"Shane" - 2007-07-14 18:53:07 - ComboFix 07-07-13.8 - Service Pack 2
FAT32 ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\dat.txt
C:\WINDOWS\main_uninstaller.exe
C:\WINDOWS\msddx.dll
C:\WINDOWS\privacy_danger
C:\WINDOWS\privacy_danger\images\capt.gif
C:\WINDOWS\privacy_danger\images\danger.jpg
C:\WINDOWS\privacy_danger\images\down.gif
C:\WINDOWS\privacy_danger\images\spacer.gif
C:\WINDOWS\privacy_danger\index.htm
C:\WINDOWS\rs.txt
((((((((((((((((((((((((( Files Created from 2007-06-14 to 2007-07-14 )))))))))))))))))))))))))))))))
2007-07-14 18:51 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-07-14 01:24 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-07-14 00:10 <DIR> d-------- C:\Program Files\SPYWAREfighter
2007-07-14 00:10 <DIR> d-------- C:\Program Files\Common Files\Application
2007-07-13 23:44 <DIR> d-------- C:\DOCUME~1\Shane\APPLIC~1\SpywareBot
2007-07-13 23:19 <DIR> d-------- C:\Program Files\Enigma Software Group
2007-07-13 21:58 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2007-07-13 21:58 <DIR> d-------- C:\DOCUME~1\Shane\APPLIC~1\SUPERAntiSpyware.com
2007-07-13 21:58 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com
2007-07-13 21:57 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-07-10 13:10 <DIR> d-------- C:\WINDOWS\Profiles
2007-07-10 13:10 <DIR> d-------- C:\DOCUME~1\Shane\WINDOWS
2007-07-10 13:09 40,960 -ra------ C:\WINDOWS\system32\hpg4400.dll
2007-07-10 13:09 385,024 -ra------ C:\WINDOWS\system32\rts8891u.dll
2007-07-10 13:09 253,952 -ra------ C:\WINDOWS\system32\hpgtulbz.dll
2007-07-10 13:09 249,856 -ra------ C:\WINDOWS\system32\hpgud32.dll
2007-07-10 13:09 225,280 -ra------ C:\WINDOWS\system32\hpgtpusd.dll
2007-07-10 13:09 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2007-07-10 13:09 118,784 -ra------ C:\WINDOWS\system32\hpsjvset.dll
2007-07-10 13:09 106,496 -ra------ C:\WINDOWS\system32\hpguapi.dll
2007-07-10 13:08 <DIR> d-------- C:\DOCUME~1\Shane\APPLIC~1\Mappen Share-to-Web-overf›rsel
2007-07-09 13:39 5,504 --a------ C:\WINDOWS\system32\drivers\MSTEE.sys
2007-07-09 13:39 15,360 --a------ C:\WINDOWS\system32\drivers\StreamIP.sys
2007-07-09 13:39 15,360 --a------ C:\WINDOWS\system32\drivers\MPE.sys
2007-07-09 13:39 10,880 --a------ C:\WINDOWS\system32\drivers\NdisIP.sys
2007-07-09 13:38 85,376 --a------ C:\WINDOWS\system32\drivers\NABTSFEC.sys
2007-07-09 13:38 53,760 --a------ C:\WINDOWS\system32\vfwwdm32.dll
2007-07-09 13:38 19,328 --a------ C:\WINDOWS\system32\drivers\WSTCODEC.SYS
2007-07-09 13:38 17,024 --a------ C:\WINDOWS\system32\drivers\CCDECODE.sys
2007-07-09 13:38 11,776 --a------ C:\WINDOWS\system32\drivers\BdaSup.sys
2007-07-09 13:38 11,136 --a------ C:\WINDOWS\system32\drivers\SLIP.sys
2007-07-06 19:22 <DIR> d-------- C:\DOCUME~1\Shane\Contacts
2007-07-06 19:21 <DIR> d-------- C:\WINDOWS\system32\DRVSTORE
2007-07-06 19:20 <DIR> d-------- C:\Program Files\MSN Messenger
2007-06-29 05:21 <DIR> d-------- C:\Program Files\Microsoft Silverlight
2007-06-14 14:30 5,120 --a------ C:\WINDOWS\system32\drivers\GtFUsb.sys
2007-06-14 14:29 <DIR> d-------- C:\Program Files\Option
2007-06-14 14:28 <DIR> d-------- C:\WINDOWS\system32\appmgmt
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-07-14 02:45:08 12 ----a-w C:\WINDOWS\bthservsdp.dat
2007-07-10 11:08:32 -------- d-----w C:\DOCUME~1\Shane\APPLIC~1\Mappen Share-to-Web-overførsel
2007-06-11 12:59:28 -------- d-----w C:\DOCUME~1\Shane\APPLIC~1\Help
2007-06-08 21:29:46 -------- d-----w C:\DOCUME~1\Shane\APPLIC~1\DivX
2007-06-08 21:28:28 -------- d-----w C:\Program Files\DivX
2007-06-08 21:12:30 -------- d-----w C:\Program Files\Windows Media Connect 2
2007-06-08 09:52:50 947,096 ----a-w C:\WINDOWS\system32\_ISource30.dll
2007-06-02 19:57:08 -------- d-----w C:\DOCUME~1\Shane\APPLIC~1\OpenOffice.org2
2007-05-31 06:45:08 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2007-05-31 06:44:56 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2007-05-31 06:44:56 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2007-05-31 06:44:56 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2007-05-31 06:44:56 740,442 ----a-w C:\WINDOWS\system32\DivX.dll
2007-05-16 15:12:02 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-04-25 14:21:16 144,896 ----a-w C:\WINDOWS\system32\schannel.dll
2007-04-23 00:15:30 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2007-04-23 00:15:26 129,784 ------w C:\WINDOWS\system32\pxafs.dll
2007-04-23 00:15:26 118,520 ------w C:\WINDOWS\system32\pxinsi64.exe
2007-04-23 00:15:26 116,472 ------w C:\WINDOWS\system32\pxcpyi64.exe
2007-04-23 00:15:20 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2007-04-23 00:15:20 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2007-04-23 00:02:36 73,728 ----a-w C:\WINDOWS\system32\dpl100.dll
2007-04-23 00:02:36 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2007-04-23 00:02:34 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2007-04-23 00:02:32 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2007-04-23 00:02:32 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2007-04-23 00:02:32 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2007-04-23 00:02:32 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2007-04-23 00:02:32 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2007-04-23 00:01:48 124,472 ----a-w C:\WINDOWS\system32\DivXCodecUpdateChecker.exe
2007-04-23 00:01:48 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2007-04-18 16:12:24 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll
2007-04-16 20:47:36 33,624 ----a-w C:\WINDOWS\system32\wups.dll
2007-04-16 20:45:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-16 20:45:48 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-04-16 20:45:42 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-04-16 20:45:36 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-04-16 20:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-04-16 20:45:20 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-16 20:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
2004-12-14 01:56 63136 --a------ c:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
2005-05-31 01:04 853672 --a------ C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
2006-08-31 20:33 322368 --a------ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
2007-02-25 09:23 2411584 -ra------ c:\program files\google\googletoolbar1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 00:56 C:\WINDOWS\system32\bthprops.cpl]
"LaunchApp"="Alaunch" []
"RTHDCPL"="RTHDCPL.EXE" [2006-06-28 14:54 C:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-16 18:04 C:\WINDOWS\SkyTel.exe]
"Alcmtr"="ALCMTR.EXE" [2005-05-03 18:43 C:\WINDOWS\Alcmtr.exe]
"AzMixerSel"="C:\Program Files\Realtek\InstallShield\AzMixerSel.exe" [2005-12-21 15:02]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-03 13:07]
"ntiMUI"="C:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe" [2006-05-15 11:15]
"@"="" []
"ADMTray.exe"="C:\Acer\Empowering Technology\admtray.exe" [2005-10-24 16:45]
"eDataSecurity Loader"="C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2005-12-27 15:50]
"ePower_DMC"="C:\Acer\Empowering Technology\ePower\ePower_DMC.exe" [2006-08-10 19:29]
"Acer ePower Management"="C:\Acer\Empowering Technology\ePower\Acer ePower Management.exe" [2006-05-22 12:54]
"LManager"="C:\PROGRA~1\LAUNCH~1\LManager.exe" [2006-07-20 22:15]
"eRecoveryService"="C:\Acer\Empowering Technology\eRecovery\Monitor.exe" [2006-01-24 18:00]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2006-05-02 13:28]
"LaunchList"="C:\Program Files\Pinnacle\Studio 9\LaunchList.exe" []
"emMON"="emMON.exe" [2006-05-30 21:24 C:\WINDOWS\emMON.exe]
"Share-to-Web Namespace Daemon"="C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2001-07-03 09:11]
"spywarefighterguard"="C:\Program Files\SPYWAREfighter\spftray.exe" [2007-06-08 11:52]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 20:00]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2007-02-25 09:23]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:55]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source=
file:///C:\WINDOWS\privacy_danger\index.htmFriendlyName= Privacy Protection
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"="C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2006-12-20 13:55]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll --a------ 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs BthServ
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9dafa69a-c272-11db-920d-0016d4592801}]
AutoRun\command- F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9dafa69b-c272-11db-920d-0016d4592801}]
AutoRun\command- F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ea2418e2-c265-11db-920b-0016d4592801}]
AutoRun\command- F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ea2418e3-c265-11db-920b-0016d4592801}]
AutoRun\command- F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ffc5d876-1868-11dc-922d-0016d4592801}]
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL GlobeTrotterConnect.msi AUTORUN=1
*Newly Created Service* - INT15.SYS
Contents of the 'Scheduled Tasks' folder
2007-07-14 01:00:02 C:\WINDOWS\tasks\SpywareBot Scheduled Scan.job
**************************************************************************
catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer,
http://www.gmer.netRootkit scan 2007-07-14 18:56:03
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-07-14 18:56:49
C:\ComboFix-quarantined-files.txt ... 2007-07-14 18:56
--- E O F ---