"Tenkai" - 2007-05-31 18:02:45 Service Pack 2 [SAFE MODE]
ComboFix 07-05.27.BV - Running from: "C:\Documents and Settings\Tenkai\Desktop\"
((((((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_NM
-------\LEGACY_NPF
-------\nm
((((((((((((((((((((((((((((((( Files Created from 2007-04-28 to 2007-05-31 ))))))))))))))))))))))))))))))))))
2007-05-31 15:09 <DIR> d-------- C:\Documents and Settings\Tenkai\DoctorWeb
2007-05-31 15:09 <DIR> d-------- C:\DOCUME~1\Tenkai\DoctorWeb
2007-05-31 13:57 66,560 --a------ C:\WINDOWS\system32\ewqdrhrjexj.exe
2007-05-29 19:12 <DIR> d-------- C:\DOCUME~1\LOCALS~1\APPLIC~1\Opera
2007-05-28 11:36 66,560 --a------ C:\WINDOWS\system32\ilohilwvh.exe
2007-05-27 16:05 66,560 --a------ C:\WINDOWS\system32\gxqfz.exe
2007-05-27 15:29 967 --a------ C:\WINDOWS\ScUnin.pif
2007-05-27 15:29 94,208 --a------ C:\WINDOWS\ScUnin.exe
2007-05-27 15:29 13,044 --a------ C:\WINDOWS\scunin.dat
2007-05-27 15:28 <DIR> d-------- C:\Program Files\Starcraft
2007-05-27 09:24 66,560 --a------ C:\WINDOWS\system32\wbgzozdlik.exe
2007-05-24 20:36 66,560 --a------ C:\WINDOWS\system32\wehaccsccle.exe
2007-05-24 20:31 66,560 --a------ C:\WINDOWS\system32\ajp.exe
2007-05-24 16:00 66,560 --a------ C:\WINDOWS\system32\xe.exe
2007-05-24 15:17 66,560 --a------ C:\WINDOWS\system32\euhpvjo.exe
2007-05-23 21:37 <DIR> d-------- C:\Silent Runners
2007-05-23 15:51 66,560 --a------ C:\WINDOWS\system32\gwxcmpkf.exe
2007-05-21 17:20 <DIR> d-------- C:\Program Files\Merriam-Webster
2007-05-19 10:34 <DIR> d-------- C:\Program Files\Common Files\Blizzard Entertainment
2007-05-19 10:31 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Azureus
2007-05-19 09:35 <DIR> d-------- C:\GMER
2007-05-11 19:10 <DIR> d-------- C:\HijackThis
2007-05-11 17:46 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
2007-05-11 17:43 620 --a------ C:\WINDOWS\unins001.dat
2007-05-11 00:34 655 --a------ C:\WINDOWS\unins000.dat
2007-05-10 23:19 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2007-05-08 19:34 443,752 --a------ C:\WINDOWS\system32\d3dx10_33.dll
2007-05-08 19:34 3,495,784 --a------ C:\WINDOWS\system32\d3dx9_33.dll
2007-05-08 19:34 261,480 --a------ C:\WINDOWS\system32\xactengine2_7.dll
2007-05-08 19:34 255,848 --a------ C:\WINDOWS\system32\xactengine2_6.dll
2007-05-08 19:34 1,123,696 --a------ C:\WINDOWS\system32\D3DCompiler_33.dll
2007-05-08 19:33 <DIR> d--h----- C:\WINDOWS\msdownld.tmp
2007-05-08 19:33 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-05-08 19:21 50,304 --a------ C:\WINDOWS\system32\drivers\AWRTRD.sys
2007-05-08 18:28 <DIR> d-------- C:\Program Files\Timeline Interactive
2007-05-08 13:32 9,472 --a------ C:\WINDOWS\system32\drivers\NSDriver.sys
2007-05-08 12:58 6,272 --a------ C:\WINDOWS\system32\drivers\AWRTPD.sys
2007-05-02 18:15 765,952 --a------ C:\WINDOWS\system32\xvidcore.dll
2007-05-02 18:15 654,848 --a------ C:\WINDOWS\system32\x264vfw.dll
2007-05-02 18:15 630,784 --a------ C:\WINDOWS\system32\vp7vfw.dll
2007-05-02 18:15 438,272 --a------ C:\WINDOWS\system32\vp6vfw.dll
2007-05-02 18:15 39,936 --a------ C:\WINDOWS\system32\huffyuv.dll
2007-05-02 18:15 217,088 --a------ C:\WINDOWS\system32\yv12vfw.dll
2007-05-02 18:15 217,088 --a------ C:\WINDOWS\system32\i420vfw.dll
2007-05-02 18:15 180,224 --a------ C:\WINDOWS\system32\xvidvfw.dll
2007-05-02 18:15 1,565,480 --a------ C:\WINDOWS\system32\wmv9vcm.dll
2007-05-02 18:14 73,728 --a------ C:\WINDOWS\system32\dpl100.dll
2007-05-02 18:14 639,066 --a------ C:\WINDOWS\system32\divx.dll
2007-05-02 18:14 3,596,288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2007-05-02 18:14 200,704 --a------ C:\WINDOWS\system32\ssldivx.dll
2007-05-02 18:14 196,608 --a------ C:\WINDOWS\system32\dtu100.dll
2007-05-02 18:14 10,752 --a------ C:\WINDOWS\system32\ff_vfw.dll
2007-05-02 18:14 1,044,480 --a------ C:\WINDOWS\system32\libdivx.dll
2007-05-02 18:14 <DIR> d-------- C:\Program Files\K-Lite Codec Pack
2007-05-02 18:14 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Real
2007-05-02 02:03 <DIR> d-------- C:\Program Files\NetBattle
2007-04-27 19:23 <DIR> d-------- C:\Program Files\SopCast
2007-04-27 19:23 <DIR> d-------- C:\DOCUME~1\Tenkai\APPLIC~1\SopCast
2007-04-24 19:23 <DIR> d-------- C:\DOCUME~1\Tenkai\APPLIC~1\TVU Networks
2007-04-13 15:19 7,680 --a------ C:\WINDOWS\system32\lsdelete.exe
2007-04-07 21:18 <DIR> d-------- C:\Converted Video
2007-04-05 21:01 <DIR> d-------- C:\Program Files\sMooVePoD
2007-04-05 20:38 1,168 --a------ C:\WINDOWS\mozver.dat
2007-04-04 15:25 <DIR> d-------- C:\DOCUME~1\HOMEAN~1\APPLIC~1\Apple Computer
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-05-31 19:48:30 179 ----a-w C:\handle.dat
2007-05-31 02:13:16 -------- d-----w C:\DOCUME~1\Tenkai\APPLIC~1\OpenOffice.org2
2007-05-29 23:05:24 -------- d-----w C:\Program Files\Zoom Player
2007-05-28 21:11:27 -------- d-----w C:\DOCUME~1\Tenkai\APPLIC~1\Image Zone Express
2007-05-27 19:38:33 -------- d-----w C:\Program Files\Opera 9
2007-05-27 03:43:35 -------- d-----w C:\DOCUME~1\Tenkai\APPLIC~1\Azureus
2007-05-27 01:17:47 -------- d-----w C:\DOCUME~1\Tenkai\APPLIC~1\LimeWire
2007-05-17 02:42:26 -------- d-----w C:\Program Files\Azureus
2007-05-11 22:46:48 -------- d-----w C:\Program Files\Lavasoft
2007-05-11 22:43:04 72,748 ----a-w C:\WINDOWS\unins001.exe
2007-05-11 21:49:02 -------- d-----w C:\Program Files\SpywareBlaster
2007-05-11 05:34:48 72,748 ----a-w C:\WINDOWS\unins000.exe
2007-05-04 04:25:54 -------- d-----w C:\DOCUME~1\Tenkai\APPLIC~1\Free Download Manager
2007-05-02 23:14:54 -------- d-----w C:\DOCUME~1\Tenkai\APPLIC~1\Apple Computer
2007-05-02 23:12:16 -------- d-----w C:\Program Files\Common Files\Real
2007-05-02 23:12:15 -------- d-----w C:\Program Files\Real
2007-05-02 23:12:03 -------- d-----w C:\DOCUME~1\Tenkai\APPLIC~1\Real
2007-05-02 23:11:39 -------- d--h--w C:\Program Files\InstallShield Installation Information
2007-05-02 23:11:31 -------- d-----w C:\Program Files\QuickTime
2007-04-28 14:54:05 -------- d-----w C:\Program Files\WarRock
2007-04-26 14:22:06 -------- d-----w C:\Program Files\THQ
2007-04-25 00:23:36 -------- d-----w C:\Program Files\TVUPlayer
2007-04-18 16:12:23 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll
2007-04-17 04:45:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-17 04:45:48 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-04-17 04:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-04-17 04:45:20 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-17 03:47:36 33,624 ----a-w C:\WINDOWS\system32\wups.dll
2007-04-17 03:45:42 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-04-17 03:45:36 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-04-17 03:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
2007-04-08 02:30:21 -------- d-----w C:\Program Files\DirectVobSub
2007-04-04 23:53:42 81,768 ----a-w C:\WINDOWS\system32\xinput1_3.dll
2007-03-31 22:25:32 -------- d-----w C:\DOCUME~1\Tenkai\APPLIC~1\pdf995
2007-03-31 19:05:15 -------- d-----w C:\Program Files\TaxCut06
2007-03-31 19:03:41 51,716 ----a-w C:\WINDOWS\system32\pdf995mon.dll
2007-03-31 19:03:41 118,784 ----a-w C:\WINDOWS\system32\pdfmona.dll
2007-03-30 18:12:26 108,144 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2007-03-29 02:52:25 -------- d-----w C:\DOCUME~1\Tenkai\APPLIC~1\Lavasoft
2007-03-28 23:53:54 -------- d-----w C:\DOCUME~1\Tenkai\APPLIC~1\Ableton
2007-03-28 23:52:02 -------- d-----w C:\Program Files\Image-Line
2007-03-28 23:42:04 -------- d-----w C:\Program Files\OpenOffice.org 2.2
2007-03-28 23:41:18 -------- d-----w C:\Program Files\OpenOffice.org 2.1
2007-03-17 13:43:01 292,864 ----a-w C:\WINDOWS\system32\winsrv.dll
2007-03-08 15:36:28 577,536 ----a-w C:\WINDOWS\system32\user32.dll
2007-03-08 15:36:28 40,960 ------w C:\WINDOWS\system32\mf3216.dll
2007-03-08 15:36:28 281,600 ----a-w C:\WINDOWS\system32\gdi32.dll
2007-03-08 13:47:48 1,843,584 ----a-w C:\WINDOWS\system32\win32k.sys
2007-03-05 17:42:18 15,128 ----a-w C:\WINDOWS\system32\x3daudio1_1.dll
2006-09-30 21:19:33 22 --sha-w C:\WINDOWS\SMINST\HPCD.sys
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{53707962-6F74-2D53-2644-206D7942484F}=C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2005-05-31 01:04]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll [2007-03-14 03:43]
{AAAE832A-5FFF-4661-9C8F-369692D1DCB9}=C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\webhelper.dll [2006-05-30 12:20]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" []
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" []
"nwiz"="nwiz.exe" [2007-02-01 21:25 C:\WINDOWS\system32\nwiz.exe]
"DISCover"="C:\Program Files\DISC\DISCover.exe" [2006-03-16 04:12]
"DiscUpdateManager"="C:\Program Files\DISC\DiscUpdMgr.exe" [2006-03-16 04:11]
"DMAScheduler"="c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe" [2006-03-20 11:05]
"PCDrProfiler"="" []
"HPBootOp"="C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-16 00:34]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPwuSchd2.exe" [2005-12-15 20:18]
"SetDefPrt"="C:\Program Files\Brother\Brmfl04b\BrStDvPt.exe" [2004-05-25 09:16]
"ControlCenter2.0"="C:\Program Files\Brother\ControlCenter2\brctrcen.exe" [2004-07-20 09:34]
"LClock"="C:\Program Files\LClock\LClock.exe" [2004-09-20 02:27]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [2005-01-19 11:45]
"LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" [2005-01-19 11:39]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 16:40]
"KBD"="C:\HP\KBD\KBD.EXE" [2005-02-02 16:44]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-06-14 16:24]
"DiskeeperSystray"="C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe" [2006-10-04 12:38]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2006-12-17 19:57]
"COMODO Firewall Pro"="C:\Program Files\Comodo\Firewall\CPF.exe" [2007-02-10 20:34]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-09 23:00]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" []
"Aim6"="" []
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"RunNarrator"=Narrator.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsMenu"=1 (0x1)
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\WebrootSpySweeperService]
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs*
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
AutoRun\command- E:\SETUP.EXE
********************************************************************
catchme 0.3.692 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-05-31 18:10:05
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
********************************************************************
Completion time: 2007-05-31 18:12:26 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-05-31 18:12
--- E O F ---
ComboFix 07-05.27.BV - Running from: "C:\Documents and Settings\Tenkai\Desktop\"
((((((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_NM
-------\LEGACY_NPF
-------\nm
((((((((((((((((((((((((((((((( Files Created from 2007-04-28 to 2007-05-31 ))))))))))))))))))))))))))))))))))
2007-05-31 15:09 <DIR> d-------- C:\Documents and Settings\Tenkai\DoctorWeb
2007-05-31 15:09 <DIR> d-------- C:\DOCUME~1\Tenkai\DoctorWeb
2007-05-31 13:57 66,560 --a------ C:\WINDOWS\system32\ewqdrhrjexj.exe
2007-05-29 19:12 <DIR> d-------- C:\DOCUME~1\LOCALS~1\APPLIC~1\Opera
2007-05-28 11:36 66,560 --a------ C:\WINDOWS\system32\ilohilwvh.exe
2007-05-27 16:05 66,560 --a------ C:\WINDOWS\system32\gxqfz.exe
2007-05-27 15:29 967 --a------ C:\WINDOWS\ScUnin.pif
2007-05-27 15:29 94,208 --a------ C:\WINDOWS\ScUnin.exe
2007-05-27 15:29 13,044 --a------ C:\WINDOWS\scunin.dat
2007-05-27 15:28 <DIR> d-------- C:\Program Files\Starcraft
2007-05-27 09:24 66,560 --a------ C:\WINDOWS\system32\wbgzozdlik.exe
2007-05-24 20:36 66,560 --a------ C:\WINDOWS\system32\wehaccsccle.exe
2007-05-24 20:31 66,560 --a------ C:\WINDOWS\system32\ajp.exe
2007-05-24 16:00 66,560 --a------ C:\WINDOWS\system32\xe.exe
2007-05-24 15:17 66,560 --a------ C:\WINDOWS\system32\euhpvjo.exe
2007-05-23 21:37 <DIR> d-------- C:\Silent Runners
2007-05-23 15:51 66,560 --a------ C:\WINDOWS\system32\gwxcmpkf.exe
2007-05-21 17:20 <DIR> d-------- C:\Program Files\Merriam-Webster
2007-05-19 10:34 <DIR> d-------- C:\Program Files\Common Files\Blizzard Entertainment
2007-05-19 10:31 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Azureus
2007-05-19 09:35 <DIR> d-------- C:\GMER
2007-05-11 19:10 <DIR> d-------- C:\HijackThis
2007-05-11 17:46 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
2007-05-11 17:43 620 --a------ C:\WINDOWS\unins001.dat
2007-05-11 00:34 655 --a------ C:\WINDOWS\unins000.dat
2007-05-10 23:19 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2007-05-08 19:34 443,752 --a------ C:\WINDOWS\system32\d3dx10_33.dll
2007-05-08 19:34 3,495,784 --a------ C:\WINDOWS\system32\d3dx9_33.dll
2007-05-08 19:34 261,480 --a------ C:\WINDOWS\system32\xactengine2_7.dll
2007-05-08 19:34 255,848 --a------ C:\WINDOWS\system32\xactengine2_6.dll
2007-05-08 19:34 1,123,696 --a------ C:\WINDOWS\system32\D3DCompiler_33.dll
2007-05-08 19:33 <DIR> d--h----- C:\WINDOWS\msdownld.tmp
2007-05-08 19:33 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-05-08 19:21 50,304 --a------ C:\WINDOWS\system32\drivers\AWRTRD.sys
2007-05-08 18:28 <DIR> d-------- C:\Program Files\Timeline Interactive
2007-05-08 13:32 9,472 --a------ C:\WINDOWS\system32\drivers\NSDriver.sys
2007-05-08 12:58 6,272 --a------ C:\WINDOWS\system32\drivers\AWRTPD.sys
2007-05-02 18:15 765,952 --a------ C:\WINDOWS\system32\xvidcore.dll
2007-05-02 18:15 654,848 --a------ C:\WINDOWS\system32\x264vfw.dll
2007-05-02 18:15 630,784 --a------ C:\WINDOWS\system32\vp7vfw.dll
2007-05-02 18:15 438,272 --a------ C:\WINDOWS\system32\vp6vfw.dll
2007-05-02 18:15 39,936 --a------ C:\WINDOWS\system32\huffyuv.dll
2007-05-02 18:15 217,088 --a------ C:\WINDOWS\system32\yv12vfw.dll
2007-05-02 18:15 217,088 --a------ C:\WINDOWS\system32\i420vfw.dll
2007-05-02 18:15 180,224 --a------ C:\WINDOWS\system32\xvidvfw.dll
2007-05-02 18:15 1,565,480 --a------ C:\WINDOWS\system32\wmv9vcm.dll
2007-05-02 18:14 73,728 --a------ C:\WINDOWS\system32\dpl100.dll
2007-05-02 18:14 639,066 --a------ C:\WINDOWS\system32\divx.dll
2007-05-02 18:14 3,596,288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2007-05-02 18:14 200,704 --a------ C:\WINDOWS\system32\ssldivx.dll
2007-05-02 18:14 196,608 --a------ C:\WINDOWS\system32\dtu100.dll
2007-05-02 18:14 10,752 --a------ C:\WINDOWS\system32\ff_vfw.dll
2007-05-02 18:14 1,044,480 --a------ C:\WINDOWS\system32\libdivx.dll
2007-05-02 18:14 <DIR> d-------- C:\Program Files\K-Lite Codec Pack
2007-05-02 18:14 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Real
2007-05-02 02:03 <DIR> d-------- C:\Program Files\NetBattle
2007-04-27 19:23 <DIR> d-------- C:\Program Files\SopCast
2007-04-27 19:23 <DIR> d-------- C:\DOCUME~1\Tenkai\APPLIC~1\SopCast
2007-04-24 19:23 <DIR> d-------- C:\DOCUME~1\Tenkai\APPLIC~1\TVU Networks
2007-04-13 15:19 7,680 --a------ C:\WINDOWS\system32\lsdelete.exe
2007-04-07 21:18 <DIR> d-------- C:\Converted Video
2007-04-05 21:01 <DIR> d-------- C:\Program Files\sMooVePoD
2007-04-05 20:38 1,168 --a------ C:\WINDOWS\mozver.dat
2007-04-04 15:25 <DIR> d-------- C:\DOCUME~1\HOMEAN~1\APPLIC~1\Apple Computer
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-05-31 19:48:30 179 ----a-w C:\handle.dat
2007-05-31 02:13:16 -------- d-----w C:\DOCUME~1\Tenkai\APPLIC~1\OpenOffice.org2
2007-05-29 23:05:24 -------- d-----w C:\Program Files\Zoom Player
2007-05-28 21:11:27 -------- d-----w C:\DOCUME~1\Tenkai\APPLIC~1\Image Zone Express
2007-05-27 19:38:33 -------- d-----w C:\Program Files\Opera 9
2007-05-27 03:43:35 -------- d-----w C:\DOCUME~1\Tenkai\APPLIC~1\Azureus
2007-05-27 01:17:47 -------- d-----w C:\DOCUME~1\Tenkai\APPLIC~1\LimeWire
2007-05-17 02:42:26 -------- d-----w C:\Program Files\Azureus
2007-05-11 22:46:48 -------- d-----w C:\Program Files\Lavasoft
2007-05-11 22:43:04 72,748 ----a-w C:\WINDOWS\unins001.exe
2007-05-11 21:49:02 -------- d-----w C:\Program Files\SpywareBlaster
2007-05-11 05:34:48 72,748 ----a-w C:\WINDOWS\unins000.exe
2007-05-04 04:25:54 -------- d-----w C:\DOCUME~1\Tenkai\APPLIC~1\Free Download Manager
2007-05-02 23:14:54 -------- d-----w C:\DOCUME~1\Tenkai\APPLIC~1\Apple Computer
2007-05-02 23:12:16 -------- d-----w C:\Program Files\Common Files\Real
2007-05-02 23:12:15 -------- d-----w C:\Program Files\Real
2007-05-02 23:12:03 -------- d-----w C:\DOCUME~1\Tenkai\APPLIC~1\Real
2007-05-02 23:11:39 -------- d--h--w C:\Program Files\InstallShield Installation Information
2007-05-02 23:11:31 -------- d-----w C:\Program Files\QuickTime
2007-04-28 14:54:05 -------- d-----w C:\Program Files\WarRock
2007-04-26 14:22:06 -------- d-----w C:\Program Files\THQ
2007-04-25 00:23:36 -------- d-----w C:\Program Files\TVUPlayer
2007-04-18 16:12:23 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll
2007-04-17 04:45:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-17 04:45:48 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-04-17 04:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-04-17 04:45:20 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-17 03:47:36 33,624 ----a-w C:\WINDOWS\system32\wups.dll
2007-04-17 03:45:42 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-04-17 03:45:36 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-04-17 03:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
2007-04-08 02:30:21 -------- d-----w C:\Program Files\DirectVobSub
2007-04-04 23:53:42 81,768 ----a-w C:\WINDOWS\system32\xinput1_3.dll
2007-03-31 22:25:32 -------- d-----w C:\DOCUME~1\Tenkai\APPLIC~1\pdf995
2007-03-31 19:05:15 -------- d-----w C:\Program Files\TaxCut06
2007-03-31 19:03:41 51,716 ----a-w C:\WINDOWS\system32\pdf995mon.dll
2007-03-31 19:03:41 118,784 ----a-w C:\WINDOWS\system32\pdfmona.dll
2007-03-30 18:12:26 108,144 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2007-03-29 02:52:25 -------- d-----w C:\DOCUME~1\Tenkai\APPLIC~1\Lavasoft
2007-03-28 23:53:54 -------- d-----w C:\DOCUME~1\Tenkai\APPLIC~1\Ableton
2007-03-28 23:52:02 -------- d-----w C:\Program Files\Image-Line
2007-03-28 23:42:04 -------- d-----w C:\Program Files\OpenOffice.org 2.2
2007-03-28 23:41:18 -------- d-----w C:\Program Files\OpenOffice.org 2.1
2007-03-17 13:43:01 292,864 ----a-w C:\WINDOWS\system32\winsrv.dll
2007-03-08 15:36:28 577,536 ----a-w C:\WINDOWS\system32\user32.dll
2007-03-08 15:36:28 40,960 ------w C:\WINDOWS\system32\mf3216.dll
2007-03-08 15:36:28 281,600 ----a-w C:\WINDOWS\system32\gdi32.dll
2007-03-08 13:47:48 1,843,584 ----a-w C:\WINDOWS\system32\win32k.sys
2007-03-05 17:42:18 15,128 ----a-w C:\WINDOWS\system32\x3daudio1_1.dll
2006-09-30 21:19:33 22 --sha-w C:\WINDOWS\SMINST\HPCD.sys
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{53707962-6F74-2D53-2644-206D7942484F}=C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2005-05-31 01:04]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll [2007-03-14 03:43]
{AAAE832A-5FFF-4661-9C8F-369692D1DCB9}=C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\webhelper.dll [2006-05-30 12:20]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" []
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" []
"nwiz"="nwiz.exe" [2007-02-01 21:25 C:\WINDOWS\system32\nwiz.exe]
"DISCover"="C:\Program Files\DISC\DISCover.exe" [2006-03-16 04:12]
"DiscUpdateManager"="C:\Program Files\DISC\DiscUpdMgr.exe" [2006-03-16 04:11]
"DMAScheduler"="c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe" [2006-03-20 11:05]
"PCDrProfiler"="" []
"HPBootOp"="C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-16 00:34]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPwuSchd2.exe" [2005-12-15 20:18]
"SetDefPrt"="C:\Program Files\Brother\Brmfl04b\BrStDvPt.exe" [2004-05-25 09:16]
"ControlCenter2.0"="C:\Program Files\Brother\ControlCenter2\brctrcen.exe" [2004-07-20 09:34]
"LClock"="C:\Program Files\LClock\LClock.exe" [2004-09-20 02:27]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [2005-01-19 11:45]
"LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" [2005-01-19 11:39]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 16:40]
"KBD"="C:\HP\KBD\KBD.EXE" [2005-02-02 16:44]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-06-14 16:24]
"DiskeeperSystray"="C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe" [2006-10-04 12:38]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2006-12-17 19:57]
"COMODO Firewall Pro"="C:\Program Files\Comodo\Firewall\CPF.exe" [2007-02-10 20:34]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-09 23:00]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" []
"Aim6"="" []
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"RunNarrator"=Narrator.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsMenu"=1 (0x1)
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\WebrootSpySweeperService]
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs*
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
AutoRun\command- E:\SETUP.EXE
********************************************************************
catchme 0.3.692 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-05-31 18:10:05
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
********************************************************************
Completion time: 2007-05-31 18:12:26 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-05-31 18:12
--- E O F ---