Locating ComboFix Log
- Right click on START on the left end of your Windows toolbar (lower left corner of your screen)
- Click on Explore
- Click on Local Disk (C:) in the left-hand window pane
- Look for ComboFix.txt in the right-hand window pane and right click on it
- Put your cursor (arrow) on Open With
- Move your cursor to the new menu that opens and click on Choose Program...
- Click on Notepad
When file opens, Copy/Paste text here.
Ah forgot that sorry.
ComboFix 10-10-01.07 - Andy 04/10/2010 21:46:24.3.2 - x86 MINIMAL
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3327.2915 [GMT 1:00]
Running from: e:\documents and settings\Andy\Desktop\ComboFix.exe
AV: ESET NOD32 Antivirus 3.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\5.exe
C:\F.exe
e:\documents and settings\unlock\wrar380.exe
e:\windows\PixArt\PAP7501\GUCI_AVS.exe
e:\windows\system32\muzapp.exe
e:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIEKE.exe
.
((((((((((((((((((((((((( Files Created from 2010-09-04 to 2010-10-04 )))))))))))))))))))))))))))))))
.
2010-10-02 22:57 . 2010-10-02 22:57 -------- d-----w- e:\documents and settings\Andy\Local Settings\Application Data\Google
2010-10-02 22:53 . 2010-10-02 22:53 -------- d-----w- e:\program files\Google
2010-09-30 23:57 . 2010-09-30 23:57 -------- d-----w- E:\_OTL
2010-09-29 16:14 . 2010-09-29 16:14 -------- d-----w- e:\program files\Common Files\Java
2010-09-28 17:06 . 2010-09-28 17:06 388096 ----a-r- e:\documents and settings\Andy\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-09-28 17:06 . 2010-09-28 17:06 -------- d-----w- e:\program files\Trend Micro
2010-09-27 21:29 . 2010-09-27 21:29 -------- d-----w- e:\documents and settings\Andy\Application Data\com.adobe.WidgetBrowser.E7BED6E5DDA59983786DD72EBFA46B1598278E07.1
2010-09-27 20:57 . 2010-09-27 20:57 2826240 ----a-w- e:\windows\system32\GPhotos.scr
2010-09-26 16:40 . 2010-09-27 21:38 -------- d-----w- e:\documents and settings\Andy\Local Settings\Application Data\photoOptimizeHistoryDataBase
2010-09-26 16:40 . 2010-09-27 21:38 -------- d-----w- e:\documents and settings\Andy\Local Settings\Application Data\Ashampoo Photo Optimizer 3
2010-09-26 15:49 . 2010-09-26 15:49 -------- d-----w- e:\documents and settings\Andy\Application Data\Ashampoo
2010-09-26 15:46 . 2010-09-26 15:46 -------- d-----w- e:\documents and settings\Andy\Local Settings\Application Data\ashampoo
2010-09-26 15:46 . 2010-09-26 15:46 -------- d-----w- e:\documents and settings\All Users\Application Data\ashampoo
2010-09-26 15:46 . 2010-09-26 16:40 -------- d-----w- e:\program files\Ashampoo
2010-09-24 17:28 . 2001-09-12 15:05 39520 ----a-w- e:\windows\system32\drivers\OPAPLPT.SYS
2010-09-24 17:28 . 2001-03-29 23:16 785 ----a-w- e:\windows\system32\OPAPLPT.DAT
2010-09-24 17:28 . 2010-09-24 17:28 -------- d-----w- e:\program files\Okidata
2010-09-23 20:52 . 2010-09-23 20:52 922112 -c----w- e:\windows\system32\dllcache\imapi2fs.dll
2010-09-23 20:52 . 2010-09-23 20:52 922112 ------w- e:\windows\system32\imapi2fs.dll
2010-09-23 20:52 . 2010-09-23 20:52 62592 -c----w- e:\windows\system32\dllcache\cdrom.sys
2010-09-23 20:52 . 2010-09-23 20:52 426496 -c----w- e:\windows\system32\dllcache\imapi2.dll
2010-09-23 20:52 . 2010-09-23 20:52 426496 ------w- e:\windows\system32\imapi2.dll
2010-09-22 02:37 . 2010-09-22 02:37 -------- d-----w- e:\program files\USB over Network (Server)
2010-09-22 02:37 . 2010-09-22 02:37 -------- d-----w- e:\program files\Common Files\FabulaTech
2010-09-18 23:11 . 2010-09-18 23:11 -------- d-----w- e:\documents and settings\All Users\Application Data\FLEXnet
2010-09-18 22:40 . 2010-09-18 22:40 -------- d-----w- e:\program files\Bonjour
2010-09-18 22:19 . 2010-09-18 22:19 -------- d-----w- e:\program files\Common Files\Macrovision Shared
2010-09-14 23:06 . 2010-09-14 23:06 -------- d-----w- e:\program files\MM-Exporter
2010-09-09 12:01 . 2010-09-09 12:02 -------- d-----w- e:\documents and settings\Andy\Application Data\MagiCut6
2010-09-09 11:58 . 2010-09-09 11:58 -------- d-----w- e:\documents and settings\All Users\Application Data\MagiCut
2010-09-09 11:58 . 2010-09-09 11:58 -------- d-----w- e:\program files\Common Files\Wintertree
2010-09-09 11:58 . 2010-09-09 11:58 -------- d-----w- e:\program files\MagiCut
2010-09-05 06:08 . 2010-09-05 12:47 -------- d-----w- e:\documents and settings\Andy\Application Data\SignGo
2010-09-05 06:08 . 2010-09-05 06:08 -------- d-----w- e:\program files\SignGo
2010-09-05 06:08 . 2010-09-05 06:08 -------- d-----w- e:\program files\Common Files\Wise Installation Wizard
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-04 20:40 . 2010-04-27 21:16 -------- d-----w- e:\documents and settings\Andy\Application Data\WTablet
2010-10-04 19:46 . 2010-06-10 08:18 -------- d---a-w- e:\documents and settings\All Users\Application Data\TEMP
2010-10-02 23:29 . 2010-06-10 08:19 -------- d-----w- e:\program files\Spyware Doctor
2010-09-29 16:13 . 2010-04-28 22:22 -------- d-----w- e:\program files\Java
2010-09-28 18:35 . 2010-04-11 08:52 -------- d-----w- e:\documents and settings\Andy\Application Data\Azureus
2010-09-27 21:31 . 2010-05-03 21:45 -------- d-----w- e:\program files\Common Files\Adobe AIR
2010-09-24 17:28 . 2010-03-28 13:33 -------- d--h--w- e:\program files\InstallShield Installation Information
2010-09-22 22:10 . 2010-04-06 23:02 3660 --sha-w- e:\documents and settings\All Users\Application Data\KGyGaAvL.sys
2010-09-22 22:10 . 2010-04-06 23:02 3660 --sha-w- e:\documents and settings\All Users\Application Data\KGyGaAvL.sys
2010-09-18 23:09 . 2010-03-28 16:59 67968 ----a-w- e:\documents and settings\Andy\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-09-18 22:39 . 2010-03-31 16:08 -------- d-----w- e:\program files\Common Files\Adobe
2010-08-29 20:49 . 2010-08-29 20:49 67968 ----a-w- e:\documents and settings\LocalService\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-08-29 20:39 . 2010-08-29 20:39 -------- d-----w- e:\program files\3CX PhoneSystem
2010-08-29 20:39 . 2010-08-29 20:39 -------- d-----w- e:\documents and settings\All Users\Application Data\3CX
2010-08-29 20:37 . 2010-08-29 20:37 -------- d-----w- e:\documents and settings\Andy\Application Data\Install
2010-08-29 14:49 . 2010-08-29 14:49 18281 ----a-w- e:\program files\irunin.ini
2010-08-29 14:48 . 2010-08-29 14:48 -------- d-----w- e:\program files\Visualtoolbox
2010-08-29 14:48 . 2010-08-29 14:49 8134 ----a-w- e:\program files\irunin.bmp
2010-08-29 14:48 . 2010-08-29 14:49 724992 ----a-w- e:\windows\iun6002.exe
2010-08-29 14:48 . 2010-08-29 14:49 215727 ----a-w- e:\program files\irunin.dat
2010-08-29 14:48 . 2010-08-29 14:49 15938 ----a-w- e:\program files\irunin.lng
2010-08-29 14:16 . 2010-08-29 14:16 -------- d-----w- e:\program files\SignMax
2010-08-28 21:41 . 2010-08-28 21:41 -------- d-----w- e:\program files\Windows Live Safety Center
2010-08-28 12:08 . 2010-08-28 12:08 -------- d-----w- e:\documents and settings\Andy\Application Data\DPA Software
2010-08-28 09:38 . 2010-08-28 09:38 -------- d-----w- e:\program files\Windows Defender
2010-08-27 21:17 . 2010-08-19 23:27 -------- d-----w- e:\documents and settings\Andy\Application Data\Audacity
2010-08-27 07:14 . 2010-08-06 23:10 -------- d-----w- e:\documents and settings\Andy\Application Data\Uniblue
2010-08-27 07:12 . 2010-08-27 07:12 -------- dc-h--w- e:\documents and settings\All Users\Application Data\{8A09CD83-59E1-4DB1-AAFC-E25174FC6706}
2010-08-27 07:12 . 2010-08-06 23:10 -------- d-----w- e:\program files\Uniblue
2010-08-26 10:40 . 2010-08-26 10:40 -------- d-----w- e:\program files\Common Files\PAP7501
2010-08-24 08:43 . 2010-08-24 08:43 -------- d-----w- e:\program files\Sysinternals Toolbox
2010-08-24 00:56 . 2010-08-24 00:56 -------- d-----w- e:\program files\Common Files\ActiveXperts
2010-08-24 00:56 . 2010-08-24 00:56 -------- d-----w- e:\program files\ActiveXperts
2010-08-22 19:52 . 2010-08-22 19:52 -------- d-----w- e:\documents and settings\NetworkService\Application Data\Vodafone
2010-08-22 19:51 . 2010-08-19 01:04 1534488 ----a-w- e:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2010-08-22 19:27 . 2010-03-28 13:35 46632 ----a-w- e:\windows\system32\drivers\l1e51x86.sys
2010-08-22 18:06 . 2007-07-20 17:40 101904 ----a-w- e:\windows\system32\drivers\AtiHdmi.sys
2010-08-22 01:03 . 2010-08-22 01:03 -------- d-----w- e:\program files\MyFree Codec
2010-08-22 01:00 . 2010-08-22 00:09 -------- d-----w- e:\documents and settings\Andy\Application Data\Sony
2010-08-22 00:59 . 2010-08-22 00:59 -------- d-----w- e:\documents and settings\Andy\Application Data\Publish Providers
2010-08-22 00:54 . 2010-08-22 00:54 -------- d-----w- e:\documents and settings\All Users\Application Data\Sony
2010-08-22 00:53 . 2010-08-22 00:01 -------- d-----w- e:\program files\Sony
2010-08-22 00:00 . 2010-08-22 00:00 -------- d-----w- e:\program files\Sony Setup
2010-08-21 23:43 . 2010-08-21 23:43 -------- d-----w- e:\program files\Fotosizer
2010-08-20 00:38 . 2010-08-19 00:40 -------- d-----w- e:\program files\Samsung
2010-08-19 23:30 . 2010-08-19 23:30 -------- d-----w- e:\documents and settings\Andy\Application Data\Free Sound Recorder
2010-08-19 23:30 . 2010-08-19 23:30 -------- d-----w- e:\program files\Free Sound Recorder
2010-08-19 23:27 . 2010-08-19 23:26 -------- d-----w- e:\program files\Audacity 1.3 Beta (Unicode)
2010-08-19 23:17 . 2010-08-19 23:17 -------- d-----w- e:\documents and settings\All Users\Application Data\PC Suite
2010-08-19 23:17 . 2010-08-19 23:17 -------- d-----w- e:\documents and settings\Andy\Application Data\PC Suite
2010-08-19 23:15 . 2010-04-15 10:52 -------- d-----w- e:\program files\PC Connectivity Solution
2010-08-19 23:14 . 2010-08-19 01:10 -------- d-----w- e:\documents and settings\Andy\Application Data\Samsung
2010-08-19 23:14 . 2010-08-19 01:09 -------- d-----w- e:\documents and settings\All Users\Application Data\Samsung
2010-08-19 23:14 . 2010-08-19 00:40 -------- d-----w- e:\program files\Common Files\Samsung
2010-08-19 21:13 . 2010-08-19 09:49 5632 ----a-w- e:\windows\system32\drivers\StarOpen.sys
2010-08-19 10:37 . 2010-08-19 09:58 -------- d-----w- e:\program files\Windows Media Connect 2
2010-08-19 01:09 . 2010-08-19 01:09 -------- d-----w- e:\program files\MarkAny
2010-08-19 01:03 . 2010-08-19 01:03 -------- d-----w- e:\program files\MSBuild
2010-08-19 01:03 . 2010-08-19 01:03 -------- d-----w- e:\program files\Reference Assemblies
2010-08-18 16:18 . 2010-08-19 21:23 52224 ----a-w- e:\documents and settings\Andy\Application Data\Mozilla\Firefox\Profiles\bcs0ufq5.Andy\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}\components\FFExternalAlert.dll
2010-08-18 16:18 . 2010-08-19 21:23 101376 ----a-w- e:\documents and settings\Andy\Application Data\Mozilla\Firefox\Profiles\bcs0ufq5.Andy\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}\components\RadioWMPCore.dll
2010-08-18 16:10 . 2010-08-19 21:23 52224 ----a-w- e:\documents and settings\Andy\Application Data\Mozilla\Firefox\Profiles\bcs0ufq5.Andy\extensions\{0fc85f5d-6207-4515-a490-45a549d285c0}\components\FFExternalAlert.dll
2010-08-18 16:10 . 2010-08-19 21:23 101376 ----a-w- e:\documents and settings\Andy\Application Data\Mozilla\Firefox\Profiles\bcs0ufq5.Andy\extensions\{0fc85f5d-6207-4515-a490-45a549d285c0}\components\RadioWMPCore.dll
2010-08-15 18:47 . 2010-08-15 18:47 -------- d-----w- e:\program files\3CXPhone
2010-08-15 17:14 . 2010-04-03 16:09 -------- d-----w- e:\program files\UltraVNC
2010-08-15 10:43 . 2010-08-26 10:56 69632 ----a-w- e:\documents and settings\Andy\Application Data\Mozilla\Firefox\Profiles\bcs0ufq5.Andy\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}\platform\WINNT\components\ColorZilla.dll
2010-08-14 15:16 . 2010-03-29 17:20 -------- d-----w- e:\program files\EPSON
2010-08-12 08:01 . 2010-08-19 21:23 57856 ----a-w- e:\documents and settings\Andy\Application Data\Mozilla\Firefox\Profiles\bcs0ufq5.Andy\extensions\{eecba28f-b68b-4b3a-b501-6ce12e6b8696}\platform\WINNT_x86-msvc\components\winprocess.dll
2010-08-11 16:07 . 2010-05-03 00:44 -------- d-----w- e:\program files\MagicISO
2010-08-10 18:21 . 2010-03-29 00:23 -------- d-----w- e:\program files\Microsoft ActiveSync
2010-08-08 11:53 . 2010-08-08 11:53 503808 ----a-w- e:\documents and settings\Andy\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-4c3a39b5-n\msvcp71.dll
2010-08-08 11:53 . 2010-08-08 11:53 499712 ----a-w- e:\documents and settings\Andy\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-4c3a39b5-n\jmc.dll
2010-08-08 11:53 . 2010-08-08 11:53 348160 ----a-w- e:\documents and settings\Andy\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-4c3a39b5-n\msvcr71.dll
2010-08-08 11:53 . 2010-08-08 11:53 61440 ----a-w- e:\documents and settings\Andy\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-360ae77d-n\decora-sse.dll
2010-08-08 11:53 . 2010-08-08 11:53 12800 ----a-w- e:\documents and settings\Andy\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-360ae77d-n\decora-d3d.dll
2010-08-07 23:28 . 2010-04-11 08:50 -------- d-----w- e:\program files\Vuze
2010-08-06 23:48 . 2010-08-06 23:48 5124000 ----a-w- e:\documents and settings\Andy\Application Data\Uniblue\RegistryBooster\_temp\ub.exe
2010-08-06 22:44 . 2010-08-06 22:44 -------- d-----w- e:\program files\MSECache
2010-08-06 22:31 . 2010-08-06 22:29 -------- d-----w- e:\program files\docXConverter3
2010-08-06 22:29 . 2010-08-02 00:01 135 ---ha-w- e:\documents and settings\Andy\Application Data\lakerda1967.sys
2010-08-06 22:29 . 2010-08-02 00:01 135 ---ha-w- e:\documents and settings\Andy\Application Data\lakerda1967.sys
2010-08-02 00:01 . 2010-08-02 00:01 360580 ----a-w- e:\windows\eSellerateEngine.dll
2010-07-28 11:56 . 2010-07-28 11:56 265528 ----a-w- e:\documents and settings\Andy\Application Data\Samsung\Kies\UpdateTemp\MCS.Thunder.Update.exe
2010-07-28 11:55 . 2010-07-28 11:55 4608 ----a-w- e:\documents and settings\Andy\Application Data\Samsung\Kies\UpdateTemp\en-GB\MCS.Thunder.Update.resources.dll
2010-07-28 11:55 . 2010-07-28 11:55 9728 ----a-w- e:\documents and settings\Andy\Application Data\Samsung\Kies\UpdateTemp\Interop.CmdAgentLib.dll
2010-07-28 11:49 . 2010-07-28 11:49 48128 ----a-w- e:\documents and settings\Andy\Application Data\Samsung\Kies\UpdateTemp\MSC.Thunder.Update.Util.dll
2010-07-28 11:49 . 2010-07-28 11:49 204288 ----a-w- e:\documents and settings\Andy\Application Data\Samsung\Kies\UpdateTemp\CabLib.dll
2010-07-28 11:49 . 2010-07-28 11:49 6656 ----a-w- e:\documents and settings\Andy\Application Data\Samsung\Kies\UpdateTemp\MSC.Thunder.UAC.dll
2010-07-28 11:49 . 2010-07-28 11:49 12288 ----a-w- e:\documents and settings\Andy\Application Data\Samsung\Kies\UpdateTemp\AdminCmdAgent.dll
2010-07-21 03:19 . 2010-06-10 08:22 767928 ----a-w- e:\windows\BDTSupport.dll
2010-07-19 10:46 . 2010-07-19 10:46 68696 ----a-w- e:\documents and settings\All Users\Application Data\3CX\Data\Http\Interface\bin\TcxTheme.dll
2010-07-19 10:46 . 2010-07-19 10:46 68696 ----a-w- e:\documents and settings\All Users\Application Data\3CX\Data\Http\Interface\myPhone\bin\TcxTheme.dll
2010-07-19 10:46 . 2010-07-19 10:46 330840 ----a-w- e:\documents and settings\All Users\Application Data\3CX\Data\Http\Interface\myPhone\bin\myPhoneInterface.dll
2010-07-19 10:46 . 2010-07-19 10:46 40024 ----a-w- e:\windows\system32\3CXInstallationChecker.exe
2010-07-19 10:46 . 2010-07-19 10:46 1563736 ----a-w- e:\documents and settings\All Users\Application Data\3CX\Data\Http\Interface\bin\WebGuiInterface.dll
2010-07-19 10:46 . 2010-07-19 10:46 27736 ----a-w- e:\documents and settings\All Users\Application Data\3CX\Data\Http\Interface\myPhone\bin\VBMutils.dll
2010-07-19 10:46 . 2010-07-19 10:46 64600 ----a-w- e:\documents and settings\All Users\Application Data\3CX\Data\Http\Interface\ivr\bin\3cxIvr.dll
2010-07-17 04:00 . 2010-04-28 22:22 423656 ----a-w- e:\windows\system32\deployJava1.dll
2008-11-18 19:44 . 2010-03-28 16:57 2453504 ----a-w- e:\program files\UltraMon_3.0.3_en_x32.msi
.
------- Sigcheck -------
[-] 2009-09-20 . 68F06FE0021B01E670AF37B8C5964FDF . 361344 . . [5.1.2600.5512] . . e:\windows\system32\drivers\tcpip.sys
[-] 2009-09-20 . AB9E8F44D2F80A8060BEFB29192F4249 . 1614848 . . [5.1.2600.5512] . . e:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{ba14329e-9550-4989-b3f2-9732e92d17cc}"= "e:\program files\Vuze_Remote\tbVuz1.dll" [2010-05-20 2515552]
[HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
2010-05-20 23:43 2515552 ----a-w- e:\program files\Vuze_Remote\tbVuz1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{ba14329e-9550-4989-b3f2-9732e92d17cc}"= "e:\program files\Vuze_Remote\tbVuz1.dll" [2010-05-20 2515552]
[HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{BA14329E-9550-4989-B3F2-9732E92D17CC}"= "e:\program files\Vuze_Remote\tbVuz1.dll" [2010-05-20 2515552]
[HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SandboxieControl"="e:\program files\Sandboxie\SbieCtrl.exe" [2010-07-04 398568]
"MsnMsgr"="e:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"SpeedUpMyPC"="e:\program files\Uniblue\SpeedUpMyPC\launcher.exe" [2010-06-25 67960]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2009-05-21 17881600]
"egui"="e:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-02-20 1443072]
"Malwarebytes' Anti-Malware"="e:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2010-03-29 437584]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"BtTray"="e:\program files\IVT Corporation\BlueSoleil\BtTray.exe" [2010-03-08 319574]
"SwitchBoard"="e:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2009-12-14 515560]
"LiveZilla"="e:\program files\LiveZilla\LiveZilla.exe" [2010-05-17 2651576]
"VMSnap3"="e:\windows\VMSnap3.exe" [2006-07-18 49152]
"PACTray"="e:\windows\PixArt\PAP7501\PACTray.exe" [2009-07-10 319488]
"Windows Defender"="e:\program files\Windows Defender\MSASCui.exe" [2006-11-03 866584]
"SunJavaUpdateSched"="e:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="e:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"_nltide_3"="advpack.dll" [2008-04-14 99840]
e:\documents and settings\Andy\Start Menu\Programs\Startup\
MagicDisc.lnk - e:\program files\MagicDisc\MagicDisc.exe [2010-5-3 576000]
Vista & XP Virtual Desktops.lnk - e:\documents and settings\Andy\Application Data\Microsoft\Installer\{F4735C64-9A74-4E48-894B-1CA5D83B99C8}\MainIcon.ico [2010-5-9 106023]
e:\documents and settings\All Users\Start Menu\Programs\Startup\
NETGEAR WG111v3 Smart Wizard.lnk - e:\program files\NETGEAR\WG111v3\WG111v3.exe [2009-12-23 2330624]
SATARaid.lnk - e:\windows\Installer\{D28ED536-CCD0-4F38-987C-A57177371172}\_F7A06503601447F2BE72B0.exe [2010-7-22 1078]
UltraMon.lnk - e:\windows\Installer\{CC15A5FC-B6D3-4A2D-8A26-D8F2702A3C00}\IcoUltraMon.ico [2010-5-8 29310]
e:\documents and settings\All Users\Start Menu\Programs\Startup\AutorunsDisabled
McAfee Security Scan Plus.lnk - e:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"FolderControl"= a9bb7b60-9ddd-428b-b704-836f2820c57e - e:\program files\Common Files\FolderControl\FolderControl.dll [2010-04-19 122880]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"e:\\Mailtraq back up march2010\\mailtraq.exe"=
"e:\\Program Files\\UltraVNC\\winvnc.exe"=
"e:\\Program Files\\UltraVNC\\vncviewer.exe"=
"e:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleilCS.exe"=
"e:\program files\Microsoft ActiveSync\rapimgr.exe"= e:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"e:\program files\Microsoft ActiveSync\wcescomm.exe"= e:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"e:\program files\Microsoft ActiveSync\WCESMgr.exe"= e:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"e:\\Program Files\\Messenger\\msmsgs.exe"=
"e:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"e:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"e:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"e:\\Program Files\\Vuze\\Azureus.exe"=
"e:\\Program Files\\3CXPhone\\3CXPhone.exe"=
"e:\\Program Files\\3CX PhoneSystem\\Bin\\Assistant\\3CXAssistantServer.exe"=
"e:\\Program Files\\3CX PhoneSystem\\Bin\\3CXMediaServer.exe"=
"e:\\Program Files\\3CX PhoneSystem\\Bin\\3CXTunnel.exe"=
"e:\\Program Files\\3CX PhoneSystem\\Bin\\3CXPhoneSystem.exe"=
"e:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"e:\\WINDOWS\\system32\\ftusbsrv.exe"=
"e:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=
"e:\\Program Files\\TeamViewer\\Version5\\TeamViewer.exe"=
"e:\\Program Files\\TeamViewer\\Version5\\TeamViewer_Service.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5900:TCP"= 5900:TCP:vnc5900
"5800:TCP"= 5800:TCP:vnc5800
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"5481:TCP"= 5481:TCP:3CX Phone System Abyss Web Server
"5486:UDP"= 5486:UDP:3CX Assistant Service
R0 BtHidBus;Bluetooth HID Bus Service;e:\windows\system32\drivers\BtHidBus.sys [1/7/2009 11:39 PM 19592]
R0 iteraid;ITERAID_Service_Install;e:\windows\system32\drivers\iteraid.sys [7/31/2010 12:29 AM 24539]
R0 PCTCore;PCTools KDS;e:\windows\system32\drivers\PCTCore.sys [6/10/2010 9:20 AM 218592]
R2 WinDefend;Windows Defender;e:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
R3 ftusbload;ftusbload;e:\windows\system32\drivers\ftusbload.sys [12/1/2009 1:58 PM 37880]
S1 epfwtdir;epfwtdir;e:\windows\system32\drivers\epfwtdir.sys [2/20/2008 11:11 AM 33800]
S2 3CX PhoneSystem Database Server;3CX PhoneSystem Database Server;E:/Program Files/3CX PhoneSystem/Bin/pgsql/bin/pg_ctl.exe runservice -N "3CX PhoneSystem Database Server" -D "E:/Program Files/3CX PhoneSystem/Data/DB" --> E:/Program Files/3CX PhoneSystem/Bin/pgsql/bin/pg_ctl.exe runservice -N 3CX PhoneSystem Database Server [?]
S2 3CXAssistantServer;3CX PhoneSystem Assistant Server;e:\program files\3CX PhoneSystem\Bin\Assistant\3CXAssistantServer.exe [7/19/2010 11:46 AM 565848]
S2 3CXCallHistoryService;3CX PhoneSystem Call History;e:\program files\3CX PhoneSystem\Bin\3CXCallHistoryService.exe [7/19/2010 11:46 AM 31832]
S2 3CXCfgServ;3CX PhoneSystem Configuration Service;e:\program files\3CX PhoneSystem\Bin\3CXSLDBServ.exe [7/19/2010 11:46 AM 666712]
S2 3CXConferenceRoom;3CX PhoneSystem Conference Room;e:\program files\3CX PhoneSystem\Bin\3CXCP.exe [7/19/2010 11:46 AM 2251864]
S2 3CXFAXSrv;3CX PhoneSystem FAX Server;e:\program files\3CX PhoneSystem\Bin\3CXFaxServer.exe [7/19/2010 11:46 AM 2948184]
S2 3CXIvr;3CX PhoneSystem Digital Receptionist;e:\program files\3CX PhoneSystem\Bin\3CXIvrServer.exe [7/19/2010 11:46 AM 3751000]
S2 3CXMediaServer;3CX PhoneSystem Media Server;e:\program files\3CX PhoneSystem\Bin\3CXMediaServer.exe [7/19/2010 11:46 AM 1248344]
S2 3CXParkOrbit;3CX PhoneSystem Parking Orbit;e:\program files\3CX PhoneSystem\Bin\3CXPO.exe [7/19/2010 11:46 AM 2202712]
S2 3CXPhoneSystem;3CX PhoneSystem;e:\program files\3CX PhoneSystem\Bin\3CXPhoneSystem.exe [7/19/2010 11:46 AM 3927128]
S2 3CXQueueManager;3CX PhoneSystem Queue Manager;e:\program files\3CX PhoneSystem\Bin\VCEHost.exe [6/25/2010 11:16 PM 2166784]
S2 3CXTunnel;3CX PhoneSystem SIP/RTP Tunneling Proxy;e:\program files\3CX PhoneSystem\Bin\3CXTunnel.exe [7/19/2010 11:46 AM 1432664]
S2 3CXVBoxMgr;3CX PhoneSystem Voicemail Manager;e:\program files\3CX PhoneSystem\Bin\3CXVoiceMailScanner.exe [7/19/2010 11:46 AM 35928]
S2 AbyssWebServer;Abyss Web Server;e:\program files\3CX PhoneSystem\Bin\Webserver\abyssws.exe [5/21/2010 12:01 AM 535102]
S2 Browser Defender Update Service;Browser Defender Update Service;e:\program files\Spyware Doctor\BDT\BDTUpdateService.exe [6/10/2010 9:22 AM 112592]
S2 BsMobileCS;BsMobileCS;e:\program files\IVT Corporation\BlueSoleil\BsMobileCS.exe [3/9/2010 4:57 PM 143467]
S2 dgdersvc;Device Error Recovery Service;e:\windows\system32\dgdersvc.exe [5/1/2010 7:50 AM 95568]
S2 EAPPkt;Realtek EAPPkt Protocol;e:\windows\system32\drivers\EAPPkt.sys [10/9/2007 1:13 PM 38144]
S2 ekrn;Eset Service;e:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2/20/2008 11:08 AM 472320]
S2 FsUsbExService;FsUsbExService;e:\windows\system32\FsUsbExService.Exe [8/19/2010 2:14 AM 217088]
S2 ftusbsrv;USB over Network (Server) service;e:\windows\system32\ftusbsrv.exe [12/1/2009 1:59 PM 1384448]
S2 MBAMService;MBAMService;e:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [3/28/2010 8:17 PM 303952]
S2 NOD32FiXTemDono;Eset Nod32 Boot;e:\windows\system32\regedt32.exe [4/14/2008 1:00 PM 3584]
S2 TabletServiceWacom;TabletServiceWacom;e:\windows\system32\Wacom_Tablet.exe [4/27/2010 10:15 PM 5010288]
S2 TeamViewer5;TeamViewer 5;e:\program files\TeamViewer\Version5\TeamViewer_Service.exe [3/18/2010 10:26 AM 1960744]
S2 UltraMonUtility;UltraMon Utility Driver;e:\program files\Common Files\Realtime Soft\UltraMonMirrorDrv\x32\UltraMonUtility.sys [9/14/2008 5:32 PM 10496]
S2 Uniblue DiskRescue;Uniblue DiskRescue;e:\program files\Uniblue\DiskRescue\UBDiskRescueSrv.exe [9/10/2008 4:22 PM 229648]
S2 uvnc_service;uvnc_service;e:\program files\UltraVNC\winvnc.exe [4/3/2010 5:09 PM 1590216]
S2 VMCService;Vodafone Mobile Connect Service;e:\program files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe [3/13/2008 7:08 PM 24576]
S3 Ambfilt;Ambfilt;e:\windows\system32\drivers\Ambfilt.sys [3/28/2010 5:20 PM 1684736]
S3 btnetBUs;Bluetooth PAN Bus Service;e:\windows\system32\drivers\btnetBus.sys [12/7/2008 12:44 PM 29192]
S3 CH341SER;CH341SER;e:\windows\system32\drivers\CH341SER.SYS [4/1/2010 12:01 PM 39632]
S3 dgderdrv;dgderdrv;e:\windows\system32\drivers\dgderdrv.sys [5/1/2010 7:50 AM 18136]
S3 FsUsbExDisk;FsUsbExDisk;e:\windows\system32\FsUsbExDisk.Sys [8/19/2010 2:14 AM 36640]
S3 ftusb;ftusb;e:\windows\system32\drivers\ftusb.sys [12/1/2009 1:58 PM 17400]
S3 GUCI_AVS;Generic USB Controller Interface (AVS);e:\windows\system32\drivers\GUCI_AVS.sys [8/26/2010 11:40 AM 543616]
S3 IvtBtBUs;IVT Bluetooth Bus Service;e:\windows\system32\drivers\IvtBtBus.sys [7/2/2008 2:58 PM 25480]
S3 KiesAllShare;SAMSUNG KiesAllShare Service;e:\program files\Samsung\Kies\WiselinkPro\WiselinkPro.exe [5/4/2010 3:33 AM 9241088]
S3 MBAMProtector;MBAMProtector;e:\windows\system32\drivers\mbam.sys [3/28/2010 8:17 PM 20824]
S3 McComponentHostService;McAfee Security Scan Component Host Service;e:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [1/15/2010 1:49 PM 227232]
S3 mv2;mv2;e:\windows\system32\drivers\mv2.sys [4/3/2010 5:09 PM 10688]
S3 RTL8187B;NETGEAR WG111v3 Wireless-G USB Adapter Vista Driver;e:\windows\system32\drivers\wg111v3.sys [7/31/2009 3:12 PM 341504]
S3 sdAuxService;PC Tools Auxiliary Service;e:\program files\Spyware Doctor\pctsAuxs.exe [6/10/2010 9:19 AM 366840]
S3 ss_bbus;SAMSUNG USB Mobile Device (WDM);e:\windows\system32\drivers\ss_bbus.sys [8/21/2010 7:59 PM 98432]
S3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);e:\windows\system32\drivers\ss_bmdfl.sys [8/21/2010 7:59 PM 14848]
S3 ss_bmdm;SAMSUNG USB Mobile Modem;e:\windows\system32\drivers\ss_bmdm.sys [8/21/2010 7:59 PM 123648]
S3 ss_bserd;SAMSUNG USB Mobile Logging Driver;e:\windows\system32\drivers\ss_bserd.sys [8/21/2010 7:59 PM 100224]
S3 SwitchBoard;SwitchBoard;e:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [12/15/2009 12:43 AM 515560]
S3 teamviewervpn;TeamViewer VPN Adapter;e:\windows\system32\drivers\teamviewervpn.sys [3/11/2010 10:17 AM 25088]
S3 vvftav303;vvftav303;e:\windows\system32\drivers\vvftav303.sys [7/7/2010 11:18 PM 475136]
S3 wacmoumonitor;Wacom Mode Helper;e:\windows\system32\drivers\wacmoumonitor.sys [4/27/2010 10:15 PM 16168]
S3 ZSMC0303;VIMICRO USB PC Camera (ZC0301PLH);e:\windows\system32\drivers\usbVM303.sys [7/7/2010 11:18 PM 1474560]
.
Contents of the 'Scheduled Tasks' folder
2010-08-24 e:\windows\Tasks\AdobeAAMUpdater-1.0-FRONTROOM-Andy.job
- e:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2010-05-03 02:44]
2010-08-24 e:\windows\Tasks\AppleSoftwareUpdate.job
- e:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2010-10-04 e:\windows\Tasks\MP Scheduled Scan.job
- e:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]
2010-10-04 e:\windows\Tasks\RegistryBooster.job
- e:\program files\Uniblue\RegistryBooster\rbmonitor.exe [2010-08-06 07:03]
2010-08-27 e:\windows\Tasks\Uniblue DiskRescue 2009.job
- e:\program files\Uniblue\DiskRescue\UBDiskRescue.exe [2008-09-10 15:22]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.co.uk/
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://www.pctools.com/mrc/fix_homepage/
uInternet Connection Wizard,ShellNext = hxxp://ati.amd.com/online/cccwelcome/registration.asp?id=1
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - e:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: {CDDE1C31-4831-453D-8E95-3DF8CAE582CA} = 194.168.4.100,194.168.8.100
FF - ProfilePath - e:\documents and settings\Andy\Application Data\Mozilla\Firefox\Profiles\bcs0ufq5.Andy\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2405725&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Radio Bar 1 Customized Web Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
FF - prefs.js: keyword.URL - hxxp://supertoolbar.ask.com/redirect?client=ff&src=kw&tb=PF&o=15176&locale=en_UK&q=
FF - component: e:\documents and settings\Andy\Application Data\Mozilla\Firefox\Profiles\bcs0ufq5.Andy\extensions\{0fc85f5d-6207-4515-a490-45a549d285c0}\components\FFExternalAlert.dll
FF - component: e:\documents and settings\Andy\Application Data\Mozilla\Firefox\Profiles\bcs0ufq5.Andy\extensions\{0fc85f5d-6207-4515-a490-45a549d285c0}\components\RadioWMPCore.dll
FF - component: e:\documents and settings\Andy\Application Data\Mozilla\Firefox\Profiles\bcs0ufq5.Andy\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}\platform\WINNT\components\ColorZilla.dll
FF - component: e:\documents and settings\Andy\Application Data\Mozilla\Firefox\Profiles\bcs0ufq5.Andy\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\components\ipc_fireftp.dll
FF - component: e:\documents and settings\Andy\Application Data\Mozilla\Firefox\Profiles\bcs0ufq5.Andy\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}\components\FFExternalAlert.dll
FF - component: e:\documents and settings\Andy\Application Data\Mozilla\Firefox\Profiles\bcs0ufq5.Andy\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}\components\RadioWMPCore.dll
FF - component: e:\documents and settings\Andy\Application Data\Mozilla\Firefox\Profiles\bcs0ufq5.Andy\extensions\{eecba28f-b68b-4b3a-b501-6ce12e6b8696}\platform\WINNT_x86-msvc\components\winprocess.dll
FF - component: e:\program files\Adobe\Adobe Contribute CS5\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}\components\Contribute.dll
FF - plugin: e:\documents and settings\Andy\Application Data\Facebook\npfbplugin_1_0_3.dll
FF - plugin: e:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: e:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: e:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: e:\program files\Mozilla Firefox\plugins\npContribute.dll
FF - plugin: e:\program files\TabletPlugins\npwacom.dll
FF - plugin: e:\program files\Windows Live\Photo Gallery\NPWLPG.dll
---- FIREFOX POLICIES ----
e:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
e:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
e:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-KiesTrayAgent - (no file)
HKLM-Run-GUCI_AVS - e:\windows\PixArt\PAP7501\GUCI_AVS.exe
HKLM-Run-PAP7501_Monitor - e:\windows\PixArt\PAP7501\GUCI_AVS.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-10-04 21:58
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\3CX PhoneSystem Database Server]
"ImagePath"="E:/Program Files/3CX PhoneSystem/Bin/pgsql/bin/pg_ctl.exe runservice -N \"3CX PhoneSystem Database Server\" -D \"E:/Program Files/3CX PhoneSystem/Data/DB\""
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\3CX PhoneSystem Database Server]
"ImagePath"="E:/Program Files/3CX PhoneSystem/Bin/pgsql/bin/pg_ctl.exe runservice -N \"3CX PhoneSystem Database Server\" -D \"E:/Program Files/3CX PhoneSystem/Data/DB\""
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1202660629-1214440339-1177238915-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*e%$*%]
@Class="Shell"
[HKEY_USERS\S-1-5-21-1202660629-1214440339-1177238915-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*e%$*%\OpenWithList]
@Class="Shell"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@e:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10e_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="e:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10e_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(272)
e:\windows\system32\Ati2evxx.dll
e:\windows\system32\atiadlxx.dll
.
Completion time: 2010-10-04 22:01:54
ComboFix-quarantined-files.txt 2010-10-04 21:01
Pre-Run: 132,906,455,040 bytes free
Post-Run: 132,867,981,312 bytes free
- - End Of File - - 8895AD5905C2F39A058C875124F2A7C2