thanks catbyte , always better to check first i think
heres the log you want
ComboFix 09-05-02.4 - P Compton 02/05/2009 17:41.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.44.1033.18.2046.1578 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
c:\docume~1\PCOMPT~1\LOCALS~1\Temp\tmp2.tmp
D:\Autorun.inf
E:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2009-04-02 to 2009-05-02 )))))))))))))))))))))))))))))))
.
2009-05-02 16:21 . 2009-05-02 16:36 ——– d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-05-02 16:20 . 2005-08-25 18:18 118784 —-a-w c:\windows\system32\MSSTDFMT.DLL
2009-05-02 16:20 . 2009-05-02 16:20 ——– d—–w c:\program files\SpywareBlaster
2009-05-02 16:19 . 2009-05-02 16:19 ——– d—–w c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-05-02 16:19 . 2009-05-02 16:19 ——– d—–w c:\program files\SUPERAntiSpyware
2009-05-02 16:19 . 2009-05-02 16:19 ——– d—–w c:\documents and settings\P Compton\Application Data\SUPERAntiSpyware.com
2009-05-02 16:18 . 2009-05-02 16:18 ——– d—–w c:\program files\Common Files\Wise Installation Wizard
2009-05-02 15:39 . 2009-05-02 15:39 ——– d—–w c:\documents and settings\P Compton\Application Data\Malwarebytes
2009-05-02 15:39 . 2009-04-06 14:32 15504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-05-02 15:39 . 2009-04-06 14:32 38496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-02 15:39 . 2009-05-02 15:39 ——– d—–w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-05-02 15:39 . 2009-05-02 15:39 ——– d—–w c:\program files\Malwarebytes' Anti-Malware
2009-04-30 17:47 . 2009-04-30 17:47 ——– d—–w c:\documents and settings\All Users\Application Data\FLEXnet
2009-04-30 15:55 . 2009-04-30 17:02 ——– d—–w c:\program files\Adobe Media Player
2009-04-30 15:54 . 2009-04-30 15:54 ——– d—–w c:\program files\Common Files\Adobe AIR
2009-04-30 15:51 . 2009-04-30 15:51 ——– d—–w c:\program files\Common Files\Macrovision Shared
2009-04-25 17:30 . 2009-04-25 17:30 ——– d—–w c:\program files\NewBlue
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-02 16:41 . 2006-03-17 17:20 6 —ha-w c:\windows\Tasks\SA.DAT
2009-05-02 15:56 . 2006-03-20 11:55 101 —-a-w c:\windows\hptuser.dat
2009-04-30 16:03 . 2006-03-20 09:40 99992 —-a-w c:\documents and settings\P Compton\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-30 15:57 . 2006-03-20 11:17 ——– d—–w c:\program files\Common Files\Adobe
2009-03-16 19:03 . 2006-03-21 10:03 372 —-a-w c:\windows\Tasks\Symantec NetDetect.job
2009-03-13 15:02 . 2006-03-21 14:28 ——– d—–w c:\program files\Common Files\Canopus Shared
2009-03-13 15:02 . 2006-03-20 09:53 ——– d–h–w c:\program files\InstallShield Installation Information
2006-03-22 09:54 . 2006-03-22 09:54 848 –sha-w c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-03-23 1830128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NexusServer"="c:\program files\Common Files\Grass Valley\ProCoder 3\Kernel\PNXSERVR.exe" [2008-08-05 520192]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 11:05 356352 —-a-w c:\program files\SUPERAntiSpyware\SASWINLO.dll
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
"wave1"= serwvdrv.dll
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
R1 TSIRCINK;Traveling Software Install Driver; [x]
S0 AACMgt;AACMgt; [x]
S0 hptmv;hptmv;c:\windows\system32\DRIVERS\hptmv.sys [2004-09-06 168041]
S1 cdrblock;cdrblock;c:\windows\system32\DRIVERS\cdrblock.sys [2007-05-31 20864]
S1 cdrport;cdrport;c:\windows\system32\DRIVERS\cdrport.sys [2005-03-11 4608]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2009-03-23 9968]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2009-03-23 72944]
S1 tsircmir;LapLink Mirror Driver Miniport;c:\windows\system32\Drivers\tsircmir.sys [2004-09-29 2816]
S2 hptsvr;HighPoint RAID Management Service;c:\program files\HighPoint Technologies, Inc.\HighPoint RAID Management Software\service\hptsvr.exe [2004-06-07 53248]
S2 TSISER;TSISER; [x]
S2 TSISTRMX;Traveling Software Stream Driver; [x]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-03-23 7408]
S3 TSIKBF5;Traveling Software Keyboard Filter Driver; [x]
S3 TSIMSF5;Traveling Software Mouse Filter Driver; [x]
S3 zskrnl;zskrnl;c:\windows\system32\DRIVERS\zskrnl.sys [2007-08-30 29952]
— Other Services/Drivers In Memory —
*NewlyCreated* - SASDIFSV
*NewlyCreated* - SASENUM
*NewlyCreated* - SASKUTIL
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{12c21efc-11c7-11db-a057-00304886ea83}]
\Shell\AutoRun\command - g:\jdlightning\Windows\JDLightning.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{32d43dd1-b5d6-11da-bca6-806d6172696f}]
\rem shell\readme\command - notepad \readme.txt
.
Contents of the 'Scheduled Tasks' folder
2009-03-16 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2006-03-21 12:24]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-AdobeBridge - (no file)
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.dvc.uk.com/index.php
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-05-02 17:42
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-05-02 17:43
ComboFix-quarantined-files.txt 2009-05-02 16:43
Pre-Run: 2,317,369,344 bytes free
Post-Run: 3,144,024,064 bytes free
110
regards phil c