UPERAntiSpyware Scan Log
http://www.superantispyware.comGenerated 08/21/2007 at 06:01 PM
Application Version : 3.7.1018
Core Rules Database Version : 3290
Trace Rules Database Version: 1301
Scan type : Complete Scan
Total Scan Time : 00:31:23
Memory items scanned : 456
Memory threats detected : 0
Registry items scanned : 5272
Registry threats detected : 0
File items scanned : 36166
File threats detected : 0
------------------------------------------------------------------------------------
ComboFix 07-08-17.2 - "HeidiNorup" 2007-08-21 17:11:06.1 -
FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1030.18.115 [GMT 2:00]
* Created a new restore point
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
D:\Autorun.inf
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_IPRIP
-------\Iprip
((((((((((((((((((((((((( Files Created from 2007-07-21 to 2007-08-21 )))))))))))))))))))))))))))))))
2007-08-21 17:09 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-08-21 16:11 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\SUPERAntiSpyware.com
2007-08-21 16:09 786,432 --ah----- C:\DOCUME~1\ADMINI~1\NTUSER.DAT
2007-08-21 16:09 <DIR> dr------- C:\DOCUME~1\ADMINI~1\Menuen Start
2007-08-21 16:09 <DIR> dr------- C:\DOCUME~1\ADMINI~1\Foretrukne
2007-08-21 16:09 <DIR> dr------- C:\DOCUME~1\ADMINI~1\Dokumenter
2007-08-21 16:09 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Skabeloner
2007-08-21 16:09 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Printere
2007-08-21 16:09 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Lokale indstillinger
2007-08-21 16:09 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Andre computere
2007-08-21 16:09 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Skrivebord
2007-08-21 16:04 <DIR> d-------- C:\Programmer\SUPERAntiSpyware
2007-08-21 16:04 <DIR> d-------- C:\DOCUME~1\HEIDIN~1\APPLIC~1\SUPERAntiSpyware.com
2007-08-21 16:04 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com
2007-08-21 14:15 <DIR> d-------- C:\Programmer\CCleaner
2007-08-20 13:20 25,992 --a------ C:\WINDOWS\system32\pgdfgsvc.exe
2007-08-20 02:08 <DIR> d-------- C:\WINDOWS\pss
2007-08-20 01:50 331,776 --a------ C:\WINDOWS\system32\sistray.exe
2007-08-20 01:50 32,768 --a------ C:\WINDOWS\system32\Keyhook.exe
2007-08-20 01:50 20,480 --------- C:\WINDOWS\system32\LCDMode.exe
2007-08-20 01:50 110,592 --------- C:\WINDOWS\system32\TVMode.dll
2007-08-20 01:49 862,208 -ra------ C:\WINDOWS\system32\sisgrv.dll
2007-08-20 01:49 7,168 -ra------ C:\WINDOWS\InstFunc.dll
2007-08-20 01:49 65,536 -ra------ C:\WINDOWS\system32\sis760.bin
2007-08-20 01:49 65,536 -ra------ C:\WINDOWS\system32\sis741.bin
2007-08-20 01:49 49,152 -ra------ C:\WINDOWS\system32\SiSPower.dll
2007-08-20 01:49 49,152 -ra------ C:\WINDOWS\system32\SiSBase.dll
2007-08-20 01:49 49,152 -ra------ C:\WINDOWS\system32\sis660.bin
2007-08-20 01:49 32,768 -ra------ C:\WINDOWS\InstFunc.exe
2007-08-20 01:49 28,672 -ra------ C:\WINDOWS\system32\SiSPInst.dll
2007-08-20 01:49 258,048 -ra------ C:\WINDOWS\system32\SiSParse.dll
2007-08-20 01:49 184,320 -ra------ C:\WINDOWS\system32\SiSInst.dll
2007-08-20 01:49 13,312 -ra------ C:\WINDOWS\system32\drivers\srvkp.sys
2007-08-20 01:49 1,740,800 -ra------ C:\WINDOWS\system32\sisgl.dll
2007-08-20 01:49 <DIR> d-------- C:\WINDOWS\system32\trayres
2007-08-20 01:49 <DIR> d-------- C:\Programmer\SiS VGA Utilities V3.65f
2007-08-19 01:02 <DIR> d-------- C:\Programmer\Microsoft CAPICOM 2.1.0.2
2007-08-18 22:08 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2007-08-18 21:31 10,344 --a------ C:\WINDOWS\system32\drivers\symlcbrd.sys
2007-08-18 21:30 <DIR> d-------- C:\Programmer\Norton Internet Security
2007-08-18 18:15 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-08-18 17:57 <DIR> d-------- C:\Programmer\Lavalys
2007-08-11 16:32 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2007-08-11 16:16 <DIR> d-------- C:\Programmer\F‘lles filer\Wise Installation Wizard
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-08-18 23:43 806 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.INF
2007-08-18 23:43 8014 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2007-08-18 23:43 48776 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2007-08-18 23:43 115000 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-06-26 16:13 660480 --a------ C:\WINDOWS\system32\dllcache\wininet.dll
2007-06-26 15:57 851968 --a------ C:\WINDOWS\system32\dllcache\vgx.dll
2007-06-26 08:10 1104896 --a------ C:\WINDOWS\system32\msxml3.dll
2007-06-26 08:10 1104896 --a------ C:\WINDOWS\system32\dllcache\msxml3.dll
2007-06-19 15:32 282112 --a------ C:\WINDOWS\system32\gdi32.dll
2007-06-19 15:32 282112 --a------ C:\WINDOWS\system32\dllcache\gdi32.dll
2007-06-14 20:11 96768 --a------ C:\WINDOWS\system32\dllcache\inseng.dll
2007-06-14 20:11 617472 --a------ C:\WINDOWS\system32\dllcache\urlmon.dll
2007-06-14 20:11 55808 --a------ C:\WINDOWS\system32\dllcache\extmgr.dll
2007-06-14 20:11 532480 --a------ C:\WINDOWS\system32\dllcache\mstime.dll
2007-06-14 20:11 474112 --a------ C:\WINDOWS\system32\dllcache\shlwapi.dll
2007-06-14 20:11 449024 --a------ C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-06-14 20:11 39424 --a------ C:\WINDOWS\system32\dllcache\pngfilt.dll
2007-06-14 20:11 357888 --a------ C:\WINDOWS\system32\dllcache\dxtmsft.dll
2007-06-14 20:11 3079680 --a------ C:\WINDOWS\system32\dllcache\mshtml.dll
2007-06-14 20:11 251392 --a------ C:\WINDOWS\system32\dllcache\iepeers.dll
2007-06-14 20:11 205312 --a------ C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-06-14 20:11 16384 --a------ C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-06-14 20:11 151552 --a------ C:\WINDOWS\system32\dllcache\cdfview.dll
2007-06-14 20:11 1494528 --a------ C:\WINDOWS\system32\dllcache\shdocvw.dll
2007-06-14 20:11 146432 --a------ C:\WINDOWS\system32\dllcache\msrating.dll
2007-06-14 20:11 1056256 --a------ C:\WINDOWS\system32\dllcache\danim.dll
2007-06-14 20:11 1023488 --a------ C:\WINDOWS\system32\dllcache\browseui.dll
2007-06-14 16:07 18432 --a------ C:\WINDOWS\system32\dllcache\iedw.exe
2007-06-13 15:22 1034240 --a------ C:\WINDOWS\system32\dllcache\explorer.exe
2007-06-13 15:22 1034240 --a------ C:\WINDOWS\explorer.exe
2007-06-08 11:52 947096 --a------ C:\WINDOWS\system32\_ISource30.dll
--------- C:\Programmer\Fælles filer\Wise Installation Wizard
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaunchApp"="Alaunch" []
"SoundMan"="SOUNDMAN.EXE" [2005-02-23 18:13 C:\WINDOWS\SOUNDMAN.EXE]
"PCMService"="C:\Programmer\Arcade\PCMService.exe" [2005-03-09 18:59]
"IMJPMIG8.1"=":C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" []
"LManager"="C:\Programmer\Launch Manager\QtZgAcer.EXE" [2005-03-28 12:30]
"ccApp"="C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe" []
"SiSPower"="SiSPower.dll" [2005-02-25 19:35 C:\WINDOWS\system32\SiSPower.dll]
"SiS Windows KeyHook"="C:\WINDOWS\system32\keyhook.exe" [2005-03-04 13:13]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-27 05:00]
"SUPERAntiSpyware"="C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-04-23 15:46]
C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\
Belkin Wireless Utility.lnk - C:\Programmer\Belkin\Belkin 802.11g Wireless Card Configuration Utility\Belkinwcui.exe [2006-09-28 16:42:01]
Utility Tray.lnk - C:\WINDOWS\system32\sistray.exe [2007-08-20 01:50:05]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Programmer\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Programmer\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eRecoveryService]
C:\Windows\System32\Check.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSPY2002]
:C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OpwareSE2]
"C:\Programmer\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPLpr]
C:\Programmer\Synaptics\SynTP\SynTPLpr.exe
R1 UBHelper;UBHelper;C:\WINDOWS\system32\drivers\UBHelper.sys
R2 Automatisk LiveUpdate-planlægning;Automatisk LiveUpdate-planlægning;"C:\Programmer\Symantec\LiveUpdate\ALUSchedulerSvc.exe"
R2 osanbm;osanbm;C:\WINDOWS\system32\drivers\osanbm.sys
R3 DKbFltr;Dritek HotKey Keyboard Filter Driver;C:\WINDOWS\system32\Drivers\DKbFltr.sys
R3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;\??\C:\PROGRA~1\Belkin\BELKIN~1.11G\DNINDIS5.SYS
R3 HSFHWSIS;HSFHWSIS;C:\WINDOWS\system32\DRIVERS\HSFHWSIS.sys
R3 SISNICXP;SiS PCI Fast Ethernet Adapter Driver for NDIS51;C:\WINDOWS\system32\DRIVERS\sisnicxp.sys
S3 int15.sys;int15.sys;\??\C:\Programmer\acer\eRecovery\int15.sys
S3 p2pgasvc;Gruppegodkendelse på peer-netværk;C:\WINDOWS\system32\svchost.exe -k p2psvc
S3 p2pimsvc;Identitetsstyring for peer-netværk;C:\WINDOWS\system32\svchost.exe -k p2psvc
S3 p2psvc;Peer-netværk;C:\WINDOWS\system32\svchost.exe -k p2psvc
S3 PNRPSvc;PNRP (Peer Name Resolution Protocol);C:\WINDOWS\system32\svchost.exe -k p2psvc
S3 SPYWAREfighterRP;SPYWAREfighterRP;"C:\Programmer\SPYWAREfighter\spfprc.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc p2psvc p2pimsvc p2pgasvc PNRPSvc
*Newly Created Service* - COMHOST
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2007-08-21 17:14:54
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-08-21 17:20:10 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-08-21 17:20
--- E O F ---