fresh log
"Andrew" - 2007-07-19 12:50:21 - ComboFix 07-07-14.6 - Service Pack 2 NTFS
((((((((((((((((((((((((( Files Created from 2007-06-19 to 2007-07-19 )))))))))))))))))))))))))))))))
2007-07-18 21:53 <DIR> d-------- C:\DOCUME~1\Andrew\DoctorWeb
2007-07-18 21:49 <DIR> d-------- C:\Program Files\CCleaner
2007-07-17 23:25 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-07-17 21:28 94,480 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2007-07-17 21:27 <DIR> d-------- C:\DOCUME~1\Andrew\APPLIC~1\HouseCall 6.6
2007-07-04 13:35 <DIR> d-------- C:\DOCUME~1\Andrew\APPLIC~1\uTorrent
2007-07-04 00:44 <DIR> d-------- C:\DOCUME~1\Andrew\APPLIC~1\Azureus
2007-07-04 00:43 <DIR> d-------- C:\Program Files\Azureus
2007-07-01 13:53 <DIR> d--h----- C:\DOCUME~1\Andrew\APPLIC~1\ijjigame
2007-06-30 21:21 <DIR> d-------- C:\WINDOWS\system32\SoftwareDistribution
2007-06-30 20:58 <DIR> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-06-30 18:54 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2007-06-30 18:27 552 --a------ C:\WINDOWS\system32\d3d8caps.dat
2007-06-29 18:42 <DIR> d-------- C:\Program Files\Silkroad
2007-06-23 11:00 <DIR> d-------- C:\DOCUME~1\Andrew\APPLIC~1\DMCache
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-07-19 16:45:24 -------- d-----w C:\Program Files\Steam
2007-07-18 23:54:11 -------- d-----w C:\DOCUME~1\Andrew\APPLIC~1\Hamachi
2007-07-18 23:51:08 -------- d-----w C:\Program Files\Warcraft III
2007-07-18 05:33:37 -------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-07-18 05:32:39 -------- d-----w C:\Program Files\Symantec
2007-07-18 03:47:32 -------- d-----w C:\Program Files\Yahoo!
2007-07-18 03:47:31 -------- d-----w C:\Program Files\WIZET
2007-07-18 03:47:29 -------- d-----w C:\Program Files\Windows Media Connect 2
2007-07-18 03:47:21 -------- d-----w C:\Program Files\Winamp
2007-07-18 03:46:54 -------- d-----w C:\Program Files\WarRock
2007-07-18 03:46:48 -------- d-----w C:\Program Files\VstPlugins
2007-07-18 03:46:48 -------- d-----w C:\Program Files\Visual Subst
2007-07-18 03:46:48 -------- d-----w C:\Program Files\Ventrilo
2007-07-18 03:46:47 -------- d-----w C:\Program Files\USB(CIF) Camera
2007-07-18 03:46:47 -------- d-----w C:\Program Files\Teamspeak2_RC2
2007-07-18 03:46:09 -------- d-----w C:\Program Files\Stardock
2007-07-18 03:46:04 -------- d-----w C:\Program Files\Sony Ericsson
2007-07-18 03:45:07 -------- d-----w C:\Program Files\Scions of Fate
2007-07-18 03:45:07 -------- d-----w C:\Program Files\Samsung
2007-07-18 03:45:05 -------- d-----w C:\Program Files\Rogers
2007-07-18 03:44:51 -------- d-----w C:\Program Files\Real
2007-07-18 03:43:48 -------- d-----w C:\Program Files\QuickTime
2007-07-18 03:43:41 -------- d-----w C:\Program Files\PokerStars
2007-07-18 03:43:37 -------- d-----w C:\Program Files\PartyGaming
2007-07-18 03:43:37 -------- d-----w C:\Program Files\OpenSource Flash Video Splitter
2007-07-18 03:43:37 -------- d-----w C:\Program Files\Online Services
2007-07-18 03:43:36 -------- d-----w C:\Program Files\Norton AntiVirus
2007-07-18 03:43:32 -------- d-----w C:\Program Files\NewSoft
2007-07-18 03:43:25 -------- d-----w C:\Program Files\muvee Technologies
2007-07-18 03:43:25 -------- d-----w C:\Program Files\MSXML 4.0
2007-07-18 03:43:22 -------- d-----w C:\Program Files\MSN Messenger
2007-07-18 03:43:16 -------- d-----w C:\Program Files\Morpheus
2007-07-18 03:43:09 -------- d-----w C:\Program Files\Microsoft SQL Server
2007-07-18 03:43:03 -------- d-----w C:\Program Files\Microsoft ActiveSync
2007-07-18 03:41:46 -------- d-----w C:\Program Files\Logitech
2007-07-18 03:41:45 -------- d-----w C:\Program Files\LimeWire
2007-07-18 03:41:44 -------- d-----w C:\Program Files\Lavasoft
2007-07-18 03:41:44 -------- d-----w C:\Program Files\Lame MP3 Codec
2007-07-18 03:41:43 -------- d-----w C:\Program Files\K-Lite Codec Pack
2007-07-18 03:41:26 -------- d-----w C:\Program Files\iTunes
2007-07-18 03:41:23 -------- d-----w C:\Program Files\iPod
2007-07-18 03:41:22 -------- d-----w C:\Program Files\Intel
2007-07-18 03:40:06 -------- d-----w C:\Program Files\Image-Line
2007-07-18 03:39:59 -------- d-----w C:\Program Files\HP
2007-07-18 03:39:56 -------- d-----w C:\Program Files\Hasbro Interactive
2007-07-18 03:39:56 -------- d-----w C:\Program Files\Hamachi
2007-07-18 03:39:56 -------- d-----w C:\Program Files\Guild Wars
2007-07-18 03:39:53 -------- d-----w C:\Program Files\Game Cam v1.4
2007-07-18 03:39:53 -------- d-----w C:\Program Files\FLVSplitter
2007-07-18 03:39:51 -------- d-----w C:\Program Files\DivX
2007-07-18 03:39:48 -------- d-----w C:\Program Files\Disc2Phone
2007-07-18 03:39:48 -------- d-----w C:\Program Files\Dell
2007-07-18 03:39:47 -------- d-----w C:\Program Files\DatPiff
2007-07-18 03:39:45 -------- d-----w C:\Program Files\DAP
2007-07-18 03:39:25 -------- d-----w C:\Program Files\CyberLink DVD Solution
2007-07-18 03:39:24 -------- d-----w C:\Program Files\CyberLink
2007-07-18 03:39:23 -------- d--h--w C:\Program Files\Creative Installation Information
2007-07-18 03:39:18 -------- d-----w C:\Program Files\Creative
2007-07-18 03:39:17 -------- d-----w C:\Program Files\CIB
2007-07-18 03:39:17 -------- d-----w C:\Program Files\CamStudio
2007-07-18 03:39:15 -------- d-----w C:\Program Files\BitTorrent
2007-07-18 03:39:14 -------- d-----w C:\Program Files\BitComet
2007-07-18 03:39:13 -------- d-----w C:\Program Files\Audible
2007-07-18 03:39:06 -------- d-----w C:\Program Files\ATI Technologies
2007-07-18 03:39:05 -------- d-----w C:\Program Files\AsiaSoft
2007-07-18 03:38:53 -------- d-----w C:\Program Files\Ahead
2007-07-18 03:37:59 -------- d-----w C:\Program Files\Adaptec
2007-07-15 03:17:45 -------- d-----w C:\Program Files\Sony
2007-07-09 12:16:34 -------- d-----w C:\Program Files\Windows Live Safety Center
2007-06-20 04:12:04 77,824 ----a-w C:\WINDOWS\system32\kdfapi.dll
2007-06-20 04:12:04 53,248 ----a-w C:\WINDOWS\system32\Kdfhok.dll
2007-06-20 04:11:56 362,312 ----a-w C:\WINDOWS\system32\kdfmgr.exe
2007-06-20 04:01:36 479,744 ----a-w C:\WINDOWS\system32\kdfinj.dll
2007-06-13 19:50:17 43,152 ----a-w C:\WINDOWS\system32\drivers\ativvpxx.vp
2007-06-13 19:25:36 339,968 ----a-w C:\WINDOWS\system32\ATIDEMGX.dll
2007-06-13 19:24:32 268,288 ----a-w C:\WINDOWS\system32\ati2dvag.dll
2007-06-13 19:24:13 2,155,520 ----a-w C:\WINDOWS\system32\drivers\ati2mtag.sys
2007-06-13 19:23:23 307,200 ----a-w C:\WINDOWS\system32\atiiiexx.dll
2007-06-13 19:17:37 139,264 ----a-w C:\WINDOWS\system32\atipdlxx.dll
2007-06-13 19:17:26 118,784 ----a-w C:\WINDOWS\system32\Oemdspif.dll
2007-06-13 19:17:18 26,112 ----a-w C:\WINDOWS\system32\Ati2mdxx.exe
2007-06-13 19:17:12 42,496 ----a-w C:\WINDOWS\system32\ati2edxx.dll
2007-06-13 19:16:59 118,784 ----a-w C:\WINDOWS\system32\ati2evxx.dll
2007-06-13 19:15:39 483,328 ----a-w C:\WINDOWS\system32\ati2evxx.exe
2007-06-13 19:14:51 53,248 ----a-w C:\WINDOWS\system32\ATIDDC.DLL
2007-06-13 19:10:33 8,097,792 ----a-w C:\WINDOWS\system32\atioglx2.dll
2007-06-13 19:07:26 2,922,208 ----a-w C:\WINDOWS\system32\ati3duag.dll
2007-06-13 18:57:21 1,512,960 ----a-w C:\WINDOWS\system32\ativvaxx.dll
2007-06-13 18:57:04 972,072 ----a-w C:\WINDOWS\system32\ativva6x.dat
2007-06-13 18:57:04 3,107,788 ----a-w C:\WINDOWS\system32\ativvaxx.dat
2007-06-13 18:57:04 3,107,788 ----a-w C:\WINDOWS\system32\ativva5x.dat
2007-06-13 18:46:28 5,431,296 ----a-w C:\WINDOWS\system32\atioglxx.dll
2007-06-13 18:43:53 262,144 ----a-w C:\WINDOWS\system32\atikvmag.dll
2007-06-13 18:42:29 17,408 ----a-w C:\WINDOWS\system32\atitvo32.dll
2007-06-13 18:41:46 49,152 ----a-w C:\WINDOWS\system32\drivers\ati2erec.dll
2007-06-13 18:41:06 50,176 ----a-w C:\WINDOWS\system32\atiok3x2.dll
2007-06-13 18:36:45 368,640 ----a-w C:\WINDOWS\system32\ati2cqag.dll
2007-06-09 19:07:15 25,544 ----a-w C:\WINDOWS\system32\drivers\hamachi.sys
2007-06-07 15:31:26 65,536 --sh--r C:\WINDOWS\system32\WINLKEY.DLL
2007-06-07 15:31:04 698,880 --sh--r C:\WINDOWS\system32\winl.DLL
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
2001-04-16 17:39 37808 --a------ C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}]
2007-01-11 11:05 386624 --a------ C:\Program Files\BitComet\tools\BitCometBHO.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
2006-10-12 04:25 434279 --a------ C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2006-10-25 01:37]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-01-31 00:57]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe" [2006-10-12 04:10]
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2005-10-18 10:57]
"RemoteControl"="C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" [2003-12-08 17:35]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-12-08 18:03]
"LVCOMSX"="C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe" [2006-05-17 11:12]
"LogitechCommunicationsManager"="C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe" [2006-05-17 15:18]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2006-05-10 10:48 C:\WINDOWS\KHALMNPR.Exe]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-10-30 10:36]
"InCD"="C:\Program Files\Ahead\InCD\InCD.exe" [2004-09-07 09:25]
"diagent"="C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" [2002-04-03 01:01]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-04-26 09:49]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-05-10 12:12]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56]
"Update Manager"="C:\Program Files\Rogers\Update Manager\UpdateManager.exe" [2004-05-27 09:26]
"Steam"="C:\Program Files\Steam\Steam.exe" [2007-06-28 06:03]
"RHSI SHS"="C:\Program Files\Rogers\SelfHealing\SHS.exe" [2006-11-06 15:15]
"LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [2007-03-08 08:20]
"CTSyncU.exe"="C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe" [2006-04-28 18:08]
"PowerBar"="C:\Program Files\CyberLink DVD Solution\Multimedia Launcher\PowerBar.exe" [2004-04-21 10:26]
"RogersAgent"="c:\Program Files\Rogers\SelfHealing\rogersagent.exe" [2006-11-06 12:41]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\wbsrv.dll --a------ 2006-10-10 18:53 135168 C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\WbSrv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=wbsys.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Usnsvc usnsvc
Contents of the 'Scheduled Tasks' folder
2006-12-09 03:30:55 C:\WINDOWS\tasks\Symantec NetDetect.job
**************************************************************************
catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer,
http://www.gmer.netRootkit scan 2007-07-19 12:57:32
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-07-19 13:00:24
C:\ComboFix-quarantined-files.txt ... 2007-07-19 13:00
C:\ComboFix2.txt ... 2007-07-18 00:07
--- E O F ---