"ARROWS" - 2007-07-09 2:31:32 - ComboFix 07-07-07.3 - Service Pack 2
((((((((((((((((((((((((( Files Created from 2007-06-08 to 2007-07-08 )))))))))))))))))))))))))))))))
2007-07-08 18:28 <DIR> d-------- C:\Program Files\Trend Micro
2007-07-08 18:01 76,560 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2007-07-08 18:00 <DIR> d-------- C:\DOCUME~1\ARROWS\.housecall6.6
2007-07-08 17:13 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-07-08 16:59 <DIR> d-------- C:\Program Files\Enigma Software Group
2007-07-08 15:18 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com
2007-07-08 03:37 <DIR> d-------- C:\VundoFix Backups
2007-07-08 00:24 50,708 --a------ C:\WINDOWS\system32\scpysbih.exe
2007-07-07 21:50 50,708 --a------ C:\WINDOWS\system32\ptoajint.exe
2007-07-07 19:56 <DIR> d--hs---- C:\WINDOWS\system32\Sys32
2007-07-05 17:29 630,200 --a------ C:\WINDOWS\system32\drivers\vetefile.sys
2007-07-05 17:29 108,392 --a------ C:\WINDOWS\system32\drivers\veteboot.sys
2007-07-01 19:45 <DIR> d-------- C:\DOCUME~1\MARIE\OngameNetwork
2007-06-21 06:38 93,128 --a------ C:\WINDOWS\system32\ElbyCDIO.dll
2007-06-15 12:38 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\SlySoft
2007-06-15 12:36 34,308 --a------ C:\WINDOWS\system32\Chip.dll
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-07-08 06:29:57 -------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-07-07 18:39:30 -------- d-----w C:\Program Files\SlySoft
2007-07-07 16:57:28 -------- d-----w C:\DOCUME~1\ARROWS\APPLIC~1\Lavasoft
2007-07-07 16:57:07 -------- d-----w C:\Program Files\Lavasoft
2007-07-07 13:26:50 -------- d-----w C:\DOCUME~1\ARROWS\APPLIC~1\Azureus
2007-07-07 09:54:32 -------- d-----w C:\DOCUME~1\ARROWS\APPLIC~1\Canon
2007-07-01 08:03:48 -------- d-----w C:\Program Files\Winamp
2007-05-30 22:54:43 -------- d-----w C:\Program Files\Xvid
2007-05-30 09:45:05 -------- d-----w C:\Program Files\Allok Video Joiner
2007-05-30 09:19:56 -------- d-----w C:\Program Files\AVIJOINER
2007-05-10 07:58:18 -------- d-----w C:\DOCUME~1\ARROWS\APPLIC~1\uTorrent
2007-05-10 07:54:41 -------- d-----w C:\Program Files\uTorrent
2007-05-03 04:31:00 75,280 ----a-w C:\WINDOWS\system32\isafprod.dll
2007-05-03 04:30:59 99,904 ----a-w C:\WINDOWS\system32\isafeif.dll
2007-05-03 04:30:59 79,424 ----a-w C:\WINDOWS\system32\vetredir.dll
2007-04-16 13:17:36 33,624 ----a-w C:\WINDOWS\system32\wups.dll
2007-04-16 13:15:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-16 13:15:48 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-04-16 13:15:42 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-04-16 13:15:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-04-16 13:15:20 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-16 13:15:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
2007-04-16 13:13:44 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-04-16 13:13:40 208,248 ----a-w C:\WINDOWS\system32\muweb.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
2005-05-31 00:04 853672 --a------ C:\PROGRA~1\SPYBOT~1\SDHelper.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
2007-03-14 03:43 501400 --a------ C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
2007-01-19 22:55 2403392 -ra------ c:\program files\google\googletoolbar4.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2002-09-11 12:27 C:\WINDOWS\SOUNDMAN.EXE]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2003-12-08 17:35]
"LVCOMS"="C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE" [2003-06-27 10:09]
"LogitechImageStudioTray"="C:\Program Files\Logitech\ImageStudio\LogiTray.exe" [2003-07-03 10:36]
"LogitechGalleryRepair"="C:\Program Files\Logitech\ImageStudio\ISStart.exe" [2003-07-03 10:37]
"LiveMonitor"="C:\Program Files\MSI\Live Update 3\LMonitor.exe" []
"CloneCDTray"="C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" [2006-09-29 04:51]
"CAVRID"="C:\Program Files\CA\eTrust Vet Antivirus\CAVRID.exe" [2007-05-03 14:00]
"cctray"="C:\Program Files\CA\eTrust Internet Security Suite\cctray\cctray.exe" [2007-03-13 14:58]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 15:40]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2007-05-15 07:52]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 11:54]
"LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe" [2006-07-18 16:12]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56]
"AnyDVD"="C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe" [2007-07-08 04:10]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoClose"=0 (0x0)
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - netsvcs
NtmlSvc
*Newly Created Service* - CATCHME
*Newly Created Service* - TMCOMM
**************************************************************************
catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-07-09 02:34:02
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0