\nlfsa4s2.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.179:F:\Documents and Settings\Jody Powell\Application Data\Mozilla\Firefox\Profiles\nlfsa4s2.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.203:F:\Documents and Settings\Jody Powell\Application Data\Mozilla\Firefox\Profiles\nlfsa4s2.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.204:F:\Documents and Settings\Jody Powell\Application Data\Mozilla\Firefox\Profiles\nlfsa4s2.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.205:F:\Documents and Settings\Jody Powell\Application Data\Mozilla\Firefox\Profiles\nlfsa4s2.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.199:F:\Documents and Settings\Jody Powell\Application Data\Mozilla\Firefox\Profiles\nlfsa4s2.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.200:F:\Documents and Settings\Jody Powell\Application Data\Mozilla\Firefox\Profiles\nlfsa4s2.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.201:F:\Documents and Settings\Jody Powell\Application Data\Mozilla\Firefox\Profiles\nlfsa4s2.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.202:F:\Documents and Settings\Jody Powell\Application Data\Mozilla\Firefox\Profiles\nlfsa4s2.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.308:F:\Documents and Settings\Jody Powell\Application Data\Mozilla\Firefox\Profiles\nlfsa4s2.default\cookies.txt -> TrackingCookie.Safer-networking : Cleaned.
:mozilla.181:F:\Documents and Settings\Jody Powell\Application Data\Mozilla\Firefox\Profiles\nlfsa4s2.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.182:F:\Documents and Settings\Jody Powell\Application Data\Mozilla\Firefox\Profiles\nlfsa4s2.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.183:F:\Documents and Settings\Jody Powell\Application Data\Mozilla\Firefox\Profiles\nlfsa4s2.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.184:F:\Documents and Settings\Jody Powell\Application Data\Mozilla\Firefox\Profiles\nlfsa4s2.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.191:F:\Documents and Settings\Jody Powell\Application Data\Mozilla\Firefox\Profiles\nlfsa4s2.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.208:F:\Documents and Settings\Jody Powell\Application Data\Mozilla\Firefox\Profiles\nlfsa4s2.default\cookies.txt -> TrackingCookie.Webtrends : Cleaned.
:mozilla.209:F:\Documents and Settings\Jody Powell\Application Data\Mozilla\Firefox\Profiles\nlfsa4s2.default\cookies.txt -> TrackingCookie.Webtrends : Cleaned.
:mozilla.165:F:\Documents and Settings\Jody Powell\Application Data\Mozilla\Firefox\Profiles\nlfsa4s2.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.166:F:\Documents and Settings\Jody Powell\Application Data\Mozilla\Firefox\Profiles\nlfsa4s2.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.167:F:\Documents and Settings\Jody Powell\Application Data\Mozilla\Firefox\Profiles\nlfsa4s2.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.168:F:\Documents and Settings\Jody Powell\Application Data\Mozilla\Firefox\Profiles\nlfsa4s2.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.169:F:\Documents and Settings\Jody Powell\Application Data\Mozilla\Firefox\Profiles\nlfsa4s2.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.170:F:\Documents and Settings\Jody Powell\Application Data\Mozilla\Firefox\Profiles\nlfsa4s2.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.155:F:\Documents and Settings\Jody Powell\Application Data\Mozilla\Firefox\Profiles\nlfsa4s2.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.156:F:\Documents and Settings\Jody Powell\Application Data\Mozilla\Firefox\Profiles\nlfsa4s2.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
F:\System Volume Information\_restore{7E69122E-5246-4A50-9191-EEE1A30F5624}\RP3\A0000328.exe -> Trojan.Pakes.bwy : Cleaned.
::Report end
ComboFix 08-02.05.3 - Jody Powell 2008-02-09 16:34:03.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1595 [GMT -5:00]
Running from: F:\Documents and Settings\Jody Powell\Desktop\ComboFix(2).exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
F:\WINDOWS\system32\drivers\down
.
((((((((((((((((((((((((( Files Created from 2008-01-09 to 2008-02-09 )))))))))))))))))))))))))))))))
.
2008-02-09 16:33 . 2008-02-09 16:35 <DIR> d-------- F:\ComboFix(2)
2008-02-09 16:33 . 2004-08-04 02:56 388,608 --a------ F:\WINDOWS\system32\kmd.exe
2008-02-07 21:21 . 2008-02-07 21:21 <DIR> d-------- F:\Program Files\Trend Micro
2008-02-07 21:06 . 2008-02-07 21:07 <DIR> d-------- F:\WINDOWS\ERUNT
2008-02-07 21:00 . 2008-02-07 21:15 <DIR> d-------- F:\SDFix
2008-02-05 18:38 . 2008-02-09 16:34 <DIR> d-------- F:\WINDOWS\TEMP
2008-02-05 18:35 . 2004-08-04 02:56 388,608 --a------ F:\kmd.exe
2008-02-05 18:35 . 2000-08-31 08:00 98,816 --a------ F:\WINDOWS\system32\sed.exe
2008-02-05 18:35 . 2000-08-31 08:00 80,412 --a------ F:\WINDOWS\system32\grep.exe
2008-02-05 18:35 . 2000-08-31 08:00 73,728 --a------ F:\WINDOWS\system32\fdsv.exe
2008-02-05 18:35 . 2000-08-31 08:00 68,096 --a------ F:\WINDOWS\system32\zip.exe
2008-02-04 18:15 . 2004-08-03 23:00 260,272 --a------ F:\cmldr
2008-02-04 18:15 . 2007-09-30 13:18 210 --a------ F:\Boot.bak
2008-02-03 19:27 . 2008-02-03 19:27 <DIR> d-------- F:\Deckard
2008-02-03 12:20 . 2008-02-09 16:35 <DIR> d-------- F:\QooBox
2008-02-03 12:20 . 2000-08-31 08:00 212,480 --a------ F:\WINDOWS\system32\swxcacls.exe
2008-02-03 12:20 . 2000-08-31 08:00 161,792 --a------ F:\WINDOWS\system32\swreg.exe
2008-02-03 12:20 . 2000-08-31 08:00 136,704 --a------ F:\WINDOWS\system32\swsc.exe
2008-02-03 12:20 . 2000-08-31 08:00 51,200 --a------ F:\WINDOWS\Nircmd.exe
2008-02-03 12:20 . 2000-08-31 08:00 49,152 --a------ F:\WINDOWS\system32\VFind.exe
2008-02-02 19:55 . 2008-02-03 02:49 <DIR> d-------- F:\WINDOWS\system32\ActiveScan
2008-02-02 19:55 . 2006-08-02 12:39 73,728 --a------ F:\WINDOWS\system32\asuninst.exe
2008-02-02 19:55 . 2008-02-02 19:55 30,590 --a------ F:\WINDOWS\system32\pavas.ico
2008-02-02 19:55 . 2003-03-25 18:53 11,776 --a------ F:\WINDOWS\system32\ZPORT4AS.dll
2008-02-02 19:55 . 2008-02-02 19:55 2,550 --a------ F:\WINDOWS\system32\Uninstall.ico
2008-02-02 19:55 . 2008-02-02 19:55 1,406 --a------ F:\WINDOWS\system32\Help.ico
2008-02-02 17:14 . 2008-02-03 10:14 <DIR> d-------- F:\Program Files\SUPERAntiSpyware
2008-02-02 17:14 . 2008-02-02 17:14 <DIR> d-------- F:\Documents and Settings\Jody Powell\Application Data\SUPERAntiSpyware.com
2008-02-02 17:14 . 2008-02-02 17:14 <DIR> d-------- F:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-02-02 17:01 . 2008-02-02 17:01 <DIR> d-------- F:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-02 17:01 . 2007-05-30 07:10 10,872 --a------ F:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-02-02 11:02 . 2008-02-07 23:47 123,952 --a------ F:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-02-02 11:02 . 2008-02-07 23:47 60,808 --a------ F:\WINDOWS\system32\S32EVNT1.DLL
2008-02-02 11:02 . 2008-02-07 23:47 10,652 --a------ F:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-02-02 11:02 . 2008-02-07 23:47 806 --a------ F:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-02-02 10:22 . 2008-02-09 16:09 <DIR> d-------- F:\Documents and Settings\All Users\Application Data\Symantec
2008-02-01 18:14 . 2008-02-01 18:14 <DIR> d-------- F:\Program Files\New Folder
2008-01-30 21:08 . 2004-10-15 18:32 83,096 --a------ F:\WINDOWS\system32\SSSensor.dll
2008-01-30 19:12 . 2008-01-30 19:12 <DIR> d-------- F:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-30 19:11 . 2008-02-02 17:13 <DIR> d-------- F:\Program Files\Common Files\Wise Installation Wizard
2008-01-29 21:45 . 2008-02-09 16:26 <DIR> d-------- F:\Config.Msi
2008-01-28 20:34 . 2004-08-04 02:08 25,600 --a------ F:\WINDOWS\system32\drivers\usbser.sys
2008-01-28 20:34 . 2004-08-04 02:08 25,600 --a--c--- F:\WINDOWS\system32\dllcache\usbser.sys
2008-01-28 20:34 . 2001-08-17 13:57 16,128 --a------ F:\WINDOWS\system32\drivers\MODEMCSA.sys
2008-01-28 20:34 . 2001-08-17 13:57 16,128 --a--c--- F:\WINDOWS\system32\dllcache\modemcsa.sys
2008-01-28 20:27 . 2008-01-28 20:27 26,768 --a------ F:\WINDOWS\CTL3D.DLL
2008-01-28 20:27 . 2008-01-28 20:27 800 --a------ F:\WINDOWS\01winver.ini
2008-01-28 20:25 . 2008-01-28 20:34 <DIR> d-------- F:\Program Files\CONEXANT
2008-01-28 20:25 . 2007-03-22 00:34 212,992 --a------ F:\WINDOWS\system32\UCI32C19.dll
2008-01-28 20:25 . 2007-04-03 07:00 147,456 --a------ F:\WINDOWS\system32\TAP32C03.dll
2008-01-28 20:25 . 2007-03-15 05:52 94,208 --a------ F:\WINDOWS\system32\ACFSDK32.dll
2008-01-28 20:25 . 2007-06-29 06:39 86,656 --a------ F:\WINDOWS\system32\drivers\ACFVA32.sys
2008-01-28 20:25 . 2007-07-10 04:14 28,928 --a------ F:\WINDOWS\system32\drivers\ACFDCP32.sys
2008-01-28 20:25 . 2007-03-15 05:52 12,672 --a------ F:\WINDOWS\system32\drivers\ACFSDK32.sys
2008-01-26 12:07 . 2008-01-26 12:07 <DIR> d-------- F:\Program Files\Insight
2008-01-11 18:49 . 2008-01-11 18:49 <DIR> d-------- F:\WINDOWS\system32\URTTEMP
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-09 21:30 --------- d-----w F:\Program Files\Common Files
2008-02-09 21:28 --------- d-----w F:\Program Files\Mozilla Firefox
2008-02-09 21:26 1,610,612,736 --sha-w F:\pagefile.sys
2008-02-09 06:14 --------- d-----w F:\Documents and Settings\All Users\Application Data\Google Updater
2008-02-03 06:33 --------- d-----w F:\Program Files\Internet Explorer
2008-02-03 06:32 --------- d-----w F:\Program Files\Google
2008-02-01 23:12 --------- d-----w F:\Program Files\Common Files\Microsoft Shared
2008-01-26 22:52 --------- d-----w F:\Documents and Settings\Jody Powell\Application Data\AdobeUM
2008-01-14 03:16 --------- d--h--w F:\Program Files\InstallShield Installation Information
2008-01-05 20:14 --------- d-----w F:\Program Files\Common Files\SWF Studio
2008-01-05 20:09 --------- d-----w F:\Program Files\The Weather Channel FW
2008-01-02 18:21 17,642,616 ----a-w F:\WINDOWS\system32\MRT.exe
2007-12-14 16:32 12,632 ----a-w F:\WINDOWS\system32\lsdelete.exe
2007-11-26 23:14 18,312 ----a-w F:\Documents and Settings\Jody Powell\Application Data\GDIPFONTCACHEV1.DAT
2007-11-16 23:59 6,656 ----a-w F:\WINDOWS\system32\pndx5016.dll
2007-11-16 23:59 5,632 ----a-w F:\WINDOWS\system32\pndx5032.dll
2007-11-16 23:59 278,528 ----a-w F:\WINDOWS\system32\pncrt.dll
2007-11-16 23:59 185,944 ----a-w F:\WINDOWS\system32\rmoc3260.dll
2007-11-13 11:31 60,416 ------w F:\WINDOWS\system32\tzchange.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="F:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2006-01-25 05:02 705002]
"DW4"="F:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe" [2007-03-16 06:51 715888]
"ctfmon.exe"="F:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56 15360]
"SUPERAntiSpyware"="F:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-02-27 11:39 1310720]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="F:\WINDOWS\System32\NvCpl.dll" [2007-09-17 00:07 8491008]
"nwiz"="nwiz.exe" [2007-09-17 00:07 1626112 F:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="F:\WINDOWS\System32\NvMcTray.dll" [2007-09-17 00:07 81920]
"Adobe Reader Speed Launcher"="F:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
"SunJavaUpdateSched"="F:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11 132496]
"TkBellExe"="F:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-11-16 18:59 185896]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2005-12-07 22:57 30208]
"LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [2006-04-13 11:09 49152]
"Client Access Service"="c:\program files\client access\cwbsvstr.exe" [2002-08-06 05:20 20530]
"Client Access Help Update"="c:\program files\client access\cwbinhlp.exe" [2002-08-06 05:20 24576]
"Client Access Check Version"="c:\program files\client access\cwbckver.exe" [2002-08-06 05:20 45106]
"Client Access Express Welcome"="c:\program files\client access\cwbwlwiz.exe" [2002-08-06 05:20 20480]
"ccApp"="F:\Program Files\Common Files\Symantec Shared\ccApp.exe" [ ]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="F:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 15:38 39264]
F:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - F:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-10-23 23:37:56 217194]
Microsoft Office.lnk - F:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 00:01:04 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= F:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
F:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-02-27 11:39 282624 F:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Messenger"=2 (0x2)
R2 SQLWriter;SQL Server VSS Writer;"F:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" [2007-02-10 04:29]
R3 acfva;acfva;F:\WINDOWS\system32\DRIVERS\ACFVA32.sys [2007-06-29 06:39]
R3 dgcfltr;DGC Filter Driver;F:\WINDOWS\system32\DRIVERS\ACFDCP32.sys [2007-07-10 04:14]
S3 SymIM;Symantec Network Security Intermediate Filter Service;F:\WINDOWS\system32\DRIVERS\SymIM.sys []
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-02-09 16:35:20
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: F:\WINDOWS\system32\winlogon.exe
-> F:\WINDOWS\system32\NavLogon.dll
.