((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\wl.exe
((((((((((((((((((((((((( Files Created from 2007-06-21 to 2007-07-21 )))))))))))))))))))))))))))))))
2007-07-20 20:05 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-07-20 17:53 <DIR> d-------- C:\Program Files\RivaTuner v2.02
2007-07-19 22:22 60,416 --a------ C:\WINDOWS\ALCFDRTM.EXE
2007-07-19 22:22 <DIR> d-------- C:\WINDOWS\system32\Lang
2007-07-19 22:17 <DIR> d-------- C:\Program Files\Realtek AC97
2007-07-19 20:07 <DIR> d-------- C:\Program Files\Setup Files
2007-07-19 19:52 45,056 --a------ C:\WINDOWS\system32\SUSBKey.dll
2007-07-19 19:52 45,056 --a------ C:\WINDOWS\system32\ginamsi.dll
2007-07-19 19:51 53,248 --a------ C:\WINDOWS\nvgpio.dll
2007-07-19 19:51 499,712 --a------ C:\WINDOWS\msvcp71.dll
2007-07-19 19:51 45,056 --a------ C:\WINDOWS\NTuneGpu.dll
2007-07-19 19:51 380,928 --a------ C:\WINDOWS\nvsulib.dll
2007-07-19 19:51 348,160 --a------ C:\WINDOWS\msvcr71.dll
2007-07-19 19:51 11,264 --a------ C:\WINDOWS\nvoclk64.sys
2007-07-19 19:51 1,060,864 --a------ C:\WINDOWS\MFC71.dll
2007-07-19 19:49 8,704 --a------ C:\WINDOWS\system32\drivers\FlashSys.sys
2007-07-19 19:49 18,359 --a------ C:\WINDOWS\system32\Ntaccess.sys
2007-07-19 19:49 <DIR> d-------- C:\Program Files\MSI
2007-07-14 11:03 <DIR> d-------- C:\Program Files\NVIDIA Corporation
2007-07-12 22:04 <DIR> d-------- C:\VundoFix Backups
2007-07-12 03:22 81,920 --a--c--- C:\WINDOWS\system32\frapsvid.dll
2007-07-10 20:20 <DIR> d-------- C:\DOCUME~1\Owner\WINDOWS
2007-07-07 10:58 <DIR> d-------- C:\Alien Arena 2007
2007-07-06 21:21 <DIR> d-------- C:\Program Files\Flock
2007-07-06 21:21 <DIR> d-------- C:\DOCUME~1\Owner\APPLIC~1\Flock
2007-07-06 20:22 3,968 --a------ C:\WINDOWS\system32\drivers\AvgArCln.sys
2007-07-03 12:33 6,784 --a------ C:\WINDOWS\nvoclock.sys
2007-07-03 12:32 352,256 --a------ C:\WINDOWS\ntuneoem.dll
2007-07-03 12:32 172,032 --a------ C:\WINDOWS\NVBenchMarks.dll
2007-07-03 12:31 57,344 --a------ C:\WINDOWS\AutoTuneScript.dll
2007-06-29 18:17 83,552 --a------ C:\WINDOWS\system32\LMIRfsClientNP.dll
2007-06-29 18:17 46,112 --a------ C:\WINDOWS\system32\drivers\LMIRfsDriver.sys
2007-06-27 19:23 <DIR> d-------- C:\Program Files\MagicISO
2007-06-25 22:21 1,073,152 --a------ C:\WINDOWS\system32\nvCplUIR.dll
2007-06-25 22:20 753,664 --a------ C:\WINDOWS\system32\nvCplUI.exe
2007-06-25 22:20 307,200 --a------ C:\WINDOWS\system32\nvExpBar.dll
2007-06-23 18:09 90,112 --a------ C:\WINDOWS\unvise32.exe
2007-06-23 18:09 <DIR> d-------- C:\Program Files\NGONVOD215822
2007-06-23 17:41 4,224 --a------ C:\WINDOWS\system32\drivers\NVStrap.sys
2007-06-23 16:45 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\nView_Profiles
2007-06-23 16:42 <DIR> d-------- C:\WINDOWS\nview
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-07-20 22:34:38 -------- d-----w C:\DOCUME~1\Owner\APPLIC~1\Smart Recorder
2007-07-20 10:52:01 -------- d-----w C:\Program Files\LogMeIn
2007-07-20 02:18:14 -------- d--h--w C:\Program Files\InstallShield Installation Information
2007-07-20 02:06:26 86,016 ----a-w C:\WINDOWS\system32\OpenAL32.dll
2007-07-20 02:06:26 413,696 ----a-w C:\WINDOWS\system32\wrap_oal.dll
2007-07-13 01:14:31 -------- d-----w C:\Program Files\SpywareBlaster
2007-07-13 01:08:04 -------- d-----w C:\Program Files\SpywareGuard
2007-07-11 22:58:20 -------- d-----w C:\DOCUME~1\Owner\APPLIC~1\Azureus
2007-07-11 22:41:46 -------- d-----w C:\Program Files\Common Files\Autodesk Shared
2007-07-07 15:49:35 -------- d-----w C:\Program Files\Trillian
2007-07-07 02:59:27 -------- d-----w C:\Program Files\HLSW
2007-06-24 19:36:27 -------- d-----w C:\Program Files\Microsoft Works
2007-06-23 14:27:24 -------- d-----w C:\Program Files\Google
2007-06-23 14:19:33 -------- d-----w C:\Program Files\OpenOffice.org 2.0
2007-06-16 21:51:38 -------- d-----w C:\DOCUME~1\Owner\APPLIC~1\OpenOffice.org2
2007-06-16 21:37:49 -------- d-----w C:\Program Files\Common Files\L&H
2007-06-16 21:37:37 -------- d-----w C:\Program Files\Microsoft ActiveSync
2007-06-16 21:36:46 -------- d-----w C:\Program Files\Microsoft.NET
2007-06-13 23:17:31 509,984 ----a-w C:\HTGD0006.exe
2007-06-13 23:17:31 40,960 ----a-w C:\HTGD0003.exe
2007-06-13 23:17:31 36,864 ----a-w C:\HTGD0005.exe
2007-06-05 23:24:03 -------- d-----w C:\Program Files\Common Files\Ahead
2007-06-05 23:22:34 -------- d-----w C:\Program Files\Nero
2007-06-04 23:46:50 -------- d-----w C:\Program Files\BitTorrent
2007-06-04 23:46:50 -------- d-----w C:\DOCUME~1\Owner\APPLIC~1\BitTorrent
2007-06-04 23:46:25 -------- d-----w C:\Program Files\Ventrilo
2007-06-04 23:46:25 -------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-06-04 23:46:21 -------- d-----w C:\Program Files\Windows Installer Clean Up
2007-06-04 23:46:20 -------- d-----w C:\Program Files\Ventrilo(2)
2007-06-04 23:20:03 -------- d-----w C:\Program Files\MSECACHE
2007-06-03 13:35:07 -------- d-----w C:\Program Files\Torbutton
2007-06-02 12:49:33 -------- d-----w C:\Program Files\FLAC
2007-05-25 23:10:39 -------- d-----w C:\Program Files\DivX
2007-05-25 21:41:03 1,571,916 --sh--w C:\WINDOWS\system32\cdeeg.bak1
2007-05-25 21:40:56 285,273 ---ha-w C:\WINDOWS\system32\geedc.dll.vir
2007-05-25 19:22:10 26,176 ----a-w C:\WINDOWS\system32\LMIport.dll
2007-05-25 19:22:08 10,304 ----a-w C:\WINDOWS\system32\LMImirr2.dll
2007-05-25 19:22:06 24,000 ----a-w C:\WINDOWS\system32\LMImirr.dll
2007-05-25 19:22:04 63,040 ----a-w C:\WINDOWS\system32\LMIinit.dll
2007-05-24 22:33:49 4,734 -c--a-w C:\WINDOWS\mozver.dat
2007-05-24 19:42:04 -------- d-----w C:\Program Files\Kirby Alarm
2007-05-23 01:38:48 -------- d-----w C:\Program Files\PowerISO
2007-05-16 15:12:02 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-05-16 13:42:22 972,336 ----a-w C:\WINDOWS\UNNeroMediaHome.exe
2007-05-15 19:56:06 239,152 ----a-w C:\WINDOWS\NuNInst.exe
2007-05-15 13:45:14 972,336 ----a-w C:\WINDOWS\UNNeroVision.exe
2007-05-11 19:23:36 204,800 ----a-w C:\WINDOWS\system32\g0.exe
2007-05-11 19:23:36 107,008 ----a-w C:\WINDOWS\system32\IDes.exe
2007-05-11 17:54:15 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2007-05-11 04:37:15 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2007-05-11 04:37:15 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2007-05-11 04:37:15 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2007-05-11 04:37:15 740,442 ----a-w C:\WINDOWS\system32\DivX.dll
2007-04-25 14:21:15 144,896 ----a-w C:\WINDOWS\system32\schannel.dll
2007-04-23 20:42:50 972,336 ----a-w C:\WINDOWS\UNRecode.exe
2007-04-23 00:15:29 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2007-04-23 00:15:24 129,784 ------w C:\WINDOWS\system32\pxafs.dll
2007-04-23 00:15:24 118,520 -c----w C:\WINDOWS\system32\pxinsi64.exe
2007-04-23 00:15:24 116,472 -c----w C:\WINDOWS\system32\pxcpyi64.exe
2007-04-23 00:15:18 200,704 -c--a-w C:\WINDOWS\system32\ssldivx.dll
2007-04-23 00:15:18 1,044,480 -c--a-w C:\WINDOWS\system32\libdivx.dll
2007-04-23 00:02:34 73,728 -c--a-w C:\WINDOWS\system32\dpl100.dll
2007-04-23 00:02:34 196,608 -c--a-w C:\WINDOWS\system32\dtu100.dll
2007-04-23 00:02:33 53,248 -c--a-w C:\WINDOWS\system32\dpuGUI10.dll
2007-04-23 00:02:31 593,920 -c--a-w C:\WINDOWS\system32\dpuGUI11.dll
2007-04-23 00:02:31 57,344 -c--a-w C:\WINDOWS\system32\dpv11.dll
2007-04-23 00:02:31 344,064 -c--a-w C:\WINDOWS\system32\dpus11.dll
2007-04-23 00:02:31 294,912 -c--a-w C:\WINDOWS\system32\dpu11.dll
2007-04-23 00:02:31 294,912 -c--a-w C:\WINDOWS\system32\dpu10.dll
2007-04-23 00:01:47 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2007-04-23 00:01:46 124,472 ----a-w C:\WINDOWS\system32\DivXCodecUpdateChecker.exe
2007-04-21 22:19:03 77,824 ----a-w C:\WINDOWS\system32\bzip2.exe
2007-04-21 21:48:59 1,406,135 --sh--w C:\WINDOWS\system32\rtstv.bak2
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}]
2006-10-26 11:28 440384 --------- C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
2006-10-22 23:08 62080 --a------ C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4A368E80-174F-4872-96B5-0B27DDD11DB2}]
2003-08-02 23:24 192512 -ra------ C:\Program Files\SpywareGuard\dlprotect.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
2005-05-31 01:04 853672 --a------ C:\PROGRA~1\SPYBOT~1\SDHelper.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}]
2006-10-31 16:29 198136 --------- C:\Program Files\Yahoo!\Common\yiesrvc.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
2007-03-14 03:43 501400 --a--c--- C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
2007-05-10 22:47 321120 --a------ C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AudioDrvEmulator"="C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" [2005-06-16 18:25]
"CTHelper"="CTHELPER.EXE" [2006-08-17 12:32 C:\WINDOWS\CTHELPER.EXE]
"CTxfiHlp"="CTXFIHLP.EXE" [2006-08-17 12:32 C:\WINDOWS\system32\CTXFIHLP.EXE]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2007-04-20 19:07]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-01-23 16:44 C:\WINDOWS\KHALMNPR.Exe]
"NVMixerTray"="C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" []
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-01-23 16:44 C:\WINDOWS\KHALMNPR.Exe]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 15:57]
"SecurDisc"="C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe" [2007-05-15 15:55]
"InCD"="C:\Program Files\Nero\Nero 7\InCD\InCD.exe" [2007-05-15 15:55]
"nwiz"="nwiz.exe" [2007-04-20 06:05 C:\WINDOWS\system32\nwiz.exe]
"RivaTuner"="C:\Program Files\RivaTuner v2.02\RivaTuner.exe" [2007-07-01 15:20]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-05-16 09:27]
"NVIDIA nTune"="C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-07-03 12:32]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2006-09-28 10:13]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
LMIinit.dll --a------ 2007-05-25 15:22 63040 C:\WINDOWS\system32\LMIinit.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\WdfLoadGroup]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\I]
AutoRun\command- I:\autoplay.exe
**************************************************************************
catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-20 20:08:56
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-07-20 20:09:26
C:\ComboFix-quarantined-files.txt ... 2007-07-20 20:09
--- E O F ---
My mainboard shorted, then I rebuilt my computer, between then and now I ran a virtuomonde removal tool, so maybe that fixed it, I don't know.