"Justin Dreyer" - 2007-07-12 22:02:28 - ComboFix 07-07-13 - Service Pack 2
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\180ax.exe
C:\WINDOWS\2020search.dll
C:\WINDOWS\2020search2.dll
C:\WINDOWS\764.exe
C:\WINDOWS\7search.dll
C:\WINDOWS\bi.dll
C:\WINDOWS\biprep.exe
C:\WINDOWS\bjam.dll
C:\WINDOWS\bokja.exe
C:\WINDOWS\cdsm32.dll
C:\WINDOWS\flt.dll
C:\WINDOWS\mspphe.dll
C:\WINDOWS\mssvr.exe
C:\WINDOWS\pbar.dll
C:\WINDOWS\saiemod.dll
C:\WINDOWS\salm.exe
C:\WINDOWS\satmat.exe
C:\WINDOWS\stcloader.exe
C:\WINDOWS\susp.exe
C:\WINDOWS\swin32.dll
C:\WINDOWS\system32\gtv_sd.bin
C:\WINDOWS\system32\msixu.dll
C:\WINDOWS\system32\sl.bin
C:\WINDOWS\system32\vxddsk.exe
C:\WINDOWS\system32\wer8274.dll
C:\WINDOWS\system32\wml.exe
C:\WINDOWS\temp\salm.exe
C:\WINDOWS\updatetc.exe
C:\WINDOWS\voiceip.dll
C:\WINDOWS\wml.exe
((((((((((((((((((((((((( Files Created from 2007-06-13 to 2007-07-13 )))))))))))))))))))))))))))))))
2007-07-12 22:02 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-07-12 16:45 <DIR> d-------- C:\Program Files\HJT
2007-07-12 16:43 <DIR> d-------- C:\WINDOWS\system32\appmgmt
2007-07-12 15:39 <DIR> d-------- C:\DOCUME~1\JUSTIN~1\APPLIC~1\Sonic
2007-07-12 15:39 <DIR> d-------- C:\DOCUME~1\JUSTIN~1\APPLIC~1\Leadertech
2007-07-10 23:29 <DIR> d-------- C:\Program Files\iPod
2007-07-10 23:28 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-07-10 23:28 <DIR> d-------- C:\Program Files\Common Files\Apple
2007-07-10 23:28 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
2007-07-10 22:09 <DIR> d-------- C:\DOCUME~1\JUSTIN~1\APPLIC~1\Google
2007-07-07 16:30 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
2007-07-04 23:34 <DIR> d---s---- C:\DOCUME~1\JUSTIN~1\UserData
2007-07-04 14:44 <DIR> d-------- C:\Program Files\All mp3
2007-07-02 17:30 <DIR> d-------- C:\DOCUME~1\JUSTIN~1\APPLIC~1\DivX
2007-07-02 17:29 <DIR> d-------- C:\Program Files\Google
2007-07-02 17:28 129,784 --------- C:\WINDOWS\system32\pxafs.dll
2007-07-02 17:28 <DIR> d-------- C:\Program Files\DivX
2007-07-01 22:37 <DIR> d-------- C:\Program Files\Soulseek
2007-06-30 22:03 967 --a------ C:\WINDOWS\ScUnin.pif
2007-06-30 22:03 70,656 --a------ C:\WINDOWS\ScUnin.exe
2007-06-30 22:03 32,845 --a------ C:\WINDOWS\scunin.dat
2007-06-30 22:03 <DIR> d-------- C:\Program Files\Starcraft
2007-06-30 18:30 0 --a------ C:\DOCUME~1\JUSTIN~1\APPLIC~1\wklnhst.dat
2007-06-30 18:30 <DIR> d-------- C:\DOCUME~1\JUSTIN~1\APPLIC~1\Template
2007-06-27 00:07 <DIR> d-------- C:\Program Files\Zeratul
2007-06-26 22:23 <DIR> d-------- C:\Program Files\LimeWire
2007-06-26 22:23 <DIR> d-------- C:\DOCUME~1\JUSTIN~1\Shared
2007-06-26 22:23 <DIR> d-------- C:\DOCUME~1\JUSTIN~1\Incomplete
2007-06-26 22:23 <DIR> d-------- C:\DOCUME~1\JUSTIN~1\APPLIC~1\LimeWire
2007-06-25 13:51 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-06-25 02:27 <DIR> d-------- C:\Program Files\SpyAway
2007-06-25 02:18 9,216 --a------ C:\WINDOWS\system32\avgwlntf.dll
2007-06-25 02:18 110,592 --a------ C:\WINDOWS\system32\avgfwafu.dll
2007-06-25 01:58 <DIR> d-------- C:\Program Files\MSXML 4.0
2007-06-25 01:52 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
2007-06-25 01:21 4 --a------ C:\WINDOWS\system32\stfv.bin
2007-06-25 01:18 20,224 --a------ C:\WINDOWS\vxddsk.exe
2007-06-25 01:04 118,784 --a------ C:\WINDOWS\system32\MSSTDFMT.DLL
2007-06-25 01:04 <DIR> d-------- C:\Program Files\SpywareBlaster
2007-06-24 22:55 1,156 --a------ C:\WINDOWS\mozver.dat
2007-06-24 16:55 23,040 --------- C:\WINDOWS\kb913800.exe
2007-06-24 16:45 82,944 --a------ C:\WINDOWS\system32\drivers\wdmaud.sys
2007-06-24 16:45 60,800 --a------ C:\WINDOWS\system32\drivers\sysaudio.sys
2007-06-24 16:45 6,400 --a------ C:\WINDOWS\system32\drivers\splitter.sys
2007-06-24 16:45 54,272 --a------ C:\WINDOWS\system32\drivers\swmidi.sys
2007-06-24 16:45 52,864 --a------ C:\WINDOWS\system32\drivers\DMusic.sys
2007-06-24 16:45 282,624 --a------ C:\WINDOWS\stsystra.exe
2007-06-24 16:45 2,944 --a------ C:\WINDOWS\system32\drivers\drmkaud.sys
2007-06-24 16:45 172,416 --a------ C:\WINDOWS\system32\drivers\kmixer.sys
2007-06-24 16:45 142,464 --a------ C:\WINDOWS\system32\drivers\aec.sys
2007-06-24 16:45 1,003,520 --a------ C:\WINDOWS\system32\stlang.dll
2007-06-24 16:45 <DIR> d-------- C:\Program Files\Sigmatel
2007-06-24 16:44 60,288 --a------ C:\WINDOWS\system32\drivers\drmk.sys
2007-06-24 16:41 <DIR> d-------- C:\WINDOWS\system32\PreInstall
2007-06-24 16:38 <DIR> d-------- C:\Program Files\PokerStars
2007-06-24 14:48 <DIR> d-------- C:\Program Files\DellSupport
2007-06-24 14:45 <DIR> d-------- C:\WINDOWS\system32\SoftwareDistribution
2007-06-24 14:40 36,864 --a------ C:\WINDOWS\system32\e100bmsg.dll
2007-06-24 14:40 19,456 --a------ C:\WINDOWS\system32\IntelNic.dll
2007-06-24 14:40 126,976 --a------ C:\WINDOWS\system32\Prounstl.exe
2007-06-23 15:46 <DIR> d-------- C:\drvrtmp
2007-06-21 23:43 <DIR> d-------- C:\Program Files\iTunes
2007-06-21 23:43 <DIR> d-------- C:\DOCUME~1\JUSTIN~1\APPLIC~1\Apple Computer
2007-06-21 23:42 <DIR> d-------- C:\Program Files\QuickTime
2007-06-21 23:42 <DIR> d-------- C:\Program Files\Apple Software Update
2007-06-21 23:42 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
2007-06-21 23:41 <DIR> d-------- C:\DOCUME~1\JUSTIN~1\APPLIC~1\U3
2007-06-21 18:06 <DIR> d-------- C:\DOCUME~1\LOCALS~1\APPLIC~1\McAfee.com Personal Firewall
2007-06-21 18:04 13,225 --a------ C:\WINDOWS\system32\drivers\Razerlow.sys
2007-06-21 18:04 <DIR> d-------- C:\Program Files\Razer
2007-06-21 18:00 <DIR> d-------- C:\DOCUME~1\JUSTIN~1\APPLIC~1\Jasc Software Inc
2007-06-21 17:59 <DIR> d-------- C:\Program Files\Jasc Software Inc
2007-06-21 17:59 <DIR> d-------- C:\Program Files\Common Files\Jasc Software Inc
2007-06-21 17:58 <DIR> d-------- C:\Program Files\Dl_cats
2007-06-21 17:58 <DIR> d-------- C:\Program Files\Abbyy FineReader 6.0 Sprint
2007-06-21 17:57 87,040 --a------ C:\WINDOWS\system32\wiafbdrv.dll
2007-06-21 17:57 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2007-06-21 17:56 983,092 --a------ C:\WINDOWS\system32\dlccgf.dll
2007-06-21 17:56 86,016 --a------ C:\WINDOWS\system32\dlcccub.dll
2007-06-21 17:56 774,144 --a------ C:\WINDOWS\system32\dlcchbn3.dll
2007-06-21 17:56 73,728 --a------ C:\WINDOWS\system32\dlcccu.dll
2007-06-21 17:56 704,512 --a------ C:\WINDOWS\system32\dlcccomc.dll
2007-06-21 17:56 65,536 --a------ C:\WINDOWS\system32\dlcccfg.dll
2007-06-21 17:56 638,976 --a------ C:\WINDOWS\system32\dlccpmui.dll
2007-06-21 17:56 491,520 --a------ C:\WINDOWS\system32\dlcccoms.exe
2007-06-21 17:56 483,328 --a------ C:\WINDOWS\system32\dlcclmpm.dll
2007-06-21 17:56 430,080 --a------ C:\WINDOWS\system32\dlccutil.dll
2007-06-21 17:56 413,696 --a------ C:\WINDOWS\system32\dlcccomm.dll
2007-06-21 17:56 40,960 --a------ C:\WINDOWS\system32\dlccvs.dll
2007-06-21 17:56 372,736 --a------ C:\WINDOWS\system32\dlccih.exe
2007-06-21 17:56 368,640 --a------ C:\WINDOWS\system32\dlcccfg.exe
2007-06-21 17:56 36,864 --a------ C:\WINDOWS\system32\dlcccur.dll
2007-06-21 17:56 176,128 --a------ C:\WINDOWS\system32\dlccinsb.dll
2007-06-21 17:56 155,648 --a------ C:\WINDOWS\system32\dlccprox.dll
2007-06-21 17:56 155,648 --a------ C:\WINDOWS\system32\dlccins.dll
2007-06-21 17:56 131,072 --a------ C:\WINDOWS\system32\dlccjswr.dll
2007-06-21 17:56 114,688 --a------ C:\WINDOWS\system32\dlccpplc.dll
2007-06-21 17:56 106,496 --a------ C:\WINDOWS\system32\dlccinsr.dll
2007-06-21 17:56 1,183,744 --a------ C:\WINDOWS\system32\dlccserv.dll
2007-06-21 17:56 1,134,592 --a------ C:\WINDOWS\system32\dlccusb1.dll
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-06-25 18:50:13 -------- d-----w C:\Program Files\DIGStream
2007-06-25 06:18:24 801 ----a-w C:\WINDOWS\system32\drivers\system_stable_header_small.gif
2007-06-25 06:18:24 567 ----a-w C:\WINDOWS\system32\drivers\users_rating.gif
2007-06-25 06:18:24 291 ----a-w C:\WINDOWS\system32\drivers\v.gif
2007-06-25 06:18:24 283 ----a-w C:\WINDOWS\system32\drivers\x.gif
2007-06-25 06:18:24 1,636 ----a-w C:\WINDOWS\system32\drivers\system_stable_header.gif
2007-06-25 06:18:23 6,533 ----a-w C:\WINDOWS\system32\drivers\system_stable_box_small.jpg
2007-06-25 06:18:23 579 ----a-w C:\WINDOWS\system32\drivers\spy_away_header_small.gif
2007-06-25 06:18:23 15,075 ----a-w C:\WINDOWS\system32\drivers\system_stable_box.jpg
2007-06-25 06:18:23 1,139 ----a-w C:\WINDOWS\system32\drivers\spy_away_header.gif
2007-06-25 06:18:22 5,097 ----a-w C:\WINDOWS\system32\drivers\spy_away_box_small.jpg
2007-06-25 06:18:22 14,484 ----a-w C:\WINDOWS\system32\drivers\protect.gif
2007-06-25 06:18:22 13,618 ----a-w C:\WINDOWS\system32\drivers\spy_away_box.jpg
2007-06-25 06:18:21 841 ----a-w C:\WINDOWS\system32\drivers\perfect_cleaner_header_small.gif
2007-06-25 06:18:21 4,557 ----a-w C:\WINDOWS\system32\drivers\perfect_cleaner_box_small.jpg
2007-06-25 06:18:21 10,260 ----a-w C:\WINDOWS\system32\drivers\perfect_cleaner_box.jpg
2007-06-25 06:18:21 1,804 ----a-w C:\WINDOWS\system32\drivers\perfect_cleaner_header.gif
2007-06-25 06:18:20 811 ----a-w C:\WINDOWS\system32\drivers\download_btn.gif
2007-06-25 06:18:20 746 ----a-w C:\WINDOWS\system32\drivers\buy_btn.gif
2007-06-25 06:18:20 737 ----a-w C:\WINDOWS\system32\drivers\logo_bg.gif
2007-06-25 06:18:20 580 ----a-w C:\WINDOWS\system32\drivers\features.gif
2007-06-25 06:18:20 3,099 ----a-w C:\WINDOWS\system32\drivers\logo.gif
2007-06-25 06:18:19 50,169 ----a-w C:\WINDOWS\system32\drivers\pt.htm
2007-06-25 06:18:19 427 ----a-w C:\WINDOWS\system32\drivers\4_stars.gif
2007-06-25 06:18:19 365 ----a-w C:\WINDOWS\system32\drivers\5_stars.gif
2007-06-25 06:18:18 945 ----a-w C:\WINDOWS\system32\drivers\s_detect.htm
2007-06-25 06:18:18 6,575 ----a-w C:\WINDOWS\system32\drivers\remove_spyware_button.gif
2007-06-25 06:18:18 6,373 ----a-w C:\WINDOWS\system32\drivers\secuity_center_logo.gif
2007-06-25 06:18:17 64 ----a-w C:\WINDOWS\system32\drivers\close_icon.gif
2007-06-25 06:18:17 4,825 ----a-w C:\WINDOWS\system32\drivers\detect.htm
2007-06-25 06:18:17 360 ----a-w C:\WINDOWS\system32\drivers\header_bg.gif
2007-06-25 06:18:17 2,186 ----a-w C:\WINDOWS\system32\drivers\alert_icon.gif
2007-06-25 06:18:17 1,014 ----a-w C:\WINDOWS\system32\drivers\icon_warning.gif
2007-06-21 21:33:15 -------- d-----w C:\Program Files\Messenger
2007-06-20 03:05:44 7,531 ----a-w C:\WINDOWS\system32\drivers\1028_Dell_DIM_DM051.mrk
2007-05-31 06:45:07 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2007-05-31 06:44:55 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2007-05-31 06:44:54 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2007-05-31 06:44:54 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2007-05-31 06:44:54 740,442 ----a-w C:\WINDOWS\system32\DivX.dll
2007-05-16 15:12:02 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-04-25 14:21:15 144,896 ----a-w C:\WINDOWS\system32\schannel.dll
2007-04-23 00:15:29 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2007-04-23 00:15:18 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2007-04-23 00:15:18 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2007-04-23 00:02:34 73,728 ----a-w C:\WINDOWS\system32\dpl100.dll
2007-04-23 00:02:34 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2007-04-23 00:02:33 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2007-04-23 00:02:31 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2007-04-23 00:02:31 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2007-04-23 00:02:31 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2007-04-23 00:02:31 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2007-04-23 00:02:31 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2007-04-23 00:01:47 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2007-04-23 00:01:46 124,472 ----a-w C:\WINDOWS\system32\DivXCodecUpdateChecker.exe
2007-04-18 16:12:23 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll
2007-04-17 03:47:36 33,624 ----a-w C:\WINDOWS\system32\wups.dll
2007-04-17 03:45:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-17 03:45:48 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-04-17 03:45:42 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-04-17 03:45:36 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-04-17 03:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-04-17 03:45:20 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-17 03:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
2006-01-12 20:38 63128 --a------ C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
2005-11-10 13:22 184423 --a------ C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-05 21:05]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 03:12]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 16:50]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 16:50]
"dlccmon.exe"="C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe" [2005-10-21 10:40]
"razer"="C:\Program Files\Razer\razerhid.exe" [2005-05-17 18:21]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41]
"SigmatelSysTrayApp"="stsystra.exe" [2006-02-10 11:17 C:\WINDOWS\stsystra.exe]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-06-25 02:18]
"MSKDetectorExe"="C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" [2005-07-12 19:05]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-07-02 17:29]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-06-28 09:14]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 11:09]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{827D3881-317C-442A-B4ED-F576CBA700BB}"="C:\WINDOWS\SYSTEM32\GWSEH.dll" [2004-09-23 07:21]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgwlntf]
avgwlntf.dll --a------ 2007-06-25 02:18 9216 C:\WINDOWS\system32\avgwlntf.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
AutoRun\command- F:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
AutoRun\command- E:\setup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e3c7ff4a-207a-11dc-b42b-00038a000015}]
AutoRun\command- F:\LaunchU3.exe -a
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{Y479C6D0-OTRW-U5GH-S1EE-E02310B4E666}
C:\WINDOWS\system32\tmrsrv32.exe
Contents of the 'Scheduled Tasks' folder
2007-07-10 17:11:02 C:\WINDOWS\tasks\AppleSoftwareUpdate.job
**************************************************************************
catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer,
http://www.gmer.netRootkit scan 2007-07-12 22:04:32
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-07-12 22:04:59
C:\ComboFix-quarantined-files.txt ... 2007-07-12 22:04
--- E O F ---