Hi
I must have done something wrong originally. I have run it again. Log posted below and attached.
Thanks.
ComboFix 11-10-08.01 - Toni 11/10/2011 20:19:37.1.2 - x86 NETWORK
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.1013.514 [GMT 1:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\Toni\Desktop\CFScript.txt.txt
AV: Kaspersky Internet Security *Disabled/Outdated* {AE1D740B-8F0F-D137-211D-873D44B3F4AE}
FW: Kaspersky Internet Security *Disabled* {9626F52E-C560-D06F-0A42-2E08BA60B3D5}
SP: Kaspersky Internet Security *Disabled/Updated* {157C95EF-A935-DEB9-1BAD-BC4F3F34BE13}
SP: STOPzilla Anti-Spyware *Enabled/Updated* {B2E69928-50DC-94CA-6A80-AAB054008761}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
file zipped: c:\windows\system32\32filasomnj.dat
file zipped: c:\windows\system32\aliqwejmlo.dat
file zipped: c:\windows\system32\asoebxjehum.dat
file zipped: c:\windows\system32\asoetuhumfo.dat
file zipped: c:\windows\system32\asowinlopfo.dat
file zipped: c:\windows\system32\cowi6432.dat
file zipped: c:\windows\system32\crasubesolon.dat
file zipped: c:\windows\system32\dllebxdllebx.dat
file zipped: c:\windows\system32\ebxcotohum.dat
file zipped: c:\windows\system32\esoexecomvir.dat
file zipped: c:\windows\system32\filcomlopfo.dat
file zipped: c:\windows\system32\humdllrimand.dat
file zipped: c:\windows\system32\lonco3264.dat
file zipped: c:\windows\system32\lopexetolop.dat
file zipped: c:\windows\system32\lopwinaimcom.dat
file zipped: c:\windows\system32\loqweasofo.dat
file zipped: c:\windows\system32\lorimcoor.dat
file zipped: c:\windows\system32\mnjebx32lon.dat
file zipped: c:\windows\system32\nidoetulo.dat
file zipped: c:\windows\system32\quicomaimcra.dat
file zipped: c:\windows\system32\quior64ni.dat
file zipped: c:\windows\system32\simtosimni.dat
file zipped: c:\windows\system32\whandjedo.dat
file zipped: c:\windows\system32\whetualiwi.dat
file zipped: c:\windows\system32\wihumarjsim.dat
file zipped: c:\windows\system32\winmnjaimwh.dat
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\32filasomnj.dat
c:\windows\system32\aliqwejmlo.dat
c:\windows\system32\asoebxjehum.dat
c:\windows\system32\asoetuhumfo.dat
c:\windows\system32\asowinlopfo.dat
c:\windows\system32\cowi6432.dat
c:\windows\system32\crasubesolon.dat
c:\windows\system32\dllebxdllebx.dat
c:\windows\system32\ebxcotohum.dat
c:\windows\system32\esoexecomvir.dat
c:\windows\system32\filcomlopfo.dat
c:\windows\system32\humdllrimand.dat
c:\windows\system32\lonco3264.dat
c:\windows\system32\lopexetolop.dat
c:\windows\system32\lopwinaimcom.dat
c:\windows\system32\loqweasofo.dat
c:\windows\system32\lorimcoor.dat
c:\windows\system32\mnjebx32lon.dat
c:\windows\system32\nidoetulo.dat
c:\windows\system32\quicomaimcra.dat
c:\windows\system32\quior64ni.dat
c:\windows\system32\simtosimni.dat
c:\windows\system32\whandjedo.dat
c:\windows\system32\whetualiwi.dat
c:\windows\system32\wihumarjsim.dat
c:\windows\system32\winmnjaimwh.dat
.
.
((((((((((((((((((((((((( Files Created from 2011-09-11 to 2011-10-11 )))))))))))))))))))))))))))))))
.
.
2011-10-11 19:36 . 2011-10-11 19:43 ——– d—–w- c:\users\Toni\AppData\Local\temp
2011-10-11 19:36 . 2011-10-11 19:36 ——– d—–w- c:\users\patch2\AppData\Local\temp
2011-09-30 18:00 . 2011-09-30 18:00 ——– d—–w- c:\users\Toni\AppData\Local\ElevatedDiagnostics
2011-09-30 16:08 . 2011-09-30 16:08 388096 —-a-r- c:\users\Toni\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-09-30 16:08 . 2011-09-30 16:08 ——– d—–w- c:\program files\Trend Micro
2011-09-25 17:54 . 2011-09-25 17:54 ——– d—–w- c:\users\Toni\AppData\Local\Mozilla
2011-09-25 17:52 . 2011-09-25 17:52 86528 —-a-w- c:\windows\system32\iesysprep.dll
2011-09-25 17:47 . 2011-09-25 17:47 683008 —-a-w- c:\windows\system32\d2d1.dll
2011-09-25 17:47 . 2011-09-25 17:47 1068544 —-a-w- c:\windows\system32\DWrite.dll
2011-09-25 17:47 . 2011-09-25 17:47 797184 —-a-w- c:\windows\system32\FntCache.dll
2011-09-25 17:47 . 2011-09-25 17:47 486400 —-a-w- c:\windows\system32\d3d10level9.dll
2011-09-25 17:47 . 2011-09-25 17:47 219648 —-a-w- c:\windows\system32\d3d10_1core.dll
2011-09-25 17:47 . 2011-09-25 17:47 189952 —-a-w- c:\windows\system32\d3d10core.dll
2011-09-25 17:47 . 2011-09-25 17:47 160768 —-a-w- c:\windows\system32\d3d10_1.dll
2011-09-25 17:47 . 2011-09-25 17:47 1172480 —-a-w- c:\windows\system32\d3d10warp.dll
2011-09-25 17:47 . 2011-09-25 17:47 1029120 —-a-w- c:\windows\system32\d3d10.dll
2011-09-25 17:47 . 2011-09-25 17:47 478720 —-a-w- c:\windows\system32\dxgi.dll
2011-09-25 17:47 . 2011-09-25 17:47 638336 —-a-w- c:\windows\system32\drivers\dxgkrnl.sys
2011-09-25 17:47 . 2011-09-25 17:47 37376 —-a-w- c:\windows\system32\cdd.dll
2011-09-25 17:44 . 2011-09-25 17:44 195584 —-a-w- c:\windows\system32\dxdiagn.dll
2011-09-25 17:44 . 2011-09-25 17:44 252928 —-a-w- c:\windows\system32\dxdiag.exe
2011-09-25 17:44 . 2011-09-25 17:44 519680 —-a-w- c:\windows\system32\d3d11.dll
2011-09-16 17:47 . 2011-09-16 17:47 ——– d—–w- c:\users\Toni\hen do
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-09-25 17:53 . 2011-09-25 17:53 4202349 —h–w- c:\windows\system32\tem32arjje.dat
2011-09-25 17:53 . 2011-09-25 17:53 4134289 —h–w- c:\windows\system32\quihumwhrim.dat
2011-09-25 17:53 . 2011-09-25 17:53 3870896 —h–w- c:\windows\system32\nilo64dim.dat
2011-09-25 17:53 . 2011-09-25 17:53 3678098 —h–w- c:\windows\system32\niqwelopvir.dat
2011-09-25 17:53 . 2011-09-25 17:53 3510736 —h–w- c:\windows\system32\tohumtolon.dat
2011-09-25 17:53 . 2011-09-25 17:53 3510736 —h–w- c:\windows\system32\toforimtem.dat
2011-09-25 17:53 . 2011-09-25 17:53 3510736 —h–w- c:\windows\system32\nihumtemsub.dat
2011-09-25 17:53 . 2011-09-25 17:53 3461143 —h–w- c:\windows\system32\loplovirto.dat
2011-09-25 17:53 . 2011-09-25 17:53 3433315 —h–w- c:\windows\system32\simarjvirdim.dat
2011-09-25 17:53 . 2011-09-25 17:53 3433315 —h–w- c:\windows\system32\qui32asoexe.dat
2011-09-25 17:53 . 2011-09-25 17:53 3433315 —h–w- c:\windows\system32\lopcraaimtem.dat
2011-09-25 17:53 . 2011-09-25 17:53 3382824 —h–w- c:\windows\system32\londoasolop.dat
2011-09-25 17:53 . 2011-09-25 17:53 3330722 —h–w- c:\windows\system32\qwelop32ni.dat
2011-09-25 17:53 . 2011-09-25 17:53 3231629 —h–w- c:\windows\system32\subandwi64.dat
2011-09-25 17:53 . 2011-09-25 17:53 3231629 —h–w- c:\windows\system32\loporandtem.dat
2011-09-25 17:53 . 2011-09-25 17:53 3178002 —h–w- c:\windows\system32\simexeqweqwe.dat
2011-09-25 17:53 . 2011-09-25 17:53 3178002 —h–w- c:\windows\system32\qwedotemcom.dat
2011-09-25 17:53 . 2011-09-25 17:53 3174320 —h–w- c:\windows\system32\wisub64and.dat
2011-09-25 17:53 . 2011-09-25 17:53 3174320 —h–w- c:\windows\system32\toqwequior.dat
2011-09-25 17:53 . 2011-09-25 17:53 3155965 —h–w- c:\windows\system32\quisimjeetu.dat
2011-09-25 17:53 . 2011-09-25 17:53 3122464 —h–w- c:\windows\system32\simdonitem.dat
2011-09-25 17:53 . 2011-09-25 17:53 3090186 —h–w- c:\windows\system32\whtemqweali.dat
2011-09-25 17:53 . 2011-09-25 17:53 3024062 —h–w- c:\windows\system32\mnjwinaimco.dat
2011-09-25 17:53 . 2011-09-25 17:53 2830392 —h–w- c:\windows\system32\mnjsimsimexe.dat
2011-09-25 17:53 . 2011-09-25 17:53 2830392 —h–w- c:\windows\system32\lopwhaimsub.dat
2011-09-25 17:53 . 2011-09-25 17:53 161792 —-a-w- c:\windows\system32\msls31.dll
2011-09-25 17:53 . 2011-09-25 17:53 1126912 —-a-w- c:\windows\system32\wininet.dll
2011-09-25 17:52 . 2011-09-25 17:52 74752 —-a-w- c:\windows\system32\RegisterIEPKEYs.exe
2011-09-25 17:52 . 2011-09-25 17:52 76800 —-a-w- c:\windows\system32\SetIEInstalledDate.exe
2011-09-25 17:52 . 2011-09-25 17:52 48640 —-a-w- c:\windows\system32\mshtmler.dll
2011-09-25 17:52 . 2011-09-25 17:52 63488 —-a-w- c:\windows\system32\tdc.ocx
2011-09-25 17:52 . 2011-09-25 17:52 23552 —-a-w- c:\windows\system32\licmgr10.dll
2011-09-25 17:52 . 2011-09-25 17:52 152064 —-a-w- c:\windows\system32\wextract.exe
2011-09-25 17:52 . 2011-09-25 17:52 420864 —-a-w- c:\windows\system32\vbscript.dll
2011-09-25 17:52 . 2011-09-25 17:52 2382848 —-a-w- c:\windows\system32\mshtml.tlb
2011-09-25 17:52 . 2011-09-25 17:52 11776 —-a-w- c:\windows\system32\mshta.exe
2011-09-25 17:48 . 2011-09-25 17:48 979456 —-a-w- c:\windows\system32\MFH264Dec.dll
2011-09-25 17:48 . 2011-09-25 17:48 357376 —-a-w- c:\windows\system32\MFHEAACdec.dll
2011-09-25 17:47 . 2011-09-25 17:47 302592 —-a-w- c:\windows\system32\mfmp4src.dll
2011-09-25 17:47 . 2011-09-25 17:47 261632 —-a-w- c:\windows\system32\mfreadwrite.dll
2011-09-25 17:47 . 2011-09-25 17:47 2873344 —-a-w- c:\windows\system32\mf.dll
2011-09-25 17:47 . 2011-09-25 17:47 98816 —-a-w- c:\windows\system32\mfps.dll
2011-09-25 17:47 . 2011-09-25 17:47 586240 —-a-w- c:\windows\system32\stobject.dll
2011-09-25 17:47 . 2011-09-25 17:47 209920 —-a-w- c:\windows\system32\mfplat.dll
2011-09-25 17:47 . 2011-09-25 17:47 288768 —-a-w- c:\windows\system32\XpsGdiConverter.dll
2011-09-25 17:47 . 2011-09-25 17:47 135680 —-a-w- c:\windows\system32\XpsRasterService.dll
2011-09-25 17:47 . 2011-09-25 17:47 258048 —-a-w- c:\windows\system32\winspool.drv
2011-09-25 17:47 . 2011-09-25 17:47 667648 —-a-w- c:\windows\system32\printfilterpipelinesvc.exe
2011-09-25 17:47 . 2011-09-25 17:47 26112 —-a-w- c:\windows\system32\printfilterpipelineprxy.dll
2011-09-25 17:47 . 2011-09-25 17:47 847360 —-a-w- c:\windows\system32\OpcServices.dll
2011-09-25 17:47 . 2011-09-25 17:47 1554432 —-a-w- c:\windows\system32\xpsservices.dll
2011-09-25 17:47 . 2011-09-25 17:47 876032 —-a-w- c:\windows\system32\XpsPrint.dll
2011-09-25 17:44 . 2011-09-25 17:44 4096 —-a-w- c:\windows\system32\drivers\en-US\dxgkrnl.sys.mui
2011-09-25 17:44 . 2011-09-25 17:44 369664 —-a-w- c:\windows\system32\WMPhoto.dll
2011-09-25 17:44 . 2011-09-25 17:44 321024 —-a-w- c:\windows\system32\PhotoMetadataHandler.dll
2011-09-25 17:44 . 2011-09-25 17:44 189440 —-a-w- c:\windows\system32\WindowsCodecsExt.dll
2011-09-25 17:44 . 2011-09-25 17:44 974848 —-a-w- c:\windows\system32\WindowsCodecs.dll
2011-09-22 06:21 . 2011-06-08 07:54 0 —-a-w- c:\users\patch2\AppData\Local\Rqoxamecus.bin
2011-09-12 23:14 . 2011-10-07 20:03 7269712 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{89423389-10D1-4BF3-ACEA-4C5E39574A64}\mpengine.dll
2011-08-14 17:54 . 2011-05-16 20:03 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-07-19 10:02 . 2011-07-19 10:02 546256 —-a-r- c:\windows\system32\SZComp5.dll
2011-07-19 10:02 . 2011-07-19 10:02 22992 —-a-r- c:\windows\system32\SZIO5.dll
2011-07-19 10:02 . 2011-07-19 10:02 132560 —-a-r- c:\windows\system32\IS3HTUI5.dll
2011-07-19 10:02 . 2011-07-19 10:02 99792 —-a-r- c:\windows\system32\IS3Svc5.dll
2011-07-19 10:02 . 2011-07-19 10:02 99792 —-a-r- c:\windows\system32\IS3Inet5.dll
2011-07-19 10:02 . 2011-07-19 10:02 67024 —-a-r- c:\windows\system32\IS3Hks5.dll
2011-07-19 10:02 . 2011-07-19 10:02 456144 —-a-r- c:\windows\system32\SZBase5.dll
2011-07-19 10:02 . 2011-07-19 10:02 398800 —-a-r- c:\windows\system32\IS3DBA5.dll
2011-07-19 10:02 . 2011-07-19 10:02 28624 —-a-r- c:\windows\system32\IS3XDat5.dll
2011-07-19 10:02 . 2011-07-19 10:02 738768 —-a-r- c:\windows\system32\IS3Base5.dll
2011-07-19 10:02 . 2011-07-19 10:02 390608 —-a-r- c:\windows\system32\IS3UI5.dll
2011-07-19 10:02 . 2011-07-19 10:02 230864 —-a-r- c:\windows\system32\IS3Win325.dll
2011-09-29 07:09 . 2011-09-30 18:48 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-04-28 857648]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-07-02 138008]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-07-02 154392]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-07-02 133912]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-03-21 1548288]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-11-05 221184]
"dscactivate"="c:\dell\dsca.exe" [2007-07-30 16384]
"WPCUMI"="c:\windows\system32\WpcUmi.exe" [2006-11-02 176128]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-09-07 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"SigmatelSysTrayApp"="sttray.exe" [2007-03-06 303104]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Digimax Viewer 2.1.lnk - c:\program files\Samsung\Digimax Viewer 2.1\STImgBrowser.exe [2008-2-15 634880]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-9-28 50688]
QuickSet.lnk - c:\windows\Installer\{7F0C4457-8E64-491B-8D7B-991504365D1E}\NewShortcut2_53A01CC614B04512A2E710D39BF83DC4.exe [2007-9-28 45056]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\KASPER~1\KASPER~1\mzvkbd3.dll c:\progra~1\KASPER~1\KASPER~1\adialhk.dll c:\progra~1\KASPER~1\KASPER~1\kloehk.dll c:\progra~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
.
R0 is3srv;is3srv;c:\windows\system32\drivers\is3srv.sys [2009-12-07 61328]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-08-27 136176]
R3 CFcatchme;CFcatchme;c:\users\Toni\AppData\Local\Temp\CFcatchme.sys [x]
R3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2010-08-12 30192]
R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2010-08-27 136176]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2009-10-30 33808]
S0 szkg5;szkg5;c:\windows\system32\DRIVERS\szkg.sys [2009-12-07 61328]
S0 szkgfs;szkgfs;c:\windows\system32\drivers\szkgfs.sys [2010-05-12 59280]
S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys [2008-07-09 20496]
S3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\DRIVERS\klfltdev.sys [2008-03-13 26640]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
2011-10-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-08-27 09:30]
.
2011-10-06 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-08-27 09:30]
.
.
——- Supplementary Scan ——-
.
uStart Page = www.bbc.co.uk
uSearchURL,(Default) = hxxp://search.aol.co.uk/web?isinit=true&query=%s
LSP: c:\windows\system32\wpclsp.dll
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\users\Toni\AppData\Roaming\Mozilla\Firefox\Profiles\syawc8w8.default\
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-10-11 20:42
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\system\controlset002\control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\controlset002\control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\controlset002\control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\iS3\Anti-Spyware\SZServer.exe
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\bcmwltry.exe
c:\program files\Common Files\AOL\ACS\AOLAcsd.exe
c:\program files\Kontiki\KService.exe
c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
c:\windows\system32\STacSV.exe
c:\windows\system32\DRIVERS\xaudio.exe
c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Common Files\iS3\Anti-Spyware\SZScanner.exe
c:\program files\STOPzilla!\STOPzilla.exe
c:\program files\Apple Software Update\SoftwareUpdate.exe
c:\program files\Apple Software Update\SoftwareUpdate.exe
c:\windows\system32\RacAgent.exe
.
**************************************************************************
.
Completion time: 2011-10-11 21:06:08 - machine was rebooted
ComboFix-quarantined-files.txt 2011-10-11 20:05
ComboFix2.txt 2011-10-10 20:27
ComboFix3.txt 2011-10-08 17:09
.
Pre-Run: 8,026,546,176 bytes free
Post-Run: 7,180,894,208 bytes free
.
- - End Of File - - 66E543B6097760F350736F54CEF12A88
Upload was successful