the computer appears to be a little more responcive
ComboFix 09-07-13.01 - user 07/14/2009 16:09.1.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2038.1294 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: CA Anti-Virus *On-access scanning disabled* (Updated) {17CFD1EA-56CF-40B5-A06B-BD3A27397C93}
FW: CA Personal Firewall *enabled* {14CB4B80-8E52-45EA-905E-67C1267B4160}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\recycler\S-1-5-21-1381983311-504644025-3442226889-1004
c:\recycler\S-1-5-21-1417001333-583907252-682003330-500
c:\windows\COUPON~1.OCX
c:\windows\CouponPrinter.ocx
c:\windows\Installer\12bd8ba6.msi
.
((((((((((((((((((((((((( Files Created from 2009-06-14 to 2009-07-14 )))))))))))))))))))))))))))))))
.
2009-07-14 14:15 . 2009-07-14 14:15 ——– d—–w- c:\documents and settings\user\Application Data\Malwarebytes
2009-07-14 14:15 . 2009-07-13 18:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-14 14:15 . 2009-07-14 14:15 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-07-14 14:15 . 2009-07-13 18:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-07-14 14:15 . 2009-07-14 14:15 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-07-14 13:00 . 2009-07-14 13:00 ——– d—–w- C:\_OTL
2009-07-14 01:46 . 2009-07-14 01:46 ——– d—–w- c:\program files\Trend Micro
2009-06-30 22:07 . 2009-06-30 22:07 53248 —-a-w- c:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\ASP43.tmp\aspapp\sunsetAsp2.exe
2009-06-19 16:00 . 2009-06-19 16:00 53248 —-a-w- c:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\ASP2AD.tmp\aspapp\sunsetAsp2.exe
2009-06-19 15:58 . 2006-10-12 16:29 83504 —-a-w- c:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\TEMP\ProgUpd.dll
2009-06-17 01:54 . 2009-06-17 01:54 ——– d—–w- c:\program files\AOL Toolbar
2009-06-17 01:52 . 2009-06-17 01:52 ——– d—–w- c:\windows\aolshare
2009-06-17 01:52 . 2009-06-21 14:30 ——– d—–w- c:\program files\AOL 9.1a
2009-06-17 00:41 . 2009-06-17 00:41 ——– d—–w- c:\program files\AOL 9.1
2009-06-17 00:35 . 2009-06-17 00:35 ——– d—–w- c:\documents and settings\user\Local Settings\Application Data\toaster
2009-06-17 00:26 . 2009-06-17 01:55 ——– d—–w- c:\program files\Common Files\aolshare
2009-06-17 00:24 . 2009-06-17 00:24 99200 —-a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\waol\0.4334.34.14\comps\sm\sminstlp.exe
2009-06-17 00:24 . 2009-06-17 00:24 1895720 —-a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\waol\0.4334.34.14\waol-0.4334.34.14.exe
2009-06-17 00:24 . 2009-06-17 00:24 142040 —-a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\waol\0.4334.34.14\comps\aolload\alsetup.exe
2009-06-17 00:22 . 2009-06-17 00:22 359184 —-a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\waol\0.4334.34.14\comps\tb\tbsetup.exe
2009-06-17 00:22 . 2009-06-17 00:22 75104 —-a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\waol\0.4334.34.14\comps\ocp\instSup.dll
2009-06-17 00:22 . 2009-06-17 00:22 223152 —-a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\waol\0.4334.34.14\comps\afix\wsfinst.exe
2009-06-17 00:22 . 2009-06-17 00:22 175224 —-a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\waol\0.4334.34.14\comps\sm\stmninst.exe
2009-06-17 00:22 . 2009-06-17 00:22 1475416 —-a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\waol\0.4334.34.14\comps\ocp\ocpinst.exe
2009-06-17 00:22 . 2009-06-17 00:22 15712 —-a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\waol\0.4334.34.14\comps\ocp\ocpchk.dll
2009-06-17 00:21 . 2009-06-17 00:22 390704 —-a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\waol\0.4334.34.14\comps\afix\WinsockFix.exe
2009-06-17 00:21 . 2009-06-17 00:21 ——– d—–w- c:\documents and settings\All Users\Application Data\AOL Downloads
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-14 18:29 . 2008-12-06 04:53 ——– d—–w- c:\documents and settings\user\Application Data\CallingID
2009-07-14 12:59 . 2007-05-17 23:08 ——– d—–w- c:\program files\Microsoft Money
2009-07-14 02:47 . 2008-05-07 20:00 ——– d—–w- c:\documents and settings\user\Application Data\Canon
2009-07-14 01:28 . 2009-03-17 03:28 ——– d—–w- c:\documents and settings\All Users\Application Data\Google Updater
2009-07-12 22:24 . 2007-05-21 16:15 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-06-30 22:10 . 2008-11-12 01:27 541696 —-a-w- c:\documents and settings\user\Application Data\SanDisk\Sansa Updater\SansaUpdater.exe
2009-06-30 22:05 . 2008-07-18 16:08 ——– d—–w- c:\documents and settings\user\Application Data\Amazon
2009-06-30 22:03 . 2008-07-18 16:05 ——– d—–w- c:\program files\Amazon
2009-06-30 21:59 . 2008-11-12 01:28 79872 —-a-w- c:\documents and settings\user\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe
2009-06-20 11:19 . 2007-05-17 23:13 ——– d—–w- c:\program files\Common Files\AOL
2009-06-19 15:39 . 2007-05-17 23:17 ——– d—–w- c:\documents and settings\user\Application Data\AOL
2009-06-17 01:56 . 2007-05-17 23:14 ——– d—–w- c:\documents and settings\All Users\Application Data\AOL
2009-06-17 00:24 . 2009-06-17 00:23 8139800 —-a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\waol\0.4334.34.14\comps\acs\acssetup.exe
2009-06-16 22:30 . 2007-05-17 23:14 ——– d—–w- c:\program files\Pure Networks
2009-06-16 22:16 . 2008-03-05 01:11 ——– d—–w- c:\documents and settings\All Users\Application Data\Napster
2009-06-16 22:16 . 2005-12-27 16:00 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-06-12 02:37 . 2008-05-12 20:30 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-06-10 16:45 . 2009-03-31 23:00 ——– d—–w- c:\program files\Java
2009-06-10 16:44 . 2009-06-10 13:27 152576 —-a-w- c:\documents and settings\user\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-06-08 18:49 . 2009-06-07 13:35 ——– d—–w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2009-06-07 13:35 . 2009-06-07 13:35 ——– d—–w- c:\program files\Yahoo!
2009-06-07 13:35 . 2009-06-07 13:35 ——– d—–w- c:\documents and settings\user\Application Data\Yahoo!
2009-05-23 00:16 . 2006-12-27 14:19 38784 —-a-w- c:\documents and settings\user\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-21 16:33 . 2008-11-23 13:05 410984 —-a-w- c:\windows\system32\deploytk.dll
2009-05-20 14:41 . 2009-05-20 14:41 ——– d—–w- c:\program files\MSBuild
2009-05-20 14:41 . 2009-05-20 14:41 ——– d—–w- c:\program files\Reference Assemblies
2009-05-20 14:00 . 2007-05-17 23:02 ——– d—–w- c:\program files\Microsoft Works
2009-05-18 08:04 . 2009-03-17 03:28 ——– d—–w- c:\program files\Google
2009-05-13 05:15 . 2006-06-23 19:33 915456 —-a-w- c:\windows\system32\wininet.dll
2009-05-07 15:32 . 2003-07-16 16:26 345600 —-a-w- c:\windows\system32\localspl.dll
2009-04-17 12:26 . 2003-07-16 16:45 1847168 —-a-w- c:\windows\system32\win32k.sys
2001-06-20 21:19 . 2001-06-19 21:34 40960 —-a-w- c:\program files\ACMonitor_X83.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SansaDispatch"="c:\documents and settings\user\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe" [2009-06-30 79872]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"AOL Fast Start"="c:\program files\AOL 9.1a\AOL.EXE" [2008-11-06 50472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"KernelFaultCheck"="c:\windows\system32\dumprep 0 -k" [X]
"igfxtray"="c:\windows\System32\igfxtray.exe" [2005-09-20 94208]
"igfxhkcmd"="c:\windows\System32\hkcmd.exe" [2005-09-20 77824]
"igfxpers"="c:\windows\System32\igfxpers.exe" [2005-09-20 114688]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 1404928]
"MoneyStartUp10.0"="c:\program files\Microsoft Money\System\Activation.exe" [2001-07-25 241714]
"AOLDialer"="c:\program files\Common Files\AOL\ACS\AOLDial.exe" [2006-10-23 71216]
"cctray"="c:\program files\CA\CA Internet Security Suite\casc.exe" [2009-03-01 374000]
"CAVRID"="c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe" [2009-03-01 271600]
"QD FastAndSafe"="c:\progra~1\NORTON~1\QDCSFS.exe" [1999-04-15 28672]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-09-28 185896]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe" [2006-10-11 75304]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-10-31 413696]
"CAPPActiveProtection"="c:\program files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe" [2009-03-01 324848]
"capfasem"="c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe" [2009-03-05 636144]
"capfupgrade"="c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe" [2009-03-05 337136]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-01-21 185872]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"Microsoft Works Update Detection"="c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2001-08-17 28738]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-21 148888]
"HostManager"="c:\program files\Common Files\AOL\1245198878\ee\AOLSoftware.exe" [2008-06-24 41824]
"SMSERIAL"="sm56hlpr.exe" - c:\windows\sm56hlpr.exe [2006-11-04 544768]
c:\documents and settings\user\Start Menu\Programs\Startup\
Webshots.lnk - c:\program files\Webshots\Launcher.exe [2007-5-18 45056]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Works Calendar Reminders.lnk.disabled [2007-5-17 875]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"EnableShellExecuteHooks"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{1869181A-9F50-4FCF-8BFF-1B8588ECB85C}"= "c:\program files\CA\CA Internet Security Suite\CA Website Inspector\LinkAdvisor\CIDLinkAdvisor.dll" [2008-12-14 1376256]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PFW]
2007-06-06 22:46 79368 —-a-w- c:\windows\system32\UmxWNP.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=UmxSbxExw.dll
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"SpybotSD TeaTimer"=c:\program files\Spybot - Search & Destroy\TeaTimer.exe
"ctfmon.exe"=c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"RealTray"=c:\program files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
"NapsterShell"=c:\program files\Napster\napster.exe /systray
"WorksFUD"=c:\program files\Microsoft Works\wkfud.exe
"Microsoft Works Portfolio"=c:\program files\Microsoft Works\WksSb.exe /AllUsers
"NeroCheck"=c:\windows\System32\\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\CA Personal Firewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\fxsclnt.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\Common Files\\AOL\\acs\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\acs\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\AOL\\1245198878\\ee\\aolsoftware.exe"=
"c:\\Program Files\\AOL 9.1a\\waol.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
R0 KmxStart;KmxStart;c:\windows\system32\drivers\KmxStart.sys [1/9/2009 5:25 PM 107512]
R1 KmxAgent;KmxAgent;c:\windows\system32\drivers\KmxAgent.sys [1/9/2009 5:25 PM 72696]
R1 KmxFile;KmxFile;c:\windows\system32\drivers\KmxFile.sys [8/25/2008 4:18 PM 52728]
R1 KmxFw;KmxFw;c:\windows\system32\drivers\KmxFw.sys [1/9/2009 5:25 PM 115704]
R2 ccSchedulerSVC;CA Common Scheduler Service;c:\program files\CA\CA Internet Security Suite\ccschedulersvc.exe [12/5/2008 11:47 PM 128240]
R2 IntuitUpdateService;Intuit Update Service;c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe [10/10/2008 6:45 AM 13088]
R2 KmxCF;KmxCF;c:\windows\system32\drivers\KmxCF.sys [1/9/2009 5:25 PM 144376]
R2 KmxSbx;KmxSbx;c:\windows\system32\drivers\KmxSbx.sys [7/30/2008 2:38 PM 58872]
R2 UmxAgent;HIPS Event Manager;c:\program files\CA\SharedComponents\HIPSEngine\UmxAgent.exe [1/9/2009 5:25 PM 1153528]
R2 UmxCfg;HIPS Configuration Interpreter;c:\program files\CA\SharedComponents\HIPSEngine\UmxCfg.exe [1/9/2009 5:25 PM 797176]
R2 UmxPol;HIPS Policy Manager;c:\program files\CA\SharedComponents\HIPSEngine\UmxPol.exe [9/2/2008 2:53 PM 289272]
R3 KmxCfg;KmxCfg;c:\windows\system32\drivers\KmxCfg.sys [1/9/2009 5:25 PM 205304]
R3 PPCtlPriv;PPCtlPriv;c:\program files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe [12/5/2008 11:47 PM 222448]
S2 BulkUsb;Genesys Logic USB Scanner Controller NT 5.0;c:\windows\system32\drivers\usbscan.sys [5/17/2007 8:45 PM 15104]
S2 gupdate1c9a6b0afb47928;Google Update Service (gupdate1c9a6b0afb47928);c:\program files\Google\Update\GoogleUpdate.exe [3/16/2009 10:30 PM 133104]
S3 ASTRA32;ASTRA32;c:\windows\system32\drivers\astra32.sys [12/27/2005 1:48 PM 24544]
— Other Services/Drivers In Memory —
*NewlyCreated* - MBAMSWISSARMY
*Deregistered* - MBAMSwissArmy
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-07-14 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-17 12:37]
2009-07-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-17 03:29]
2009-07-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-17 03:29]
2009-02-18 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SpybotSD.exe [2008-08-08 19:45]
2009-07-14 c:\windows\Tasks\User_Feed_Synchronization-{05083F62-BD28-404E-A477-15783C3B39D1}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 09:31]
.
- - - - ORPHANS REMOVED - - - -
URLSearchHooks-{9ee802e8-c931-47ab-b570-aa8f791598ca} - c:\program files\eMusic\tbeMu0.dll
BHO-{9ee802e8-c931-47ab-b570-aa8f791598ca} - c:\program files\eMusic\tbeMu0.dll
Toolbar-{9ee802e8-c931-47ab-b570-aa8f791598ca} - c:\program files\eMusic\tbeMu0.dll
WebBrowser-{9EE802E8-C931-47AB-B570-AA8F791598CA} - c:\program files\eMusic\tbeMu0.dll
HKLM-Run-AOLAspSunset2 - c:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\updates\aspapp\sunsetAsp2.exe
.
——- Supplementary Scan ——-
.
uInternet Connection Wizard,ShellNext = hxxp://www.gocyberlink.com/registration/registration1.asp?SoftWare=POWERDVD&Version_Num=5.0&Cd_Key=MV39844293845489&Company=Company&FName=user&Lang=Enu
IE: &AOL Toolbar Search - c:\documents and settings\All Users\Application Data\AOL\ieToolbar\resources\en-US\local\search.html
IE: &Search - ?p=ZRxdm429MUUS
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
IE: Easy-WebPrint Add To Print List - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
LSP: c:\windows\system32\VetRedir.dll
Trusted Zone: turbotax.com
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-07-14 16:16
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
SansaDispatch = c:\documents and settings\user\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe??52ffe.gS???.?l?????????%252fcocoon%252fbls%252fupdates%252fSANSA%252ffe%252fverify-cert
scanning hidden files …
c:\windows\repair
scan completed successfully
hidden files: 1
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(672)
c:\windows\system32\UmxWnp.Dll
c:\program files\CA\SharedComponents\PPRT\bin\CACheck.dll
c:\program files\CA\SharedComponents\PPRT\bin\CAHook.dll
c:\program files\CA\SharedComponents\PPRT\bin\CAServer.dll
- - - - - - - > 'lsass.exe'(728)
c:\windows\system32\VetRedir.dll
c:\windows\system32\ISafeIf.dll
- - - - - - - > 'explorer.exe'(5396)
c:\windows\system32\WININET.dll
c:\program files\CA\SharedComponents\PPRT\bin\CACheck.dll
c:\program files\CA\SharedComponents\PPRT\bin\CAHook.dll
c:\program files\CA\SharedComponents\PPRT\bin\CAServer.dll
c:\program files\ScanSoft\OmniPageSE4.0\OpHookSE4.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-07-14 16:20
ComboFix-quarantined-files.txt 2009-07-14 21:20
Pre-Run: 229,386,842,112 bytes free
Post-Run: 229,458,272,256 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptOut
251 — E O F — 2009-06-12 02:37