oki
"David" - 2007-05-17 18:26:47 Service Pack 2
ComboFix 07-05.17.6.V - Running from: "C:\Downloads\"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\DOCUME~1\David\Desktop\internet.lnk
((((((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\nm
((((((((((((((((((((((((((((((( Files Created from 2007-04-05 to 2007-05-17 ))))))))))))))))))))))))))))))))))
2007-05-17 17:57 218,112 --a------ C:\Program Files\HJTrenamed.exe
2007-05-17 16:48 <DIR> d-------- C:\DOCUME~1\David\APPLIC~1\DriveCleaner 2006 Free
2007-05-17 16:37 89,088 --a------ C:\WINDOWS\system32\atl71.dll
2007-05-17 16:37 499,712 --a------ C:\WINDOWS\system32\msvcp71.dll
2007-05-17 16:37 348,160 --a------ C:\WINDOWS\system32\msvcr71.dll
2007-05-17 16:37 1,060,864 --a------ C:\WINDOWS\system32\mfc71.dll
2007-05-17 14:32 <DIR> d-------- C:\Program Files\Online TV Player 3
2007-05-15 15:52 <DIR> d-------- C:\Program Files\Anti-Blaxx
2007-05-15 15:47 98,304 --a------ C:\WINDOWS\system32\CmdLineExt.dll
2007-05-14 10:59 <DIR> d-------- C:\Program Files\Lionhead Studios Ltd
2007-05-11 10:54 <DIR> d-------- C:\DOCUME~1\Guest\APPLIC~1\MusicIP
2007-05-10 14:23 <DIR> d-------- C:\My Downloads
2007-05-10 14:23 <DIR> d-------- C:\DOCUME~1\Guest\APPLIC~1\BearShare
2007-05-08 16:23 9,464 --------- C:\WINDOWS\system32\drivers\cdralw2k.sys
2007-05-08 16:23 9,336 --------- C:\WINDOWS\system32\drivers\cdr4_xp.sys
2007-05-08 16:23 129,784 --------- C:\WINDOWS\system32\pxafs.dll
2007-05-08 16:23 <DIR> d-------- C:\Program Files\Winamp
2007-05-08 16:23 <DIR> d-------- C:\DOCUME~1\David\APPLIC~1\MusicIP
2007-05-04 21:31 <DIR> d-------- C:\DOCUME~1\Guest\APPLIC~1\Google
2007-05-03 22:39 <DIR> d-------- C:\Program Files\Microprose
2007-05-03 20:18 67,538 --a------ C:\WINDOWS\War3Unin.dat
2007-05-03 20:18 2,829 --a------ C:\WINDOWS\War3Unin.pif
2007-05-03 20:18 139,264 --a------ C:\WINDOWS\War3Unin.exe
2007-05-03 18:43 <DIR> d-------- C:\Program Files\Google
2007-05-03 18:43 <DIR> d-------- C:\Program Files\BitComet
2007-05-03 18:43 <DIR> d-------- C:\Downloads
2007-05-03 18:43 <DIR> d-------- C:\DOCUME~1\David\APPLIC~1\Google
2007-05-03 18:43 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
2007-05-03 15:09 56,832 --------- C:\WINDOWS\system32\iyvu9_32.dll
2007-05-03 15:09 143,872 --------- C:\WINDOWS\system32\iacenc.dll
2007-05-03 15:08 <DIR> d-------- C:\Program Files\Microsoft Games
2007-05-03 13:20 <DIR> d-------- C:\DOCUME~1\Guest\038A524F58DB438A83918F7F0CA14B9E.TMP
2007-05-03 12:08 <DIR> d-------- C:\DOCUME~1\Guest\APPLIC~1\F-Secure
2007-05-03 12:06 1,310,720 --ah----- C:\DOCUME~1\Guest\NTUSER.DAT
2007-04-30 21:18 <DIR> d-------- C:\DOCUME~1\David\Contacts
2007-04-30 21:17 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-04-30 21:17 <DIR> d-------- C:\Program Files\MSN Messenger
2007-04-30 13:28 <DIR> d-------- C:\Program Files\DivX
2007-04-30 12:50 <DIR> d-------- C:\Program Files\QuickTime
2007-04-30 11:57 <DIR> d-------- C:\Program Files\directx
2007-04-30 11:55 <DIR> d--h----- C:\Program Files\InstallShield Installation Information
2007-04-30 11:54 <DIR> d-------- C:\Program Files\Common Files\InstallShield
2007-04-30 11:44 <DIR> d-------- C:\DOCUME~1\David\APPLIC~1\BearShare
2007-04-30 11:43 <DIR> d-------- C:\Program Files\BearShare Applications
2007-04-30 10:26 23,040 --------- C:\WINDOWS\kb913800.exe
2007-04-29 20:21 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\TrackMania United
2007-04-29 20:17 2,297,552 --a------ C:\WINDOWS\system32\d3dx9_26.dll
2007-04-29 18:57 262,144 --a------ C:\DOCUME~1\ALLUSE~1\ntuser.dat
2007-04-29 18:49 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
2007-04-29 18:22 <DIR> d--hs---- C:\RECYCLER
2007-04-29 18:03 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2007-04-29 18:03 <DIR> d-------- C:\WINDOWS\system32\PreInstall
2007-04-29 17:02 <DIR> d-------- C:\Program Files\DAEMON Tools
2007-04-29 17:00 682,232 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2007-04-29 16:12 82,944 --a------ C:\WINDOWS\system32\drivers\wdmaud.sys
2007-04-29 16:12 60,800 --a------ C:\WINDOWS\system32\drivers\sysaudio.sys
2007-04-29 16:12 6,400 --a------ C:\WINDOWS\system32\drivers\splitter.sys
2007-04-29 16:12 54,272 --a------ C:\WINDOWS\system32\drivers\swmidi.sys
2007-04-29 16:12 52,864 --a------ C:\WINDOWS\system32\drivers\DMusic.sys
2007-04-29 16:12 5,376 --a------ C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2007-04-29 16:12 4,992 --a------ C:\WINDOWS\system32\drivers\MSPQM.sys
2007-04-29 16:12 2,944 --a------ C:\WINDOWS\system32\drivers\drmkaud.sys
2007-04-29 16:12 172,416 --a------ C:\WINDOWS\system32\drivers\kmixer.sys
2007-04-29 16:12 142,464 --a------ C:\WINDOWS\system32\drivers\aec.sys
2007-04-29 16:11 7,552 --a------ C:\WINDOWS\system32\drivers\MSKSSRV.sys
2007-04-29 16:11 57,472 --a------ C:\WINDOWS\system32\drivers\redbook.sys
2007-04-29 16:11 3,072 --a------ C:\WINDOWS\system32\drivers\audstub.sys
2007-04-29 16:10 96,256 --a------ C:\WINDOWS\system32\drivers\ac97intc.sys
2007-04-29 16:10 870,784 --a------ C:\WINDOWS\system32\ati3d1ag.dll
2007-04-29 16:10 701,440 --a------ C:\WINDOWS\system32\drivers\ati2mtag.sys
2007-04-29 16:10 60,288 --a------ C:\WINDOWS\system32\drivers\drmk.sys
2007-04-29 16:10 516,768 --a------ C:\WINDOWS\system32\ativvaxx.dll
2007-04-29 16:10 42,368 --a------ C:\WINDOWS\system32\drivers\AGP440.SYS
2007-04-29 16:10 4,096 --a------ C:\WINDOWS\system32\ksuser.dll
2007-04-29 16:10 229,376 --a------ C:\WINDOWS\system32\ati2cqag.dll
2007-04-29 16:10 201,728 --a------ C:\WINDOWS\system32\ati2dvag.dll
2007-04-29 16:10 20,992 --a------ C:\WINDOWS\system32\drivers\RTL8139.sys
2007-04-29 16:10 145,792 --a------ C:\WINDOWS\system32\drivers\portcls.sys
2007-04-29 16:10 1,888,992 --a------ C:\WINDOWS\system32\ati3duag.dll
2007-04-29 16:09 74,240 --a------ C:\WINDOWS\system32\usbui.dll
2007-04-29 16:09 10,624 --a------ C:\WINDOWS\system32\drivers\gameenum.sys
2007-04-29 16:08 9,936 --a------ C:\WINDOWS\system\LZEXPAND.DLL
2007-04-29 16:08 9,008 --a------ C:\WINDOWS\system\VER.DLL
2007-04-29 16:08 85,020 --a------ C:\WINDOWS\system32\dgsetup.dll
2007-04-29 16:08 82,944 --a------ C:\WINDOWS\system\OLECLI.DLL
2007-04-29 16:08 8,704 --a------ C:\WINDOWS\system32\batt.dll
2007-04-29 16:08 8,192 -ra------ C:\WINDOWS\system32\kbdhept.dll
2007-04-29 16:08 74,752 --a------ C:\WINDOWS\system32\storprop.dll
2007-04-29 16:08 7,168 -ra------ C:\WINDOWS\system32\kbdcz.dll
2007-04-29 16:08 69,584 --a------ C:\WINDOWS\system\AVICAP.DLL
2007-04-29 16:08 69,120 --a------ C:\WINDOWS\NOTEPAD.EXE
2007-04-29 16:08 68,768 --a------ C:\WINDOWS\system\MMSYSTEM.DLL
2007-04-29 16:08 6,656 -ra------ C:\WINDOWS\system32\kbdycl.dll
2007-04-29 16:08 6,656 -ra------ C:\WINDOWS\system32\kbdsl1.dll
2007-04-29 16:08 6,656 -ra------ C:\WINDOWS\system32\kbdsl.dll
2007-04-29 16:08 6,656 -ra------ C:\WINDOWS\system32\kbdpl.dll
2007-04-29 16:08 6,656 -ra------ C:\WINDOWS\system32\kbdhu.dll
2007-04-29 16:08 6,656 -ra------ C:\WINDOWS\system32\kbdhela3.dll
2007-04-29 16:08 6,656 -ra------ C:\WINDOWS\system32\kbdcz2.dll
2007-04-29 16:08 6,656 -ra------ C:\WINDOWS\system32\kbdcz1.dll
2007-04-29 16:08 6,656 -ra------ C:\WINDOWS\system32\kbdcr.dll
2007-04-29 16:08 6,656 -ra------ C:\WINDOWS\system32\KBDAL.DLL
2007-04-29 16:08 6,144 -ra------ C:\WINDOWS\system32\kbdtuq.dll
2007-04-29 16:08 6,144 -ra------ C:\WINDOWS\system32\kbdtuf.dll
2007-04-29 16:08 6,144 -ra------ C:\WINDOWS\system32\kbdlv1.dll
2007-04-29 16:08 6,144 -ra------ C:\WINDOWS\system32\kbdlv.dll
2007-04-29 16:08 6,144 -ra------ C:\WINDOWS\system32\kbdhela2.dll
2007-04-29 16:08 6,144 -ra------ C:\WINDOWS\system32\kbdgkl.dll
2007-04-29 16:08 6,144 -ra------ C:\WINDOWS\system32\kbdest.dll
2007-04-29 16:08 5,632 -ra------ C:\WINDOWS\system32\kbdro.dll
2007-04-29 16:08 5,632 -ra------ C:\WINDOWS\system32\kbdpl1.dll
2007-04-29 16:08 5,632 -ra------ C:\WINDOWS\system32\kbdmon.dll
2007-04-29 16:08 5,632 -ra------ C:\WINDOWS\system32\kbdlt1.dll
2007-04-29 16:08 5,632 -ra------ C:\WINDOWS\system32\kbdlt.dll
2007-04-29 16:08 5,632 -ra------ C:\WINDOWS\system32\kbdkyr.dll
2007-04-29 16:08 5,632 -ra------ C:\WINDOWS\system32\kbdhu1.dll
2007-04-29 16:08 5,632 -ra------ C:\WINDOWS\system32\kbdhe319.dll
2007-04-29 16:08 5,632 -ra------ C:\WINDOWS\system32\kbdhe220.dll
2007-04-29 16:08 5,632 -ra------ C:\WINDOWS\system32\kbdhe.dll
2007-04-29 16:08 5,632 -ra------ C:\WINDOWS\system32\kbdazel.dll
2007-04-29 16:08 5,120 --a------ C:\WINDOWS\system\SHELL.DLL
2007-04-29 16:08 32,816 --a------ C:\WINDOWS\system\COMMDLG.DLL
2007-04-29 16:08 24,661 --a------ C:\WINDOWS\system32\spxcoins.dll
2007-04-29 16:08 24,064 --a------ C:\WINDOWS\system\OLESVR.DLL
2007-04-29 16:08 19,200 --a------ C:\WINDOWS\system\TAPI.DLL
2007-04-29 16:08 176,157 --a------ C:\WINDOWS\system32\dgrpsetu.dll
2007-04-29 16:08 15,360 --a------ C:\WINDOWS\TASKMAN.EXE
2007-04-29 16:08 13,312 --a------ C:\WINDOWS\system32\irclass.dll
2007-04-29 16:08 126,912 --a------ C:\WINDOWS\system\MSVIDEO.DLL
2007-04-29 16:08 11,264 --a------ C:\WINDOWS\system32\drivers\irenum.sys
2007-04-29 16:08 109,456 --a------ C:\WINDOWS\system\AVIFILE.DLL
2007-04-29 16:08 103,424 --a------ C:\WINDOWS\system32\EqnClass.Dll
2007-04-29 16:08 <DIR> dr------- C:\Program Files
2007-04-29 16:08 <DIR> dr------- C:\DOCUME~1\ALLUSE~1\Documents
2007-04-29 16:08 <DIR> d--hs---- C:\WINDOWS\Installer
2007-04-29 16:08 <DIR> d-------- C:\Program Files\Common Files\SpeechEngines
2007-04-29 16:08 <DIR> d-------- C:\Program Files\Common Files\ODBC
2007-04-29 16:07 <DIR> d--hs---- C:\System Volume Information
2007-04-29 16:07 <DIR> d-------- C:\WINDOWS\system32\CatRoot2
2007-04-29 16:07 <DIR> d-------- C:\WINDOWS\system32\CatRoot
2007-04-29 16:07 <DIR> d-------- C:\Documents and Settings
2007-04-29 15:59 <DIR> dr-hsc--- C:\WINDOWS\system32\dllcache
2007-04-29 15:59 <DIR> dr--s---- C:\WINDOWS\Fonts
2007-04-29 15:59 <DIR> dr------- C:\WINDOWS\Web
2007-04-29 15:59 <DIR> d--h----- C:\WINDOWS\inf
2007-04-29 15:59 <DIR> d-------- C:\WINDOWS\WinSxS
2007-04-29 15:59 <DIR> d-------- C:\WINDOWS\twain_32
2007-04-29 15:59 <DIR> d-------- C:\WINDOWS\system32\wins
2007-04-29 15:59 <DIR> d-------- C:\WINDOWS\system32\wbem
2007-04-29 15:59 <DIR> d-------- C:\WINDOWS\system32\usmt
2007-04-29 15:59 <DIR> d-------- C:\WINDOWS\system32\spool
2007-04-29 15:59 <DIR> d-------- C:\WINDOWS\system32\ShellExt
2007-04-29 15:59 <DIR> d-------- C:\WINDOWS\system32\Setup
2007-04-29 15:59 <DIR> d-------- C:\WINDOWS\system32\ras
2007-04-29 15:59 <DIR> d-------- C:\WINDOWS\system32\oobe
2007-04-29 15:59 <DIR> d-------- C:\WINDOWS\system32\npp
2007-04-29 15:59 <DIR> d-------- C:\WINDOWS\system32\mui
2007-04-29 15:59 <DIR> d-------- C:\WINDOWS\system32\inetsrv
2007-04-29 15:59 <DIR> d-------- C:\WINDOWS\system32\IME
2007-04-29 15:59 <DIR> d-------- C:\WINDOWS\system32\icsxml
2007-04-29 15:59 <DIR> d-------- C:\WINDOWS\system32\ias
2007-04-29 15:59 <DIR> d-------- C:\WINDOWS\system32\export
2007-04-29 15:59 <DIR> d-------- C:\WINDOWS\system32\drivers\etc
2007-04-29 15:59 <DIR> d-------- C:\WINDOWS\system32\drivers\disdn
2007-04-29 15:59 <DIR> d-------- C:\WINDOWS\system32\drivers
2007-04-29 15:59 <DIR> d-------- C:\WINDOWS\system32\dhcp
2007-04-29 15:59 <DIR> d-------- C:\WINDOWS\system32\config
2007-04-29 15:59 <DIR> d-------- C:\WINDOWS\system32\3com_dmi
2007-04-29 15:59 <DIR> d-------- C:\WINDOWS\system32\3076
2007-04-29 15:59 <DIR> d-------- C:\WINDOWS\system32\2052
2007-04-29 15:59 <DIR> d-------- C:\WINDOWS\system32\1054
2007-04-29 15:59 <DIR> d-------- C:\WINDOWS\system32\1042
2007-04-29 15:59 <DIR> d-------- C:\WINDOWS\system32\1041
2007-04-29 15:59 <DIR> d-------- C:\WINDOWS\system32\1037
2007-04-29 15:59 <DIR> d-------- C:\WINDOWS\system32\1033
2007-04-29 15:59 <DIR> d-------- C:\WINDOWS\system32\1031
2007-04-29 15:59 <DIR> d-------- C:\WINDOWS\system32\1028
2007-04-29 15:59 <DIR> d-------- C:\WINDOWS\system32\1025
2007-04-29 15:59 <DIR> d-------- C:\WINDOWS\system32
2007-04-29 15:59 <DIR> d-------- C:\WINDOWS\system
2007-04-29 15:59 <DIR> d-------- C:\WINDOWS\security
2007-04-29 15:59 <DIR> d-------- C:\WINDOWS\Resources
2007-04-29 15:59 <DIR> d-------- C:\WINDOWS\repair
2007-04-29 15:59 <DIR> d-------- C:\WINDOWS\Provisioning
2007-04-29 15:59 <DIR> d-------- C:\WINDOWS\PeerNet
2007-04-29 15:59 <DIR> d-------- C:\WINDOWS\pchealth
2007-04-29 15:59 <DIR> d-------- C:\WINDOWS\mui
2007-04-29 15:59 <DIR> d-------- C:\WINDOWS\msapps
2007-04-29 15:59 <DIR> d-------- C:\WINDOWS\msagent
2007-04-29 15:59 <DIR> d-------- C:\WINDOWS\Media
2007-04-29 15:59 <DIR> d-------- C:\WINDOWS\ime
2007-04-29 15:59 <DIR> d-------- C:\WINDOWS\Help
2007-04-29 15:59 <DIR> d-------- C:\WINDOWS\ehome
2007-04-29 15:59 <DIR> d-------- C:\WINDOWS\Driver Cache
2007-04-29 15:59 <DIR> d-------- C:\WINDOWS\dell
2007-04-29 15:59 <DIR> d-------- C:\WINDOWS\Debug
2007-04-29 15:59 <DIR> d-------- C:\WINDOWS\Cursors
2007-04-29 15:59 <DIR> d-------- C:\WINDOWS\Connection Wizard
2007-04-29 15:59 <DIR> d-------- C:\WINDOWS\Config
2007-04-29 15:59 <DIR> d-------- C:\WINDOWS\AppPatch
2007-04-29 15:59 <DIR> d-------- C:\WINDOWS\addins
2007-04-29 15:59 <DIR> d-------- C:\WINDOWS
2007-04-29 15:48 <DIR> d-------- C:\DOCUME~1\David\APPLIC~1\PEX
2007-04-29 15:48 <DIR> d-------- C:\DOCUME~1\David\APPLIC~1\F-Secure
2007-04-29 15:44 70,864 --a------ C:\WINDOWS\system32\drivers\fsdfw.sys
2007-04-29 15:44 33,584 --a------ C:\WINDOWS\system32\drivers\fsndis5.sys
2007-04-29 15:44 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\F-Secure
2007-04-29 15:32 118,842 -r------- C:\WINDOWS\bwUnin-6.3.2.116-4476822L.exe
2007-04-29 15:32 <DIR> d-------- C:\Program Files\F-Secure Internet Security
2007-04-29 15:28 <DIR> d---s---- C:\DOCUME~1\David\UserData
2007-04-29 15:21 61,440 --a------ C:\WINDOWS\system32\WMErrDAN.dll
2007-04-29 15:20 <DIR> d-------- C:\Program Files\Windows XP MUI Pack
2007-04-29 15:12 <DIR> d-------- C:\WINDOWS\RegisteredPackages
2007-04-29 15:08 46,592 --------- C:\WINDOWS\system32\drivers\irbus.sys
2007-04-29 15:08 19,200 --------- C:\WINDOWS\system32\drivers\hidir.sys
2007-04-29 15:06 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2007-04-29 15:02 <DIR> d-------- C:\WINDOWS\system32\URTTemp
2007-04-29 15:02 <DIR> d-------- C:\Program Files\RGB
2007-04-29 14:57 <DIR> d-------- C:\Program Files\GemMaster
2007-04-29 14:57 <DIR> d-------- C:\Program Files\ESPNMotion
2007-04-29 14:57 <DIR> d-------- C:\Program Files\EnglishOtto
2007-04-29 14:57 <DIR> d-------- C:\Program Files\DIGStream
2007-04-29 14:57 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\DIGStream
2007-04-29 14:37 3,407,872 --ah----- C:\DOCUME~1\David\NTUSER.DAT
2007-04-29 14:36 <DIR> d-------- C:\WINDOWS\system32\SoftwareDistribution
2007-04-29 14:35 262,144 --ah----- C:\DOCUME~1\LOCALS~1\NTUSER.DAT
2007-04-29 14:35 <DIR> d-------- C:\WINDOWS\SoftwareDistribution
2007-04-29 14:35 <DIR> d-------- C:\WINDOWS\Prefetch
2007-04-29 14:34 262,144 --ah----- C:\DOCUME~1\NETWOR~1\NTUSER.DAT
2007-04-29 14:27 <DIR> d-------- C:\WINDOWS\system32\xircom
2007-04-29 14:27 <DIR> d-------- C:\Program Files\microsoft frontpage
2007-04-29 14:26 262,144 --ah----- C:\DOCUME~1\DEFAUL~1\NTUSER.DAT
2007-04-29 14:26 0 -rahs---- C:\MSDOS.SYS
2007-04-29 14:26 0 -rahs---- C:\IO.SYS
2007-04-29 14:26 0 --a------ C:\CONFIG.SYS
2007-04-29 14:26 0 --a------ C:\AUTOEXEC.BAT
2007-04-29 14:26 <DIR> d-------- C:\DELL
2007-04-29 14:25 112,128 --a------ C:\WINDOWS\system32\mapi32.dll
2007-04-29 14:23 <DIR> dr------- C:\WINDOWS\Offline Web Pages
2007-04-29 14:23 <DIR> d--hs---- C:\DOCUME~1\ALLUSE~1\DRM
2007-04-29 14:23 <DIR> d--h----- C:\Program Files\WindowsUpdate
2007-04-29 14:23 <DIR> d---s---- C:\WINDOWS\Downloaded Program Files
2007-04-29 14:22 81,920 --a------ C:\WINDOWS\system32\isign32.dll
2007-04-29 14:22 81,920 --a------ C:\WINDOWS\system32\ils.dll
2007-04-29 14:22 8,192 --a------ C:\WINDOWS\system32\bitsprx2.dll
2007-04-29 14:22 73,728 --a------ C:\WINDOWS\system32\icwdial.dll
2007-04-29 14:22 73,472 --a------ C:\WINDOWS\system32\drivers\sr.sys
2007-04-29 14:22 7,168 --a------ C:\WINDOWS\system32\bitsprx3.dll
2007-04-29 14:22 69,632 --a------ C:\WINDOWS\system32\msconf.dll
2007-04-29 14:22 679,424 --a------ C:\WINDOWS\system32\inetcomm.dll
2007-04-29 14:22 67,584 --a------ C:\WINDOWS\system32\srclient.dll
2007-04-29 14:22 65,536 --a------ C:\WINDOWS\system32\icwphbk.dll
2007-04-29 14:22 64,512 --a------ C:\WINDOWS\system32\acctres.dll
2007-04-29 14:22 6,656 --a------ C:\WINDOWS\system32\wuauserv.dll
2007-04-29 14:22 48,128 --a------ C:\WINDOWS\system32\inetres.dll
2007-04-29 14:22 465,176 --a------ C:\WINDOWS\system32\wuapi.dll
2007-04-29 14:22 45,568 --a------ C:\WINDOWS\system32\safrslv.dll
2007-04-29 14:22 43,520 --a------ C:\WINDOWS\system32\safrcdlg.dll
2007-04-29 14:22 43,520 --a------ C:\WINDOWS\system32\racpldlg.dll
2007-04-29 14:22 41,240 --a------ C:\WINDOWS\system32\wups.dll
2007-04-29 14:22 382,464 --a------ C:\WINDOWS\system32\qmgr.dll
2007-04-29 14:22 34,560 --a------ C:\WINDOWS\system32\mnmdd.dll
2007-04-29 14:22 32,768 --a------ C:\WINDOWS\system32\mnmsrvc.exe
2007-04-29 14:22 32,768 --a------ C:\WINDOWS\system32\isrdbg32.dll
2007-04-29 14:22 29,696 --a------ C:\WINDOWS\system32\safrdm.dll
2007-04-29 14:22 28,672 --a------ C:\WINDOWS\system32\nmmkcert.dll
2007-04-29 14:22 274,944 --a------ C:\WINDOWS\system32\mstask.dll
2007-04-29 14:22 274,432 --a------ C:\WINDOWS\system32\inetcfg.dll
2007-04-29 14:22 252,928 --a------ C:\WINDOWS\system32\msoeacct.dll
2007-04-29 14:22 239,104 --a------ C:\WINDOWS\system32\srrstr.dll
2007-04-29 14:22 23,040 --a------ C:\WINDOWS\system32\fltmc.exe
2007-04-29 14:22 194,328 --a------ C:\WINDOWS\system32\wuaueng1.dll
2007-04-29 14:22 190,976 --a------ C:\WINDOWS\system32\schedsvc.dll
2007-04-29 14:22 18,944 --a------ C:\WINDOWS\system32\qmgrprxy.dll
2007-04-29 14:22 173,536 --a------ C:\WINDOWS\system32\wuweb.dll
2007-04-29 14:22 172,312 --a------ C:\WINDOWS\system32\wuauclt1.exe
2007-04-29 14:22 170,496 --a------ C:\WINDOWS\system32\srsvc.dll
2007-04-29 14:22 16,896 --a------ C:\WINDOWS\system32\fltlib.dll
2007-04-29 14:22 16,384 --a------ C:\WINDOWS\system32\icfgnt5.dll
2007-04-29 14:22 128,896 --a------ C:\WINDOWS\system32\drivers\fltmgr.sys
2007-04-29 14:22 127,256 --a------ C:\WINDOWS\system32\wucltui.dll
2007-04-29 14:22 124,184 --a------ C:\WINDOWS\system32\wuauclt.exe
2007-04-29 14:22 12,288 --a------ C:\WINDOWS\system32\nmevtmsg.dll
2007-04-29 14:22 12,288 --a------ C:\WINDOWS\system32\mstinit.exe
2007-04-29 14:22 11,264 --a------ C:\WINDOWS\system32\atrace.dll
2007-04-29 14:22 105,984 --a------ C:\WINDOWS\system32\msoert2.dll
2007-04-29 14:22 1,343,768 --a------ C:\WINDOWS\system32\wuaueng.dll
2007-04-29 14:22 <DIR> d---s---- C:\WINDOWS\Tasks
2007-04-29 14:22 <DIR> d-------- C:\WINDOWS\system32\Restore
2007-04-29 14:22 <DIR> d-------- C:\WINDOWS\system32\Macromed
2007-04-29 14:22 <DIR> d-------- C:\WINDOWS\system32\DirectX
2007-04-29 14:22 <DIR> d-------- C:\WINDOWS\srchasst
2007-04-29 14:22 <DIR> d-------- C:\Program Files\Common Files\MSSoap
2007-04-29 14:20 21,640 --a------ C:\WINDOWS\system32\emptyregdb.dat
2007-04-29 14:19 <DIR> d-------- C:\WINDOWS\Registration
2007-04-29 14:19 <DIR> d-------- C:\Program Files\Online Services
2007-04-29 14:18 85,504 --a------ C:\WINDOWS\system32\mhn.dll
2007-04-29 14:18 8,704 --a------ C:\WINDOWS\system32\igdetect.dll
2007-04-29 14:18 7,093,760 --a------ C:\WINDOWS\system32\space.scr
2007-04-29 14:18 5,068,800 --a------ C:\WINDOWS\system32\davinci.scr
2007-04-29 14:18 43,528 --------- C:\WINDOWS\system32\drivers\pxhelp20.sys
2007-04-29 14:18 4,396,544 --a------ C:\WINDOWS\system32\wpgldfsh.scr
2007-04-29 14:18 3,343,360 --a------ C:\WINDOWS\system32\nature.scr
2007-04-29 14:18 11,008 --a------ C:\WINDOWS\system32\drivers\mhndrv.sys
2007-04-29 14:18 1,742,336 --a------ C:\WINDOWS\system32\mypixdx.scr
2007-04-29 14:18 <DIR> d-------- C:\Program Files\Windows Plus
2007-04-29 14:18 <DIR> d-------- C:\Program Files\Movie Maker
2007-04-29 14:17 97,792 --a------ C:\WINDOWS\system32\comrepl.dll
2007-04-29 14:17 9,728 --a------ C:\WINDOWS\system32\reset.exe
2007-04-29 14:17 80,384 --a------ C:\WINDOWS\system32\charmap.exe
2007-04-29 14:17 73,216 --a------ C:\WINDOWS\system32\avwav.dll
2007-04-29 14:17 605,696 --a------ C:\WINDOWS\system32\getuname.dll
2007-04-29 14:17 56,832 --a------ C:\WINDOWS\system32\sol.exe
2007-04-29 14:17 55,296 --a------ C:\WINDOWS\system32\freecell.exe
2007-04-29 14:17 54,272 --a------ C:\WINDOWS\system32\stclient.dll
2007-04-29 14:17 5,632 --a------ C:\WINDOWS\system32\write.exe
2007-04-29 14:17 5,120 --a------ C:\WINDOWS\system32\dcomcnfg.exe
2007-04-29 14:17 44,544 --a------ C:\WINDOWS\system32\hticons.dll
2007-04-29 14:17 4,096 --a------ C:\WINDOWS\system32\rdpcfgex.dll
2007-04-29 14:17 4,096 --a------ C:\WINDOWS\system32\mtxex.dll
2007-04-29 14:17 35,328 --a------ C:\WINDOWS\system32\winchat.exe
2007-04-29 14:17 33,792 --a------ C:\WINDOWS\system32\regini.exe
2007-04-29 14:17 25,600 --a------ C:\WINDOWS\system32\comaddin.dll
2007-04-29 14:17 25,088 --a------ C:\WINDOWS\system32\mtxlegih.dll
2007-04-29 14:17 227,840 --a------ C:\WINDOWS\system32\avtapi.dll
2007-04-29 14:17 22,016 --a------ C:\WINDOWS\system32\qwinsta.exe
2007-04-29 14:17 20,992 --a------ C:\WINDOWS\system32\msg.exe
2007-04-29 14:17 20,480 --a------ C:\WINDOWS\system32\mtxdm.dll
2007-04-29 14:17 16,896 --a------ C:\WINDOWS\system32\tsshutdn.exe
2007-04-29 14:17 16,896 --a------ C:\WINDOWS\system32\qappsrv.exe
2007-04-29 14:17 16,384 --a------ C:\WINDOWS\system32\tskill.exe
2007-04-29 14:17 16,384 --a------ C:\WINDOWS\system32\avmeter.dll
2007-04-29 14:17 15,872 --a------ C:\WINDOWS\system32\rwinsta.exe
2007-04-29 14:17 15,872 --a------ C:\WINDOWS\system32\cdmodem.dll
2007-04-29 14:17 15,360 --a------ C:\WINDOWS\system32\logoff.exe
2007-04-29 14:17 147,456 --a------ C:\WINDOWS\system32\comsnap.dll
2007-04-29 14:17 14,848 --a------ C:\WINDOWS\system32\tsdiscon.exe
2007-04-29 14:17 14,848 --a------ C:\WINDOWS\system32\tscon.exe
2007-04-29 14:17 14,848 --a------ C:\WINDOWS\system32\shadow.exe
2007-04-29 14:17 138,752 --a------ C:\WINDOWS\system32\sndvol32.exe
2007-04-29 14:17 126,976 --a------ C:\WINDOWS\system32\mshearts.exe
2007-04-29 14:17 119,808 --a------ C:\WINDOWS\system32\winmine.exe
2007-04-29 14:17 114,688 --a------ C:\WINDOWS\system32\calc.exe
2007-04-29 14:17 1,161 --a------ C:\WINDOWS\system32\usrlogon.cmd
2007-04-29 14:17 <DIR> d-------- C:\Program Files\MSN Gaming Zone
2007-04-29 14:17 <DIR> d-------- C:\Program Files\Messenger
2007-04-29 14:16 956,416 --a------ C:\WINDOWS\system32\msdtctm.dll
2007-04-29 14:16 93,696 --a------ C:\WINDOWS\system32\tscfgwmi.dll
2007-04-29 14:16 91,136 --a------ C:\WINDOWS\system32\mtxoci.dll
2007-04-29 14:16 87,176 --a------ C:\WINDOWS\system32\rdpwsx.dll
2007-04-29 14:16 85,504 --a------ C:\WINDOWS\system32\catsrvps.dll
2007-04-29 14:16 67,072 --a------ C:\WINDOWS\system32\rdshost.exe
2007-04-29 14:16 655,360 --a------ C:\WINDOWS\system32\mstscax.dll
2007-04-29 14:16 625,152 --a------ C:\WINDOWS\system32\catsrvut.dll
2007-04-29 14:16 62,464 --a------ C:\WINDOWS\system32\rdpclip.exe
2007-04-29 14:16 60,416 --a------ C:\WINDOWS\system32\remotepg.dll
2007-04-29 14:16 60,416 --a------ C:\WINDOWS\system32\colbact.dll
2007-04-29 14:16 6,144 --a------ C:\WINDOWS\system32\msdtc.exe
2007-04-29 14:16 58,880 --a------ C:\WINDOWS\system32\msdtclog.dll
2007-04-29 14:16 58,880 --a------ C:\WINDOWS\system32\licwmi.dll
2007-04-29 14:16 56,320 --a------ C:\WINDOWS\system32\servdeps.dll
2007-04-29 14:16 540,160 --a------ C:\WINDOWS\system32\comuid.dll
2007-04-29 14:16 538,624 --a------ C:\WINDOWS\system32\spider.exe
2007-04-29 14:16 498,688 --a------ C:\WINDOWS\system32\clbcatq.dll
2007-04-29 14:16 44,544 --a------ C:\WINDOWS\system32\tscupgrd.exe
2007-04-29 14:16 426,496 --a------ C:\WINDOWS\system32\msdtcprx.dll
2007-04-29 14:16 407,552 --a------ C:\WINDOWS\system32\mstsc.exe
2007-04-29 14:16 40,840 --a------ C:\WINDOWS\system32\drivers\termdd.sys
2007-04-29 14:16 38,912 --a------ C:\WINDOWS\system32\cfgbkend.dll
2007-04-29 14:16 347,136 --a------ C:\WINDOWS\system32\hypertrm.dll
2007-04-29 14:16 343,040 --a------ C:\WINDOWS\system32\mspaint.exe
2007-04-29 14:16 295,424 --a------ C:\WINDOWS\system32\termsrv.dll
2007-04-29 14:16 225,792 --a------ C:\WINDOWS\system32\catsrv.dll
2007-04-29 14:16 21,896 --a------ C:\WINDOWS\system32\drivers\tdtcp.sys
2007-04-29 14:16 20,480 --a------ C:\WINDOWS\system32\qprocess.exe
2007-04-29 14:16 196,864 --a------ C:\WINDOWS\system32\drivers\rdpdr.sys
2007-04-29 14:16 19,968 --a------ C:\WINDOWS\system32\rdpsnd.dll
2007-04-29 14:16 185,344 --a------ C:\WINDOWS\system32\cmprops.dll
2007-04-29 14:16 183,808 --a------ C:\WINDOWS\system32\accwiz.exe
2007-04-29 14:16 17,408 --a------ C:\WINDOWS\system32\mmfutil.dll
2007-04-29 14:16 161,280 --a------ C:\WINDOWS\system32\msdtcuiu.dll
2007-04-29 14:16 147,968 --a------ C:\WINDOWS\system32\rdchost.dll
2007-04-29 14:16 140,800 --a------ C:\WINDOWS\system32\sessmgr.exe
2007-04-29 14:16 139,528 --a------ C:\WINDOWS\system32\drivers\rdpwd.sys
2007-04-29 14:16 131,584 --a------ C:\WINDOWS\system32\sndrec32.exe
2007-04-29 14:16 13,824 --a------ C:\WINDOWS\system32\rdsaddin.exe
2007-04-29 14:16 123,392 --a------ C:\WINDOWS\system32\mplay32.exe
2007-04-29 14:16 12,040 --a------ C:\WINDOWS\system32\drivers\tdpipe.sys
2007-04-29 14:16 110,080 --a------ C:\WINDOWS\system32\clbcatex.dll
2007-04-29 14:16 11,776 --a------ C:\WINDOWS\system32\xolehlp.dll
2007-04-29 14:16 11,264 --a------ C:\WINDOWS\system32\icaapi.dll
2007-04-29 14:16 102,912 --a------ C:\WINDOWS\system32\clipbrd.exe
2007-04-29 14:16 1,267,200 --a------ C:\WINDOWS\system32\comsvcs.dll
2007-04-29 14:16 <DIR> d-------- C:\WINDOWS\system32\MsDtc
2007-04-29 14:16 <DIR> d-------- C:\WINDOWS\system32\Com
2007-04-29 14:16 <DIR> d-------- C:\Program Files\Windows NT
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-05-03 16:43:24 2,560 ----a-w C:\WINDOWS\system32\BitCometRes.dll
2007-03-17 13:43:01 292,864 ----a-w C:\WINDOWS\system32\winsrv.dll
2007-03-08 15:36:28 577,536 ----a-w C:\WINDOWS\system32\user32.dll
2007-03-08 15:36:28 40,960 ----a-w C:\WINDOWS\system32\mf3216.dll
2007-03-08 15:36:28 281,600 ----a-w C:\WINDOWS\system32\gdi32.dll
2007-03-08 13:47:48 1,843,584 ----a-w C:\WINDOWS\system32\win32k.sys
2007-02-05 20:17:02 185,344 ----a-w C:\WINDOWS\system32\upnphost.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}=C:\Program Files\BitComet\tools\BitCometBHO_1.1.3.28.dll [2007-03-29 16:31]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll [2007-03-14 03:43]
{9030D464-4C02-4ABF-8ECC-5164760863C6}=C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2006-08-31 20:33]
{AA58ED58-01DD-4d91-8333-CF10577473F7}=c:\program files\google\googletoolbar2.dll [2007-05-05 11:41]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 13:56]
"F-Secure Manager"="C:\Program Files\F-Secure Internet Security\Common\FSM32.exe" [2005-06-03 00:37]
"F-Secure TNB"="C:\Program Files\F-Secure Internet Security\TNB\TNBUtil.exe" [2005-07-18 16:51]
"F-Secure Startup Wizard"="C:\Program Files\F-Secure Internet Security\FSGUI\FSSW.exe" [2005-08-23 15:38]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-30 12:50]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2007-04-25 17:44]
"Anti-Blaxx Manager"="C:\Program Files\Anti-Blaxx\Anti-Blaxx.exe" [2007-05-01 09:58]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 13:00]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2007-04-04 00:29]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:55]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2007-05-05 11:41]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=hex(2):43,3a,5c,57,49,4e,44,4f,57,53,5c,52,65,73,6f,75,72,\
63,65,73,5c,54,68,65,6d,65,73,5c,52,6f,79,61,6c,65,5c,52,6f,79,61,6c,65,2e,\
6d,73,73,74,79,6c,65,73,00
"InstallTheme"=hex(2):43,3a,5c,57,49,4e,44,4f,57,53,5c,52,65,73,6f,75,72,63,65,\
73,5c,54,68,65,6d,65,73,5c,52,6f,79,61,6c,65,2e,74,68,65,6d,65,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages msv1_0
Security Packages kerberos msv1_0 schannel wdigest
Notification Packages scecli
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HTTPFilter HTTPFilter
LocalService Alerter WebClient LmHosts RemoteRegistry upnphost SSDPSRV
NetworkService DnsCache
DcomLaunch DcomLaunch TermService
rpcss RpcSs
imgsvc StiSvc
termsvcs TermService
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs*
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\J]
Shell\AutoRun\command J:\LaunchU3.exe
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a50c2d39-0472-11dc-8416-0048546b0177}]
Shell\AutoRun\command J:\LaunchU3.exe
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Scheduled scanning task.job
********************************************************************
catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-05-17 18:31:15
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
********************************************************************
Completion time: 2007-05-17 18:33:22 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-05-17 18:33
--- E O F ---