((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
Note empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“WMPNSCFG”=“C:\Program Files\Windows Media Player\WMPNSCFG.exe” [2006-11-02 04:34 201728]
“AOL Fast Start”=“C:\Program Files\AOL 9.0\AOL.exe” [2007-04-17 22:49 50736]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“MSServer”=“C:\Windows\system32\awvtt.dll” [2007-12-28 09:26 38912]
“Windows Defender”=“C:\Program Files\Windows Defender\MSASCui.exe” [2007-11-13 08:46 1006264]
“avast!”=“C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe” [2007-12-04 05:00 79224]
“SynTPEnh”=“C:\Program Files\Synaptics\SynTP\SynTPEnh.exe” [2008-01-08 08:31 761948]
“IgfxTray”=“C:\Windows\system32\igfxtray.exe” [2008-01-08 08:31 98304]
“HotKeysCmds”=“C:\Windows\system32\hkcmd.exe” [2008-01-08 08:31 106496]
“Persistence”=“C:\Windows\system32\igfxpers.exe” [2008-01-08 08:31 81920]
“RemoteControl”=“C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe” [2008-01-08 08:31 71216]
“HostManager”=“C:\Program Files\Common Files\AOL\1199815578\ee\AOLSoftware.exe” [2006-09-25 16:52 50736]
“!AVG Anti-Spyware”=“C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe” [2007-06-11 01:25 6731312]
C:\Users\Dale\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Windows Calendar.lnk - C:\Program Files\Windows Calendar\WinCal.exe [2007-11-13 08:46:57]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
“EnableLUA”= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
“{3B556978-10EB-4F71-A61E-A736354D1269}”= C:\Windows\system32\awvtt.dll [2007-12-28 09:26 38912]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
–a------ 2007-03-09 11:09 63712 C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a------ 2007-10-10 19:51 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Host Process]
C:\Users\Dale\svchost.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM]
–a------ 2006-03-20 17:34 213936 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
–a------ 2006-03-20 17:34 213936 C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
–a------ 2006-03-20 17:34 86960 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a------ 2006-09-01 15:57 282624 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YSearchProtection]
–a------ 2007-06-08 06:59 224248 C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalService REG_MULTI_SZ nsi lltdsvc SSDPSRV upnphost SCardSvr w32time EventSystem RemoteRegistry WinHttpAutoProxySvc lanmanworkstation TBS SLUINotify THREADORDER fdrespub netprofm fdphost wcncsvc QWAVE WebClient
LocalSystemNetworkRestricted REG_MULTI_SZ hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc wlansvc EMDMgmt TabletInputService WPDBusEnum
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
\shell\AutoRun\command - G:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{c8dcedce-8fe4-11dc-bc4f-00038a000015}]
\shell\AutoRun\command - G:\LaunchU3.exe -a
Newly Created Service - AVGASCLN
.
Contents of the ‘Scheduled Tasks’ folder
“2008-01-03 17:08:05 C:\Windows\Tasks\AppleSoftwareUpdate.job”
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
“2008-01-08 17:58:49 C:\Windows\Tasks\McDefragTask.job”
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe’
“2008-01-08 17:58:49 C:\Windows\Tasks\McQcTask.job”
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe
.
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-08 12:32:24
Windows 6.0.6000 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\Windows\system32\winlogon.exe [6.00.6000.16386]
→ C:\Windows\system32\awvtt.dll
PROCESS: C:\Windows\Explorer.EXE [6.00.6000.16549]
→ C:\Windows\system32\awvtt.dll
.
Completion time: 2008-01-08 12:37:30 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-08 20:37:20
.
2008-01-07 22:31:35 — E O F —