"Owner" - 07-01-30 0:46:59 Service Pack 2
ComboFix 07-01-25 - Running from: "C:\Documents and Settings\Owner\Desktop"
((((((((((((((((((((((((((((((( Files Created from 2006-12-30 to 2007-01-30 ))))))))))))))))))))))))))))))))))
2007-01-29 23:37 <DIR> d-------- C:\bintheredunthat
2007-01-29 23:28 <DIR> d-------- C:\New Folder
2007-01-29 23:28 <DIR> d-------- C:\BFU
2007-01-28 09:53 4,816 --a------ C:\WINDOWS\system32\drivers\aeaudio.sys
2007-01-28 09:53 3,744 --a------ C:\WINDOWS\system32\drivers\smsens.sys
2007-01-28 09:52 542,976 --a------ C:\WINDOWS\system32\drivers\smwdm.sys
2007-01-28 09:52 49,152 --a------ C:\WINDOWS\system32\DSndUp.exe
2007-01-28 09:52 45,056 --a------ C:\WINDOWS\system32\CleanUp.exe
2007-01-28 09:52 <DIR> d-------- C:\Program Files\Analog Devices
2007-01-27 22:19 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2007-01-27 22:17 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2007-01-27 21:54 <DIR> d-------- C:\Program Files\Common Files\Java
2007-01-27 21:37 <DIR> d-------- C:\WINDOWS\WBEM
2007-01-27 16:46 <DIR> d--h-c--- C:\WINDOWS\ie7
2007-01-27 16:39 <DIR> d-------- C:\WINDOWS\network diagnostic
2007-01-26 21:04 81,024 --a------ C:\WINDOWS\system32\drivers\msfwdrv.sys
2007-01-26 21:04 105,856 --a------ C:\WINDOWS\system32\drivers\msfwhlpr.sys
2007-01-26 21:03 67,784 --a------ C:\WINDOWS\system32\drivers\MpFilter.sys
2007-01-26 21:03 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-01-26 20:59 <DIR> dr--s---- C:\WINDOWS\assembly
2007-01-26 20:58 <DIR> d-------- C:\WINDOWS\Microsoft.NET
2007-01-26 20:53 <DIR> d-------- C:\Program Files\Microsoft Windows OneCare Live
2007-01-26 17:24 <DIR> d-------- C:\hjt
2007-01-24 12:40 <DIR> d-------- C:\Program Files\PCPitstop
2007-01-23 00:03 <DIR> d-------- C:\Program Files\Common Files\Agnitum Shared
2007-01-23 00:03 <DIR> d-------- C:\Program Files\Agnitum
2007-01-19 00:21 <DIR> d-------- C:\Program Files\Incomplete
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-01-30 00:38 -------- d-------- C:\DOCUME~1\Owner\Application Data\mp3rocket
2007-01-28 17:38 -------- d-------- C:\Program Files\google
2007-01-28 09:52 -------- d--h----- C:\Program Files\installshield installation information
2007-01-28 09:18 -------- d-------- C:\Program Files\mozilla firefox
2007-01-27 22:10 -------- d-------- C:\Program Files\mp3 rocket
2007-01-27 21:55 -------- d-------- C:\Program Files\java
2007-01-27 14:45 262 --a------ C:\DOCUME~1\Owner\Application Data\winsscookie.txt
2007-01-25 15:08 -------- d-------- C:\Program Files\ws_ftp
2007-01-25 11:22 -------- d-------- C:\Program Files\Common Files\real
2007-01-25 11:22 -------- d-------- C:\DOCUME~1\Owner\Application Data\real
2007-01-25 10:10 -------- d-------- C:\Program Files\movie maker
2007-01-24 22:48 43 ---hs---- C:\DOCUME~1\Owner\Application Data\.zreglib
2007-01-24 14:43 -------- d-------- C:\Program Files\mp3rocket
2007-01-24 12:24 -------- d-------- C:\Program Files\real
2007-01-24 12:20 -------- d-------- C:\Program Files\itunes
2007-01-19 13:02 -------- d-------- C:\DOCUME~1\Owner\Application Data\apple computer
2006-12-30 16:32 -------- d-------- C:\Program Files\divx
2006-12-30 16:12 -------- d-------- C:\Program Files\Common Files\symantec shared
2006-12-30 16:12 -------- d-------- C:\Program Files\Common Files\aol
2006-12-30 16:10 -------- d-------- C:\Program Files\microsoft activesync
2006-12-30 16:06 -------- d-------- C:\Program Files\vol_wizard
2006-12-30 16:05 -------- d-------- C:\Program Files\plaxo
2006-12-30 15:09 -------- d-------- C:\Program Files\bigfix
2006-12-15 19:16 -------- d-------- C:\Program Files\kodak
2006-12-15 19:14 -------- d-------- C:\Program Files\Common Files\kodak
2006-12-07 14:50 -------- d-------- C:\Program Files\netscape
2006-11-08 00:06 679424 --a------ C:\WINDOWS\system32\inetcomm.dll
2006-11-07 21:03 6049280 --------- C:\WINDOWS\system32\ieframe.dll
2006-11-07 21:03 50688 --------- C:\WINDOWS\system32\msfeedsbs.dll
2006-11-07 21:03 458752 --------- C:\WINDOWS\system32\msfeeds.dll
2006-11-07 21:03 413696 --a------ C:\WINDOWS\system32\vbscript.dll
2006-11-07 21:03 231424 --a------ C:\WINDOWS\system32\webcheck.dll
2006-11-07 21:03 180736 --------- C:\WINDOWS\system32\ieui.dll
2006-11-07 21:03 156160 --a------ C:\WINDOWS\system32\msls31.dll
2006-11-07 03:27 382976 --a------ C:\WINDOWS\system32\iedkcs32.dll
2006-11-07 03:27 229376 --a------ C:\WINDOWS\system32\ieaksie.dll
2006-11-07 03:26 71680 --a------ C:\WINDOWS\system32\admparse.dll
2006-11-07 03:26 55296 --a------ C:\WINDOWS\system32\iesetup.dll
2006-11-07 03:26 54784 --a------ C:\WINDOWS\system32\ie4uinit.exe
2006-11-07 03:26 43008 --a------ C:\WINDOWS\system32\iernonce.dll
2006-11-07 03:26 152064 --a------ C:\WINDOWS\system32\ieakeng.dll
2006-11-07 03:26 13312 --a------ C:\WINDOWS\system32\ieudinit.exe
2006-11-07 03:26 123904 --a------ C:\WINDOWS\system32\advpack.dll
2006-11-07 03:25 161792 --a------ C:\WINDOWS\system32\ieakui.dll
2006-11-04 14:14 1245696 --a------ C:\WINDOWS\system32\msxml4.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"AnyDVD"="C:\\Program Files\\SlySoft\\AnyDVD\\AnyDVD.exe"
"Aim6"="\"C:\\Program Files\\AIM6\\aim6.exe\" /d locale=en-US ee://aol/imApp"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.908.5008\\GoogleToolbarNotifier.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"OneCareUI"="\"C:\\Program Files\\Microsoft Windows OneCare Live\\winssnotify.exe\""
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_10\\bin\\jusched.exe\""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonceex]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
Source REG_SZ
https://customerservice.southerncompany.com...eYourEnergy.gif[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\1]
Source REG_SZ
http://www.navyfcu.org/images/index_v3_nv-ro.gif[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\2]
Source REG_SZ
http://yaps5thave.tripod.com/imagelib/site...yout/spacer.gif[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\OneCareMP
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ AlerterWebClientLmHostsRemoteRegistryupnphostSSDPSRV
NetworkService REG_MULTI_SZ DnsCache
rpcss REG_MULTI_SZ RpcSs
imgsvc REG_MULTI_SZ StiSvc
termsvcs REG_MULTI_SZ TermService
HTTPFilter REG_MULTI_SZ HTTPFilter
DcomLaunch REG_MULTI_SZ DcomLaunchTermService
WudfServiceGroup REG_MULTI_SZ WUDFSvc
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\MP Scheduled Quick Scan.job
C:\WINDOWS\tasks\MP Scheduled Scan.job
C:\WINDOWS\tasks\MP Scheduled Signature Update.job
Completion time: 07-01-30 0:50:41