Success!!!! New copy of CF and it ran and here's the report.
ComboFix 09-09-28.01 - Owner 09/28/2009 20:01.1.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1527.871 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\progra~1\COMMON~1\{34BDA~1
c:\progra~1\COMMON~1\{B4BDA~1
c:\program files\AskSearch\bin\DefaultSearch.dll
c:\program files\Windows Police Pro
c:\program files\Windows Police Pro\msvcm80.dll
c:\program files\Windows Police Pro\msvcp80.dll
c:\program files\Windows Police Pro\msvcr80.dll
c:\program files\Windows Police Pro\tmp\dbsinit.exe
c:\program files\Windows Police Pro\tmp\images\i1.gif
c:\program files\Windows Police Pro\tmp\images\i2.gif
c:\program files\Windows Police Pro\tmp\images\i3.gif
c:\program files\Windows Police Pro\tmp\images\j1.gif
c:\program files\Windows Police Pro\tmp\images\j2.gif
c:\program files\Windows Police Pro\tmp\images\j3.gif
c:\program files\Windows Police Pro\tmp\images\jj1.gif
c:\program files\Windows Police Pro\tmp\images\jj2.gif
c:\program files\Windows Police Pro\tmp\images\jj3.gif
c:\program files\Windows Police Pro\tmp\images\l1.gif
c:\program files\Windows Police Pro\tmp\images\l2.gif
c:\program files\Windows Police Pro\tmp\images\l3.gif
c:\program files\Windows Police Pro\tmp\images\pix.gif
c:\program files\Windows Police Pro\tmp\images\t1.gif
c:\program files\Windows Police Pro\tmp\images\t2.gif
c:\program files\Windows Police Pro\tmp\images\up1.gif
c:\program files\Windows Police Pro\tmp\images\up2.gif
c:\program files\Windows Police Pro\tmp\images\w1.gif
c:\program files\Windows Police Pro\tmp\images\w11.gif
c:\program files\Windows Police Pro\tmp\images\w2.gif
c:\program files\Windows Police Pro\tmp\images\w3.gif
c:\program files\Windows Police Pro\tmp\images\w3.jpg
c:\program files\Windows Police Pro\tmp\images\wt1.gif
c:\program files\Windows Police Pro\tmp\images\wt2.gif
c:\program files\Windows Police Pro\tmp\images\wt3.gif
c:\program files\Windows Police Pro\tmp\wispex.html
c:\recycler\S-1-5-21-3963078224-3239512543-965112274-1003
c:\windows\Downloaded Program Files\ODCTOOLS
c:\windows\Downloaded Program Files\popcaploader.inf
c:\windows\Installer\d8f3d.msp
c:\windows\run.log
c:\windows\svchast.exe
c:\windows\system32\bennuar.old
c:\windows\system32\drivers\etc\lmhosts
c:\windows\system32\drivers\gasfkyrnsixdny.sys
c:\windows\system32\drivers\gasfkywxwheexy.sys
c:\windows\system32\drivers\MSIVXpjkcjmmgtpeyknoootlqoynymnuhbgqw.sys.vir
c:\windows\system32\drivers\UACd.sys
c:\windows\system32\drivers\UACyuijpyxevr.sys
c:\windows\system32\gasfkybpkbwute.dll
c:\windows\system32\gasfkygqmcetyn.dll
c:\windows\system32\gasfkypopnbjou.dat
c:\windows\system32\gasfkyrgfldlve.dat
c:\windows\system32\gasfkyrtfgeism.dll
c:\windows\system32\gasfkyycnirppr.dll
c:\windows\system32\images
c:\windows\system32\images\i1.gif
c:\windows\system32\images\i2.gif
c:\windows\system32\images\i3.gif
c:\windows\system32\images\j1.gif
c:\windows\system32\images\j2.gif
c:\windows\system32\images\j3.gif
c:\windows\system32\images\jj1.gif
c:\windows\system32\images\jj2.gif
c:\windows\system32\images\jj3.gif
c:\windows\system32\images\l1.gif
c:\windows\system32\images\l2.gif
c:\windows\system32\images\l3.gif
c:\windows\system32\images\pix.gif
c:\windows\system32\images\t1.gif
c:\windows\system32\images\t2.gif
c:\windows\system32\images\up1.gif
c:\windows\system32\images\up2.gif
c:\windows\system32\images\w1.gif
c:\windows\system32\images\w11.gif
c:\windows\system32\images\w2.gif
c:\windows\system32\images\w3.gif
c:\windows\system32\images\w3.jpg
c:\windows\system32\images\wt1.gif
c:\windows\system32\images\wt2.gif
c:\windows\system32\images\wt3.gif
c:\windows\system32\net.net
c:\windows\system32\UACabuxoqhxbq.dll
c:\windows\system32\wispex.html
c:\windows\wiaserviv.log
Infected copy of c:\windows\system32\eventlog.dll was found and disinfected
Restored copy from - c:\windows\system32\dllcache\eventlog.dll
c:\windows\system32\proquota.exe . . . is missing!!
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_gasfkyquqfvbyg
——-\Legacy_UACd.sys
——-\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
——-\Service_gasfkyquqfvbyg
——-\Service_UACd.sys
——-\Legacy_AntipPolice_
——-\Service_AntipPolice_
((((((((((((((((((((((((( Files Created from 2009-08-28 to 2009-09-29 )))))))))))))))))))))))))))))))
.
2009-09-26 06:33 . 2009-09-26 06:33 ——– d—–w- C:\found.000
2009-09-24 05:57 . 2009-09-24 05:14 71680 —-a-w- C:\mbr.exe
2009-09-21 07:33 . 2009-09-26 04:21 0 —-a-r- c:\windows\win32k.sys
2009-09-21 07:11 . 2009-09-21 07:11 68608 —-a-w- c:\windows\system32\drivers\tivmtqfoysnnvsji.sys
2009-09-13 05:42 . 2009-09-13 05:42 ——– d—–w- c:\documents and settings\Cory\Application Data\Malwarebytes
2009-09-12 04:24 . 2009-09-12 04:24 ——– d—–w- c:\documents and settings\Freddie\Application Data\Malwarebytes
2009-09-09 04:57 . 2009-09-09 04:57 ——– d—–w- c:\documents and settings\Owner\Application Data\GOL_byHasbro
2009-09-09 04:47 . 2009-09-09 04:47 ——– d—–w- C:\GameHouse Games
2009-09-09 04:45 . 2009-09-09 04:45 ——– d—–w- c:\program files\RealArcade
2009-09-07 17:57 . 2009-09-07 17:57 ——– d—–w- c:\documents and settings\All Users\Application Data\kds_kodak
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-29 03:05 . 2008-05-27 03:59 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-09-10 21:54 . 2008-08-17 19:03 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 21:53 . 2008-05-27 03:59 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-09-10 04:24 . 2008-09-07 04:19 ——– d—–w- c:\program files\Microsoft Silverlight
2009-09-08 04:41 . 2007-01-23 22:27 ——– d—–w- c:\program files\IKEA HomePlanner
2009-09-07 23:46 . 2006-09-17 17:57 ——– d—–w- c:\documents and settings\Owner\Application Data\U3
2009-09-07 21:57 . 2004-11-16 04:32 ——– d—–w- c:\program files\Notebook Maximizer
2009-09-07 18:22 . 2008-08-17 20:53 ——– d—–w- c:\documents and settings\Owner\Application Data\AdobeUM
2009-08-29 03:31 . 2007-07-04 15:49 37592 -c–a-w- c:\documents and settings\Freddie\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-27 05:46 . 2008-01-01 21:37 37592 —-a-w- c:\documents and settings\Cory\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-26 02:24 . 2006-08-25 20:58 37592 —-a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-25 10:16 . 2009-08-25 10:16 ——– d—–w- c:\program files\MSBuild
2009-08-25 10:16 . 2009-08-25 10:16 ——– d—–w- c:\program files\Reference Assemblies
2009-08-25 10:03 . 2009-08-25 10:03 ——– d—–w- c:\program files\MSXML 6.0
2009-08-25 03:26 . 2008-10-27 01:38 11952 —-a-w- c:\windows\system32\avgrsstx.dll
2009-08-25 03:26 . 2008-10-27 01:38 335240 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-25 03:26 . 2008-10-27 01:38 27784 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-08-18 18:04 . 2009-08-18 18:04 ——– d—–w- c:\program files\Marvell
2009-08-06 08:10 . 2009-08-06 08:10 282624 —-a-w- c:\windows\system32\yk51x86.dll
2009-08-06 08:10 . 2004-11-16 03:20 297728 —-a-w- c:\windows\system32\drivers\yk51x86.sys
2009-08-05 09:11 . 2004-11-15 23:32 204800 —-a-w- c:\windows\system32\mswebdvd.dll
2009-07-17 18:55 . 2004-11-15 23:32 58880 —-a-w- c:\windows\system32\atl.dll
2009-07-14 06:43 . 2004-11-15 23:33 286208 —-a-w- c:\windows\system32\wmpdxm.dll
2008-02-10 04:01 . 2008-02-10 04:01 10752 –sha-w- c:\program files\Thumbs.db
2007-12-10 02:53 . 2007-12-10 02:41 1679619 —-a-w- c:\program files\Uninst.isu
2006-10-21 16:09 . 2006-10-21 16:09 985904 —-a-w- c:\program files\FreecorderSetup.exe
2001-09-02 00:01 . 2007-12-10 02:43 1486848 —-a-r- c:\program files\TONKA Monster Trucks.exe
2001-08-31 05:59 . 2007-12-10 02:43 21139 ——w- c:\program files\Readme.txt
2001-08-28 02:14 . 2007-12-10 02:43 40960 ——w- c:\program files\TONKA MONSTER TRUCKS Install Guide.DOC
2001-08-15 22:39 . 2007-12-10 02:43 2202 ——w- c:\program files\Tonka Monster Trucks.ico
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-07-18 01:20 279944 —-a-w- c:\program files\AskBarDis\bar\bin\askBar.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-07-24 16:55 1090816 —-a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-07-18 279944]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-07-18 279944]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2003-09-05 65536]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\lib\NMBgMonitor.exe" [2005-11-10 94208]
"Creative Detector"="c:\program files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-03 102400]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-19 204288]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-10-08 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-10-08 126976]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-10-14 98394]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-10-14 688218]
"LtMoh"="c:\program files\ltmoh\Ltmoh.exe" [2003-09-06 184320]
"AGRSMMSG"="c:\windows\AGRSMMSG.exe" [2004-10-28 88363]
"Tvs"="c:\program files\Toshiba\Tvs\TvsTray.exe" [2004-11-13 73728]
"SoundMAXPnP"="c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-07-27 1388544]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-08-03 122939]
"TPSMain"="c:\windows\system32\TPSMain.exe" [2004-08-27 278528]
"PadTouch"="c:\program files\TOSHIBA\Touch and Launch\PadExe.exe" [2004-09-07 1077301]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb10.exe" [2004-03-04 172032]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 241664]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2005-12-04 461584]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-01-27 401408]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-01-27 385024]
"EOUApp"="c:\program files\Intel\Wireless\Bin\EOUWiz.exe" [2006-01-27 356352]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-08-25 2007832]
"EKIJ5000StatusMonitor"="c:\windows\System32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe" [2007-11-13 1052672]
"THotkey"="c:\program files\Toshiba\Toshiba Applet\thotkey.exe" [2004-12-15 368640]
"SmoothView"="c:\program files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [2004-09-15 135168]
"PCClient.exe"="c:\program files\Trend Micro\Antivirus\PCClient.exe" [2004-02-17 634949]
"HP Software Update"="c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2004-02-18 49152]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-07 57344]
"TFncKy"="TFncKy.exe" [BU]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"SYSDLL"="SYSDLL" [X]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]
RAMASST.lnk - c:\windows\system32\RAMASST.exe [2004-12-7 155648]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
2006-01-27 13:12 110592 —-a-w- c:\program files\Intel\Wireless\Bin\LgNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-25 03:26 11952 —-a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\rootrepeal.sys]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^TONKA« Construction 2 Registration.lnk]
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\TONKA« Construction 2 Registration.lnk
backup=c:\windows\pss\TONKA« Construction 2 Registration.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [10/26/2008 6:38 PM 335240]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [10/26/2008 6:38 PM 297752]
R2 IntuitUpdateService;Intuit Update Service;c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe [10/10/2008 5:45 AM 13088]
R2 KodakSvc;Kodak AiO Device Service;c:\program files\Kodak\Printer\Center\KodakSvc.exe [12/13/2007 12:07 PM 18944]
R2 Tmfilter;Tmfilter;c:\windows\system32\drivers\TmXPFlt.sys [3/5/2004 12:53 PM 204816]
R2 Tmntsrv;Trend NT Realtime Service;c:\program files\Trend Micro\Antivirus\Tmntsrv.exe [2/17/2004 3:57 PM 241737]
R2 Tmpreflt;Tmpreflt;c:\windows\system32\drivers\tmpreflt.sys [3/5/2004 12:53 PM 36368]
R2 tmproxy;Trend Micro Proxy Service;c:\program files\Trend Micro\Antivirus\tmproxy.exe [2/17/2004 3:58 PM 204873]
S3 bfastfao;bfastfao;\??\c:\docume~1\Owner\LOCALS~1\Temp\bfastfao.sys –> c:\docume~1\Owner\LOCALS~1\Temp\bfastfao.sys [?]
.
Contents of the 'Scheduled Tasks' folder
2009-07-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local;
uInternet Settings,ProxyServer = http=localhost:7171
uSearchURL,(Default) = hxxp://toolbar.ask.com/toolbarv/askRedirect?o=20008&gct=&gc=1&q=%s
IE: &AOL Toolbar search - c:\program files\AOL Toolbar\toolbar.dll/SEARCH.HTML
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: turbotax.com
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://www.gamehouse.com/games/zylom/zylomplayer.cab
.
- - - - ORPHANS REMOVED - - - -
SafeBoot-AVG Anti-Spyware Driver
SafeBoot-AVG Anti-Spyware Guard
AddRemove-BearShare Test - e:\progra~1\BEARSH~1\UNWISE.EXE
AddRemove-HijackThis - c:\documents and settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\8DSB0VWV\HijackThis.exe
AddRemove-Malwarebytes' Anti-Malware_is1 - e:\malwarebytes' anti-malware\unins000.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-09-28 20:11
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(628)
c:\program files\Intel\Wireless\Bin\LgNotify.dll
- - - - - - - > 'explorer.exe'(4736)
c:\windows\system32\WPDShServiceObj.dll
c:\program files\ArcSoft\Software Suite\PhotoImpression\share\pihook.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\TPwrCfg.DLL
c:\windows\system32\TPwrReg.dll
c:\windows\system32\TPSTrace.DLL
.
———————— Other Running Processes ————————
.
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\drivers\CDAC11BA.EXE
c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe
c:\windows\system32\CTSVCCDA.EXE
c:\windows\system32\DVDRAMSV.exe
c:\program files\Intel\Wireless\Bin\OProtSvc.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Analog Devices\SoundMAX\SMAgent.exe
c:\toshiba\IVP\swupdate\swupdtmr.exe
c:\program files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
c:\program files\Pure Networks\Network Magic\nmsrvc.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\Intel\Wireless\Bin\1XConfig.exe
c:\windows\system32\TPSBattM.exe
c:\program files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
.
**************************************************************************
.
Completion time: 2009-09-29 20:17 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-29 03:17
Pre-Run: 21,442,486,272 bytes free
Post-Run: 21,425,373,184 bytes free
308 — E O F — 2009-09-09 05:16
Thanks, things have been running better, I know we have a ways to go.
Fred