"Pat" - 07-01-18 21:01:57 Service Pack 2
ComboFix 07-01-18 - Running from: "C:\Program Files\Mozilla Firefox"((((((((((((((((((((((((((((((( Files Created from 2006-12-18 to 2007-01-18 ))))))))))))))))))))))))))))))))))
2007-01-18 20:21 5,288 --a------ C:\WINDOWS\system32\tmp.reg
2007-01-18 20:19 79,360 --a------ C:\WINDOWS\system32\swxcacls.exe
2007-01-18 20:19 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-01-18 20:19 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-01-18 20:19 40,960 --a------ C:\WINDOWS\system32\swsc.exe
2007-01-18 20:19 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2007-01-18 20:19 135,168 --a------ C:\WINDOWS\system32\swreg.exe
2007-01-18 17:34 <DIR> d-------- C:\!KillBox
2007-01-18 17:32 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-01-18 17:32 <DIR> d-------- C:\Program Files\Grisoft
2007-01-18 16:26 <DIR> d-------- C:\Program Files\Hijackthis
2007-01-18 15:30 <DIR> d-------- C:\Program Files\ScanSpyware v3.8.0.4
2007-01-18 14:06 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2007-01-18 14:06 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-01-18 14:06 <DIR> d-------- C:\DOCUME~1\Pat\Application Data\SUPERAntiSpyware.com
2007-01-18 14:06 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\SUPERAntiSpyware.com
2007-01-18 13:48 <DIR> d-------- C:\Program Files\NoAdware5.0
2007-01-18 09:57 127,208 --a------ C:\WINDOWS\system32\mucltui.dll
2007-01-17 13:00 <DIR> d-------- C:\DOCUME~1\Pat\Application Data\WholeSecurity
2007-01-17 12:51 <DIR> d-------- C:\Program Files\Innovative Solutions
2007-01-16 12:40 <DIR> d-------- C:\4825ad8bf970d2cd70
2007-01-16 12:25 <DIR> d-------- C:\5a4e58954e5da01beeb53b
2007-01-15 13:49 <DIR> d-------- C:\Program Files\Norton Internet Security
2007-01-11 10:23 32,768 --a------ C:\WINDOWS\system32\setup9x.exe
2007-01-11 10:23 192 --a------ C:\WINDOWS\system32\ggg.bat
2007-01-10 17:44 79 --a------ C:\WINDOWS\delay.reg
2007-01-10 17:08 48,776 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2007-01-10 17:08 115,000 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-01-09 16:12 0 --a------ C:\WINDOWS\system32\taskkill.exe
2007-01-09 13:53 87,608 --a------ C:\DOCUME~1\Pat\Application Data\ezpinst.exe
2007-01-09 13:53 47,360 --a------ C:\WINDOWS\system32\drivers\pcouffin.sys
2007-01-09 13:53 47,360 --a------ C:\DOCUME~1\Pat\Application Data\pcouffin.sys
2007-01-09 13:53 <DIR> d-------- C:\Program Files\vso
2007-01-09 13:53 <DIR> d-------- C:\DOCUME~1\Pat\Application Data\Vso
2007-01-09 11:03 <DIR> d-------- C:\DOCUME~1\Pat\Application Data\dvdcss
2007-01-09 10:26 <DIR> d-------- C:\DOCUME~1\Pat\Application Data\DeepBurner
2007-01-07 14:18 153 --a------ C:\DelUS.bat
2007-01-06 17:38 286,720 --a------ C:\WINDOWS\iun506.exe
2007-01-06 17:38 <DIR> d-------- C:\Program Files\Learn to Play Bridge
2006-12-20 18:19 <DIR> d-------- C:\Program Files\MTV Networks
2006-12-20 18:03 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2006-12-20 18:00 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2006-12-19 17:09 276,792 --a------ C:\WINDOWS\system32\drivers\srtspl.sys
2006-12-19 17:09 25,400 --a------ C:\WINDOWS\system32\drivers\srtspx.sys
2006-12-19 17:09 247,096 --a------ C:\WINDOWS\system32\drivers\srtsp.sys
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-01-18 20:54 -------- d-------- C:\Program Files\mozilla firefox
2007-01-18 20:13 -------- d-------- C:\Program Files\notebook maximizer
2007-01-18 18:10 -------- d-------- C:\Program Files\Common Files\symantec shared
2007-01-18 13:47 -------- d-------- C:\Program Files\noadware4
2007-01-18 12:36 -------- d-------- C:\DOCUME~1\Pat\Application Data\adobeum
2007-01-17 13:34 -------- d-------- C:\DOCUME~1\Pat\Application Data\azureus
2007-01-17 13:33 -------- d-------- C:\Program Files\spywareblaster
2007-01-17 13:33 -------- d-------- C:\Program Files\quotetracker
2007-01-17 13:33 -------- d-------- C:\DOCUME~1\Pat\Application Data\mp3rocket
2007-01-15 13:51 -------- d-------- C:\Program Files\symantec
2007-01-12 17:12 -------- d-------- C:\Program Files\limewire
2007-01-11 13:03 7824 --a------ C:\DOCUME~1\Pat\Application Data\pcouffin.cat
2007-01-11 13:03 34 --a------ C:\DOCUME~1\Pat\Application Data\pcouffin.log
2007-01-11 13:03 1144 --a------ C:\DOCUME~1\Pat\Application Data\pcouffin.inf
2007-01-10 15:49 -------- d-------- C:\Program Files\astonsoft
2007-01-10 15:47 -------- d-------- C:\Program Files\microsoft works
2007-01-10 15:45 -------- d-------- C:\Program Files\mozilla thunderbird
2007-01-10 15:17 -------- d-------- C:\Program Files\registry mechanic
2007-01-10 14:54 -------- d-------- C:\Program Files\advanced system optimizer
2006-12-08 14:16 -------- d-------- C:\Program Files\Common Files\adobe
2006-12-04 10:35 -------- d-------- C:\Program Files\auction auto bidder
2006-11-30 16:54 -------- d-------- C:\Program Files\mytrack
2006-11-29 22:23 -------- d--h----- C:\Program Files\installshield installation information
2006-11-29 17:34 -------- d---s---- C:\DOCUME~1\Pat\Application Data\microsoft
2006-11-28 17:08 -------- d-------- C:\Program Files\america online 9.0a
2006-11-27 14:43 -------- d-------- C:\Program Files\google
2006-11-21 12:01 -------- d-------- C:\Program Files\expedia
2006-11-20 13:06 -------- d-------- C:\Program Files\quicktime
2006-11-07 23:06 679424 --a------ C:\WINDOWS\system32\inetcomm.dll
2006-11-04 14:14 1245696 --a------ C:\WINDOWS\system32\msxml4.dll
2006-11-02 13:14 704 --a------ C:\DOCUME~1\Pat\Application Data\update.log
2006-11-02 13:11 0 --a--c--- C:\Program Files\Common Files\err.log
2006-10-19 07:56 713216 --a------ C:\WINDOWS\system32\sxs.dll
2006-10-18 21:58 8704 --a------ C:\WINDOWS\system32\wdfmgr.exe
2006-10-18 21:58 8704 --a------ C:\WINDOWS\system32\uwdf.exe
2006-10-18 21:47 99840 --a------ C:\WINDOWS\system32\wmpshell.dll
2006-10-18 21:47 991744 --a------ C:\WINDOWS\system32\drmv2clt.dll
2006-10-18 21:47 937984 --a------ C:\WINDOWS\system32\wmnetmgr.dll
2006-10-18 21:47 8231936 --a------ C:\WINDOWS\system32\wmploc.dll
2006-10-18 21:47 767488 --------- C:\WINDOWS\system32\wmvsencd.dll
2006-10-18 21:47 757248 --a------ C:\WINDOWS\system32\wmadmod.dll
2006-10-18 21:47 7168 --a------ C:\WINDOWS\system32\asferror.dll
2006-10-18 21:47 656896 --------- C:\WINDOWS\system32\wmvxencd.dll
2006-10-18 21:47 63488 --a------ C:\WINDOWS\system32\wpdmtpus.dll
2006-10-18 21:47 629760 --a------ C:\WINDOWS\system32\wpd_ci.dll
2006-10-18 21:47 613376 --------- C:\WINDOWS\system32\wmpmde.dll
2006-10-18 21:47 603648 --a------ C:\WINDOWS\system32\wmspdmod.dll
2006-10-18 21:47 542720 --a------ C:\WINDOWS\system32\blackbox.dll
2006-10-18 21:47 535040 --------- C:\WINDOWS\system32\wmdrmsdk.dll
2006-10-18 21:47 429056 --a------ C:\WINDOWS\system32\wmdrmdev.dll
2006-10-18 21:47 414208 --a------ C:\WINDOWS\system32\msscp.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\wmvdmoe2.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\wmvdmod.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\wmvadve.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\wmvadvd.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\wmsdmoe2.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\wmsdmod.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\wdfapi.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\mpg4dmod.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\mp4sdmod.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\mp43dmod.dll
2006-10-18 21:47 38400 --------- C:\WINDOWS\system32\wpdshextres.dll
2006-10-18 21:47 37376 --a------ C:\WINDOWS\system32\wmdmps.dll
2006-10-18 21:47 35840 --a------ C:\WINDOWS\system32\wpdconns.dll
2006-10-18 21:47 356352 --a------ C:\WINDOWS\system32\wpdsp.dll
2006-10-18 21:47 348672 --a------ C:\WINDOWS\system32\wmdrmnet.dll
2006-10-18 21:47 33792 --a------ C:\WINDOWS\system32\wmdmlog.dll
2006-10-18 21:47 321536 --a------ C:\WINDOWS\system32\mswmdm.dll
2006-10-18 21:47 317440 --------- C:\WINDOWS\system32\mp4sdecd.dll
2006-10-18 21:47 314880 --a------ C:\WINDOWS\system32\wmpdxm.dll
2006-10-18 21:47 295936 --------- C:\WINDOWS\system32\wmpeffects.dll
2006-10-18 21:47 284160 --------- C:\WINDOWS\system32\portabledeviceapi.dll
2006-10-18 21:47 276992 --a------ C:\WINDOWS\system32\audiodev.dll
2006-10-18 21:47 27136 --a------ C:\WINDOWS\system32\mspmsnsv.dll
2006-10-18 21:47 2603008 --------- C:\WINDOWS\system32\wpdshext.dll
2006-10-18 21:47 259072 --------- C:\WINDOWS\system32\mpg4decd.dll
2006-10-18 21:47 259072 --------- C:\WINDOWS\system32\mp43decd.dll
2006-10-18 21:47 2450944 --a------ C:\WINDOWS\system32\wmvcore.dll
2006-10-18 21:47 242688 --a------ C:\WINDOWS\system32\wmpasf.dll
2006-10-18 21:47 229376 --a------ C:\WINDOWS\system32\cewmdm.dll
2006-10-18 21:47 227328 --a------ C:\WINDOWS\system32\wmerror.dll
2006-10-18 21:47 222208 --a------ C:\WINDOWS\system32\wmasf.dll
2006-10-18 21:47 212992 --------- C:\WINDOWS\system32\mfplat.dll
2006-10-18 21:47 211456 --a------ C:\WINDOWS\system32\qasf.dll
2006-10-18 21:47 204288 --a------ C:\WINDOWS\system32\wmpsrcwp.dll
2006-10-18 21:47 199168 --------- C:\WINDOWS\system32\portabledevicewmdrm.dll
2006-10-18 21:47 179712 --a------ C:\WINDOWS\system32\msnetobj.dll
2006-10-18 21:47 175616 --a------ C:\WINDOWS\system32\mspmsp.dll
2006-10-18 21:47 166912 --------- C:\WINDOWS\system32\portabledevicetypes.dll
2006-10-18 21:47 1661440 --a------ C:\WINDOWS\system32\wmpencen.dll
2006-10-18 21:47 1574912 --------- C:\WINDOWS\system32\wmvencod.dll
2006-10-18 21:47 157184 --a------ C:\WINDOWS\system32\wmidx.dll
2006-10-18 21:47 154624 --a------ C:\WINDOWS\system32\wpdmtp.dll
2006-10-18 21:47 1543680 --------- C:\WINDOWS\system32\wmvdecod.dll
2006-10-18 21:47 1382912 --------- C:\WINDOWS\system32\wmvsdecd.dll
2006-10-18 21:47 133632 --------- C:\WINDOWS\system32\wpdshserviceobj.dll
2006-10-18 21:47 1329152 --a------ C:\WINDOWS\system32\wmspdmoe.dll
2006-10-18 21:47 132096 --------- C:\WINDOWS\system32\portabledevicewiacompat.dll
2006-10-18 21:47 130048 --------- C:\WINDOWS\system32\wmpps.dll
2006-10-18 21:47 11264 --a------ C:\WINDOWS\system32\laprxy.dll
2006-10-18 21:47 1117696 --a------ C:\WINDOWS\system32\wmadmoe.dll
2006-10-18 21:47 101888 --------- C:\WINDOWS\system32\portabledeviceclassextension.dll
2006-10-18 20:03 100864 --a------ C:\WINDOWS\system32\logagent.exe
2006-10-18 20:00 249856 --------- C:\WINDOWS\system32\drmupgds.exe
2006-10-18 20:00 17408 --------- C:\WINDOWS\system32\wpdshextautoplay.exe
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"TOSCDSPD"="C:\\Program Files\\TOSHIBA\\TOSCDSPD\\toscdspd.exe"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"Window Washer"="C:\\Program Files\\Webroot\\Washer\\wwDisp.exe"
"MSGTAG"="\"C:\\Program Files\\MSGTAG\\MSGTAG.exe\" /startup"
"Creative Detector"="C:\\Program Files\\Creative\\MediaSource\\Detector\\CTDetect.exe /R"
"Taskbar Button Manager"="C:\\Program Files\\Innovative Solutions\\Taskbar Button Manager\\tbm.exe"
"SUPERAntiSpyware"="C:\\Program Files\\SUPERAntiSpyware\\SUPERAntiSpyware.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"IgfxTray"="C:\\WINDOWS\\system32\\igfxtray.exe"
"HotKeysCmds"="C:\\WINDOWS\\system32\\hkcmd.exe"
@=""
"IntelWireless"="C:\\Program Files\\Intel\\Wireless\\Bin\\ifrmewrk.exe /tf Intel PROSet/Wireless"
"dla"="C:\\WINDOWS\\system32\\dla\\tfswctrl.exe"
"AGRSMMSG"="AGRSMMSG.exe"
"Apoint"="C:\\Program Files\\Apoint2K\\Apoint.exe"
"TPNF"="C:\\Program Files\\TOSHIBA\\TouchPad\\TPTray.exe"
"TOSHIBA Accessibility"="C:\\Program Files\\TOSHIBA\\Accessibility\\FnKeyHook.exe"
"TCtryIOHook"="TCtrlIOHook.exe"
"TFncKy"="TFncKy.exe"
"CeEKEY"="C:\\Program Files\\TOSHIBA\\E-KEY\\CeEKey.exe"
"TPSMain"="TPSMain.exe"
"SVPWUTIL"="C:\\Program Files\\Toshiba\\Windows Utilities\\SVPWUTIL.exe SVPwUTIL"
"PadTouch"="C:\\Program Files\\TOSHIBA\\Touch and Launch\\PadExe.exe"
"ZoomingHook"="ZoomingHook.exe"
"SmoothView"="C:\\Program Files\\TOSHIBA\\TOSHIBA Zooming Utility\\SmoothView.exe"
"HWSetup"="C:\\Program Files\\TOSHIBA\\TOSHIBA Applet\\HWSetup.exe hwSetUP"
"Tvs"="C:\\Program Files\\Toshiba\\Tvs\\TvsTray.exe"
"Pinger"="c:\\toshiba\\ivp\\ism\\pinger.exe /run"
"Notebook Maximizer"="C:\\Program Files\\Notebook Maximizer\\maximizer_startup.exe"
"Ulead AutoDetector v2"="C:\\Program Files\\Common Files\\Ulead Systems\\AutoDetector\\monitor.exe"
"Adobe Photo Downloader"="\"C:\\Program Files\\Adobe\\Photoshop Album Starter Edition\\3.0\\Apps\\apdproxy.exe\""
"Samsung PanelMgr"="C:\\WINDOWS\\Samsung\\PanelMgr\\ssmmgr.exe /autorun"
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="C:\\Program Files\\Google\\Gmail Notifier\\gnotify.exe"
"OpwareSE2"="\"C:\\Program Files\\ScanSoft\\OmniPageSE2.0\\OpwareSE2.exe\""
"OPSE reminder"="\"C:\\Program Files\\ScanSoft\\OmniPageSE2.0\\EregEng\\Ereg.exe\" -r \"C:\\Program Files\\ScanSoft\\OmniPageSE2.0\\EregEng\\ereg.ini\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"osCheck"="\"C:\\Program Files\\Norton Internet Security\\osCheck.exe\""
"!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
"backup"="C:\\WINDOWS\\pss\\Microsoft Office.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\MICROS~2\\Office10\\OSA.EXE -b -l"
"item"="Microsoft Office"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Pat^Start Menu^Programs^Startup^Webshots.lnk]
"backup"="C:\\WINDOWS\\pss\\Webshots.lnkStartup"
"location"="Startup"
"command"="C:\\PROGRA~1\\Webshots\\Launcher.exe /t"
"item"="Webshots"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0
*newlycreated* - HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\LEGACY_COMHOST
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Norton Internet Security - Run Full System Scan - Pat.job
Completion time: 07-01-18 21:05:08