ComboFix 08-03-10.1 - Ashley R 2008-03-10 18:42:29.3 - NTFSx86
Running from: C:\Documents and Settings\Ashley R\Desktop\ComboFix.exe
* Created a new restore point
[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
.
((((((((((((((((((((((((( Files Created from 2008-02-10 to 2008-03-10 )))))))))))))))))))))))))))))))
.
2008-03-10 18:32 . 2008-03-10 18:32 <DIR> d-------- C:\Program Files\Sun
2008-03-10 18:32 . 2008-02-22 02:33 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-03-10 18:23 . 2008-03-10 18:32 <DIR> d-------- C:\Program Files\Java
2008-03-10 18:22 . 2008-03-10 18:22 <DIR> d-------- C:\Program Files\Common Files\Java
2008-02-21 17:32 . 2008-02-21 17:32 <DIR> d--h----- C:\WINDOWS\PIF
2008-02-21 17:32 . 2008-02-21 17:34 72 --a------ C:\WINDOWS\chex.INI
2008-02-19 10:09 . 2008-03-04 06:14 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
2008-02-19 10:09 . 2008-02-19 10:09 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-02-17 23:52 . 2008-02-17 23:52 <DIR> d-------- C:\WINDOWS\58DD514344174F43A7DD5B8B29CEDBEA.TMP
2008-02-16 15:01 . 2008-02-16 15:01 <DIR> d-------- C:\Program Files\Trend Micro
2008-02-16 12:16 . 2008-02-16 12:16 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-02-16 12:16 . 2008-03-10 08:00 <DIR> d-------- C:\Documents and Settings\Ashley R\Application Data\AVG7
2008-02-16 12:16 . 2008-02-16 12:16 499,712 --a------ C:\WINDOWS\system32\msvcp71.dll
2008-02-16 12:16 . 2008-02-16 12:16 348,160 --a------ C:\WINDOWS\system32\msvcr71.dll
2008-02-16 12:15 . 2008-02-16 12:15 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-16 12:15 . 2008-02-16 12:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg7
2008-02-10 11:19 . 2004-08-04 07:00 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24 1694208]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:00 15360]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 21:05 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-02-16 12:15 579072]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-02-16 12:16 219136]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
D-Link AirPlus G Wireless Utility.lnk - C:\Program Files\D-Link\AirPlus G Wireless Adapter Utility\AirPlus.exe [2007-02-23 19:51:46 782412]
D-Link REG Utility.lnk - C:\Program Files\D-Link\AirPlus G Wireless Adapter Utility\Reg.exe [2007-02-23 19:51:45 24576]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 03:01:04 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
R2 BjsPort;Canon BJ Scanner Port Driver;C:\WINDOWS\system32\drivers\BjsPort.SYS [1999-09-27 10:47]
R3 neo20xx;neo20xx;C:\WINDOWS\system32\DRIVERS\neo20xx.sys [2001-08-17 07:50]
R3 OBOE;Toshiba FIR Port Type-O;C:\WINDOWS\system32\DRIVERS\tos4mo.sys [2001-08-17 07:10]
R3 wdm_opl3sax;YAMAHA OPL3-SAx Audio Driver (WDM);C:\WINDOWS\system32\drivers\opl3sax.sys [2001-08-17 07:20]
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-10 18:47:25
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-03-10 18:49:42
ComboFix-quarantined-files.txt 2008-03-10 23:49:28
ComboFix2.txt 2008-02-17 17:01:14
ComboFix3.txt 2008-02-17 14:26:42
.
2008-02-25 18:53:48 --- E O F ---