Sorry this took so long. I ran scans on two different nights only to find out the computer automatically restarted so I had to do the scans over again. Here is the latest ComFix scan log. I don;t know why the log says Comodo is enabled since I disabled it just before running the scan.
Thanks for helping,
GB
ComboFix 11-03-03.04 - Owner 03/09/2011 8:02.13.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1534.1102 [GMT -9:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: COMODO Firewall *Enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.
((((((((((((((((((((((((( Files Created from 2011-02-09 to 2011-03-09 )))))))))))))))))))))))))))))))
.
2011-03-09 00:25 . 2011-03-09 00:25 ——– d—–w- c:\wixp\LastGood
2011-03-06 00:36 . 2011-03-06 00:36 ——– dc-h–w- c:\documents and settings\All Users.WIXP\Application Data\{EFBAD1D6-DB32-4E45-ACA1-FB05458C6D20}
2011-03-06 00:34 . 2011-03-06 00:34 ——– d—–w- c:\program files\Radium Technologies
2011-03-06 00:34 . 2011-03-06 00:34 ——– d—–w- c:\documents and settings\All Users.WIXP\Application Data\Radium Technologies
2011-03-05 23:51 . 2011-03-05 23:51 ——– d—–w- c:\program files\Kerkia
2011-02-24 17:08 . 2011-02-23 14:56 371544 —-a-w- c:\wixp\system32\drivers\aswSnx.sys
2011-02-24 17:04 . 2011-02-24 17:04 ——– d—–w- c:\program files\Common Files\Java
2011-02-22 12:08 . 2011-02-22 12:08 ——– d—–w- c:\wixp\system32\XPSViewer
2011-02-22 12:06 . 2008-07-06 12:06 89088 —-a-w- c:\wixp\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2011-02-22 12:05 . 2008-07-06 12:06 89088 -c—-w- c:\wixp\system32\dllcache\filterpipelineprintproc.dll
2011-02-22 12:05 . 2008-07-06 12:06 117760 ——w- c:\wixp\system32\prntvpt.dll
2011-02-22 12:05 . 2008-07-06 12:06 575488 -c—-w- c:\wixp\system32\dllcache\xpsshhdr.dll
2011-02-22 12:05 . 2008-07-06 12:06 575488 ——w- c:\wixp\system32\xpsshhdr.dll
2011-02-22 12:05 . 2008-07-06 12:06 1676288 -c—-w- c:\wixp\system32\dllcache\xpssvcs.dll
2011-02-22 12:05 . 2008-07-06 12:06 1676288 ——w- c:\wixp\system32\xpssvcs.dll
2011-02-22 12:05 . 2008-07-06 10:50 597504 -c—-w- c:\wixp\system32\dllcache\printfilterpipelinesvc.exe
2011-02-22 12:05 . 2008-07-06 10:50 597504 ——w- c:\wixp\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2011-02-22 12:05 . 2011-02-22 12:06 ——– d—–w- C:\92bc20fcc047355f0049ae
2011-02-19 11:39 . 2009-08-05 23:58 93872 —-a-w- c:\wixp\system32\drivers\SBREDrv.sys
2011-02-18 04:08 . 2011-02-18 04:08 ——– d—–w- c:\wixp\system32\drivers\NSS
2011-02-18 04:08 . 2011-02-18 04:08 ——– d—–w- c:\program files\Norton Security Scan
2011-02-18 04:08 . 2011-02-18 04:08 ——– d—–w- c:\program files\NortonInstaller
2011-02-18 01:52 . 2011-02-18 01:52 ——– d—–w- c:\documents and settings\Owner.KHALSA-FAMILY\Application Data\f-secure
2011-02-18 01:52 . 2011-02-18 01:52 ——– d—–w- c:\documents and settings\All Users.WIXP\Application Data\F-Secure
2011-02-18 01:32 . 2009-06-30 19:37 28552 —-a-w- c:\wixp\system32\drivers\pavboot.sys
2011-02-18 01:31 . 2011-02-18 01:31 ——– d—–w- c:\program files\Panda Security
2011-02-18 01:29 . 2011-02-18 01:29 ——– d—–w- c:\documents and settings\All Users.WIXP\Application Data\CA
2011-02-16 23:19 . 2011-02-17 07:31 ——– d—–w- c:\wixp\BDOSCAN8
2011-02-15 21:17 . 2011-02-15 21:17 ——– d—–w- c:\documents and settings\Owner.KHALSA-FAMILY\Application Data\CBS Interactive
2011-02-12 00:28 . 2011-02-12 00:28 ——– d-sh–w- c:\documents and settings\Administrator.KHALSA-FAMILY\PrivacIE
2011-02-12 00:24 . 2011-02-12 00:24 ——– d-sh–w- c:\documents and settings\Administrator.KHALSA-FAMILY\IETldCache
2011-02-12 00:15 . 2011-02-12 00:15 ——– d—–w- c:\wixp\system32\wbem\Repository
2011-02-09 13:53 . 2011-02-09 13:53 270848 -c—-w- c:\wixp\system32\dllcache\sbe.dll
2011-02-09 13:53 . 2011-02-09 13:53 186880 -c—-w- c:\wixp\system32\dllcache\encdec.dll
2011-02-09 04:52 . 2010-11-02 15:17 40960 -c—-w- c:\wixp\system32\dllcache\ndproxy.sys
2011-02-09 04:49 . 2010-10-11 14:59 45568 -c—-w- c:\wixp\system32\dllcache\wab.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-23 15:04 . 2010-07-30 23:59 40648 —-a-w- c:\wixp\avastSS.scr
2011-02-23 15:04 . 2010-06-03 06:33 190016 —-a-w- c:\wixp\system32\aswBoot.exe
2011-02-23 14:56 . 2010-06-03 06:34 301528 —-a-w- c:\wixp\system32\drivers\aswSP.sys
2011-02-23 14:55 . 2010-06-03 06:34 49240 —-a-w- c:\wixp\system32\drivers\aswTdi.sys
2011-02-23 14:55 . 2010-06-03 06:34 102232 —-a-w- c:\wixp\system32\drivers\aswmon2.sys
2011-02-23 14:55 . 2010-06-03 06:34 96344 —-a-w- c:\wixp\system32\drivers\aswmon.sys
2011-02-23 14:55 . 2010-06-03 06:34 25432 —-a-w- c:\wixp\system32\drivers\aswRdr.sys
2011-02-23 14:54 . 2010-06-03 06:34 30680 —-a-w- c:\wixp\system32\drivers\aavmker4.sys
2011-02-23 14:54 . 2010-06-03 06:34 19544 —-a-w- c:\wixp\system32\drivers\aswFsBlk.sys
2011-02-09 13:53 . 2002-09-03 16:57 270848 —-a-w- c:\wixp\system32\sbe.dll
2011-02-09 13:53 . 2002-09-03 16:32 186880 —-a-w- c:\wixp\system32\encdec.dll
2011-02-03 06:40 . 2010-04-26 04:47 472808 —-a-w- c:\wixp\system32\deployJava1.dll
2011-02-03 04:19 . 2010-06-07 23:16 73728 —-a-w- c:\wixp\system32\javacpl.cpl
2011-02-02 07:58 . 2009-12-22 01:28 2067456 —-a-w- c:\wixp\system32\mstscax.dll
2011-01-27 11:57 . 2009-12-22 01:28 677888 —-a-w- c:\wixp\system32\mstsc.exe
2011-01-21 21:59 . 2010-09-11 07:41 285480 —-a-w- c:\wixp\system32\guard32.dll
2011-01-21 21:59 . 2010-09-11 07:40 94784 —-a-w- c:\wixp\system32\drivers\inspect.sys
2011-01-21 21:59 . 2010-09-11 07:40 27576 —-a-w- c:\wixp\system32\drivers\cmdhlp.sys
2011-01-21 21:59 . 2010-09-11 07:40 239368 —-a-w- c:\wixp\system32\drivers\cmdGuard.sys
2011-01-21 21:59 . 2010-09-11 07:40 15592 —-a-w- c:\wixp\system32\drivers\cmderd.sys
2011-01-21 14:44 . 2002-09-03 16:59 439296 —-a-w- c:\wixp\system32\shimgvw.dll
2011-01-07 14:09 . 2002-09-03 16:27 290048 —-a-w- c:\wixp\system32\atmfd.dll
2010-12-31 13:10 . 2002-09-03 17:11 1854976 —-a-w- c:\wixp\system32\win32k.sys
2010-12-22 12:34 . 2002-09-03 16:39 301568 —-a-w- c:\wixp\system32\kerberos.dll
2010-12-21 03:09 . 2010-09-17 09:53 38224 —-a-w- c:\wixp\system32\drivers\mbamswissarmy.sys
2010-12-21 03:08 . 2010-09-17 09:53 20952 —-a-w- c:\wixp\system32\drivers\mbam.sys
2010-12-20 23:59 . 2002-09-03 17:12 916480 —-a-w- c:\wixp\system32\wininet.dll
2010-12-20 23:59 . 2002-09-03 16:39 43520 —-a-w- c:\wixp\system32\licmgr10.dll
2010-12-20 23:59 . 2002-09-03 16:35 1469440 ——w- c:\wixp\system32\inetcpl.cpl
2010-12-20 17:26 . 2002-09-03 16:39 730112 —-a-w- c:\wixp\system32\lsasrv.dll
2010-12-20 12:55 . 2009-12-22 11:33 385024 —-a-w- c:\wixp\system32\html.iec
.
.
((((((((((((((((((((((((((((( SnapShot@2011-03-07_12.03.22 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-03-08 12:20 . 2011-03-08 12:20 16384 c:\wixp\Temp\Perflib_Perfdata_184.dat
+ 2010-10-18 21:01 . 2011-03-08 12:03 49152 c:\wixp\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ConfigIcon.dll
- 2010-10-18 21:01 . 2011-02-10 03:00 49152 c:\wixp\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ConfigIcon.dll
- 2002-09-03 16:59 . 2008-04-14 00:12 135168 c:\wixp\system32\shsvcs.dll
+ 2002-09-03 16:59 . 2009-07-27 23:17 135168 c:\wixp\system32\shsvcs.dll
+ 2009-07-27 23:17 . 2009-07-27 23:17 135168 c:\wixp\system32\dllcache\shsvcs.dll
+ 2011-01-27 11:57 . 2011-01-27 11:57 677888 c:\wixp\system32\dllcache\lhmstsc.exe
+ 2011-02-02 07:58 . 2011-02-02 07:58 2067456 c:\wixp\system32\dllcache\lhmstscx.dll
+ 2010-10-29 19:43 . 2011-03-09 12:17 37943240 c:\wixp\system32\MRT.exe
+ 2011-03-08 12:01 . 2011-03-08 12:01 20308992 c:\wixp\Installer\3816a31.msp
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-02-23 15:04 122512 —-a-w- c:\program files\Alwil Software\Avast5\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE" [2011-02-24 2423752]
"SandboxieControl"="c:\program files\Sandboxie\SbieCtrl.exe" [2010-10-17 404200]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-12-24 39408]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2011-02-07 107000]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\wixp\system32\igfxtray.exe" [2004-02-10 155648]
"HotKeysCmds"="c:\wixp\system32\hkcmd.exe" [2004-02-10 118784]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2010-05-31 323976]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2011-02-23 3451496]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2011-01-21 2548552]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
c:\documents and settings\Owner.KHALSA-FAMILY\Start Menu\Programs\Startup\
CNET TechTracker.lnk - c:\documents and settings\Owner.KHALSA-FAMILY\Application Data\CBS Interactive\CNET TechTracker\TechTracker.exe [2010-12-2 2621952]
c:\documents and settings\All Users.WIXP\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.189\SSScheduler.exe [2010-9-2 255536]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2010-01-26 02:20 10536 —-a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\wixp\system32\guard32.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WIXP^Start Menu^Programs^Startup^BounceBack Launcher.lnk]
backup=c:\wixp\pss\BounceBack Launcher.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner.KHALSA-FAMILY^Start Menu^Programs^Startup^OpenOffice.org 3.2.lnk]
backup=c:\wixp\pss\OpenOffice.org 3.2.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner.KHALSA-FAMILY^Start Menu^Programs^Startup^TimeLeft.lnk]
backup=c:\wixp\pss\TimeLeft.lnkStartup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Live Meeting 8\\Console\\PWConsole.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Giganology\\Gigaget\\Gigaget.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
R0 pavboot;pavboot;c:\wixp\system32\drivers\pavboot.sys [2/17/2011 4:32 PM 28552]
R1 aswSnx;aswSnx;c:\wixp\system32\drivers\aswSnx.sys [2/24/2011 8:08 AM 371544]
R1 aswSP;aswSP;c:\wixp\system32\drivers\aswSP.sys [6/2/2010 9:34 PM 301528]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\wixp\system32\drivers\cmdGuard.sys [9/10/2010 10:40 PM 239368]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\wixp\system32\drivers\cmdhlp.sys [9/10/2010 10:40 PM 27576]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 9:25 AM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 9:41 AM 67656]
R1 SBRE;SBRE;c:\wixp\system32\drivers\SBREDrv.sys [2/19/2011 2:39 AM 93872]
R2 aswFsBlk;aswFsBlk;c:\wixp\system32\drivers\aswFsBlk.sys [6/2/2010 9:34 PM 19544]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\progra~1\mcafee\SITEAD~1\mcsacore.exe [1/23/2010 11:42 PM 88176]
R2 portD;CMS PortIO Service;c:\wixp\system32\drivers\portd2k.sys [1/13/2010 1:43 PM 7424]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [12/23/2009 7:05 PM 135664]
S3 BIOSCHK;BIOSCHK;\??\c:\docume~1\OWNER~1.KHA\LOCALS~1\Temp\TII69D.tmp\disk1\BIOSCHK.SYS –> c:\docume~1\OWNER~1.KHA\LOCALS~1\Temp\TII69D.tmp\disk1\BIOSCHK.SYS [?]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.189\McCHSvc.exe [9/2/2010 11:18 AM 227232]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2/17/2010 9:15 AM 12872]
S4 0258871292614199mcinstcleanup;McAfee Application Installer Cleanup (0258871292614199);c:\wixp\TEMP\025887~1.EXE c:\progra~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service –> c:\wixp\TEMP\025887~1.EXE c:\progra~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service [?]
.
Contents of the 'Scheduled Tasks' folder
2011-03-08 c:\wixp\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-24 04:05]
2011-03-09 c:\wixp\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-24 04:05]
2011-03-08 c:\wixp\Tasks\GoogleUpdateTaskUserS-1-5-21-602162358-1383384898-725345543-1003Core.job
- c:\documents and settings\Owner.KHALSA-FAMILY\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-12-24 04:05]
2011-03-09 c:\wixp\Tasks\GoogleUpdateTaskUserS-1-5-21-602162358-1383384898-725345543-1003UA.job
- c:\documents and settings\Owner.KHALSA-FAMILY\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-12-24 04:05]
2011-03-08 c:\wixp\Tasks\Norton Security Scan for Owner.job
- c:\program files\Norton Security Scan\Engine\3.0.1.8\Nss.exe [2011-02-18 14:06]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://yahoo.com/
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Download All by Gigaget - c:\program files\Giganology\Gigaget\getallurl.htm
IE: &Download by Gigaget - c:\program files\Giganology\Gigaget\geturl.htm
IE: Add to Google Photos Screensa&ver - c:\wixp\system32\GPhotos.scr/200
IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
IE: RoboForm Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
DPF: DirectAnimation Java Classes - file://c:\wixp\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\wixp\Java\classes\xmldso.cab
DPF: {E6BB2089-163F-466B-812A-748096614DFD} - hxxp://cainternetsecurity.net/scanner/cascanner.cab
.
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-03-09 08:20
Windows 5.1.2600 Service Pack 3 NTFS
detected NTDLL code modification:
ZwClose, ZwOpenFile
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WIXP\\system32\\Macromed\\Flash\\FlashUtil10m_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WIXP\\system32\\Macromed\\Flash\\FlashUtil10m_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(580)
c:\wixp\system32\guard32.dll
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\wixp\system32\WININET.dll
c:\program files\Citrix\GoToAssist\514\G2AWinLogon.dll
- - - - - - - > 'lsass.exe'(636)
c:\wixp\system32\guard32.dll
- - - - - - - > 'explorer.exe'(2612)
c:\wixp\system32\WININET.dll
c:\wixp\system32\guard32.dll
c:\program files\BillP Studios\WinPatrol\PATROLPRO.DLL
c:\progra~1\mcafee\SITEAD~1\saHook.dll
c:\wixp\system32\ieframe.dll
c:\wixp\system32\webcheck.dll
c:\wixp\system32\WPDShServiceObj.dll
c:\wixp\system32\PortableDeviceTypes.dll
c:\wixp\system32\PortableDeviceApi.dll
.
Completion time: 2011-03-09 08:26:27
ComboFix-quarantined-files.txt 2011-03-09 17:26
ComboFix2.txt 2011-03-08 08:03
ComboFix3.txt 2011-03-07 12:11
.
Pre-Run: 17,768,366,080 bytes free
Post-Run: 17,956,970,496 bytes free
.
- - End Of File - - CAB90A6EE89497C9EA2DEEC42BEC079F