Hi oldman960,
Zero Access was still detected.
No files mentioned in the pop-up warning but said it was in the tcp/ip stack.
Computer is running good in spite of the above.
Thanks for your help.
OTL and ComboFix logs follow:
_________________________________
All processes killed
========== SERVICES/DRIVERS ==========
========== FILES ==========
C:\TDSSKiller_Quarantine\29.03.2013_14.17.21\tdlfs0000 folder moved successfully.
C:\TDSSKiller_Quarantine\29.03.2013_14.17.21 folder moved successfully.
C:\TDSSKiller_Quarantine\29.03.2013_12.31.03\mbr0000\tdlfs0000 folder moved successfully.
C:\TDSSKiller_Quarantine\29.03.2013_12.31.03\mbr0000\mbr0000 folder moved successfully.
C:\TDSSKiller_Quarantine\29.03.2013_12.31.03\mbr0000 folder moved successfully.
C:\TDSSKiller_Quarantine\29.03.2013_12.31.03 folder moved successfully.
C:\TDSSKiller_Quarantine folder moved successfully.
File\Folder C:\Documents and Settings\Amy\Local Settings\Application Data\{71EA6046-8286-4ADC-BF58-501E76626E60} not found.
C:\Documents and Settings\Amy\Application Data\F8825A71ED75651A8D57DC362A93BB58 folder moved successfully.
C:\Program Files\DotSpot_2kEI\Installr\1.bin folder moved successfully.
C:\Program Files\DotSpot_2kEI\Installr folder moved successfully.
C:\Program Files\DotSpot_2kEI folder moved successfully.
< rmdir C:\WINDOWS\$NtUninstallKB32607$ /c >
C:\Documents and Settings\Amy\Desktop\cmd.bat deleted successfully.
C:\Documents and Settings\Amy\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: All Users
User: Amy
->Temp folder emptied: 81226866 bytes
->Temporary Internet Files folder emptied: 158292790 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 1221 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 0 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 274163710 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 490.00 mb
Restore point Set: OTL Restore Point
OTL by OldTimer - Version 3.2.69.0 log created on 04112013_063544
Files\Folders moved on Reboot…
PendingFileRenameOperations files…
Registry entries deleted on Reboot…
_______________________________________________
ComboFix 13-04-10.02 - Amy 04/11/2013 6:56.7.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3326.2919 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
* Resident AV is active
.
.
.
((((((((((((((((((((((((( Files Created from 2013-03-11 to 2013-04-11 )))))))))))))))))))))))))))))))
.
.
2013-04-10 17:13 . 2013-04-10 17:13 ——– d—–w- c:\program files\ESET
2013-03-30 17:21 . 2012-12-14 20:49 21104 —-a-w- c:\windows\system32\drivers\mbam.sys
2013-03-29 18:18 . 2013-03-29 18:18 ——– d—–w- c:\documents and settings\Amy\Local Settings\Application Data\Sun
2013-03-29 18:15 . 2013-03-29 18:15 ——– d—–w- c:\documents and settings\Amy\Local Settings\Application Data\PCHealth
2013-03-29 17:29 . 2013-03-29 17:28 143872 —-a-w- c:\windows\system32\javacpl.cpl
2013-03-29 17:29 . 2013-03-29 17:28 861088 —-a-w- c:\windows\system32\npDeployJava1.dll
2013-03-29 17:29 . 2013-03-29 17:28 94112 —-a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-03-29 17:28 . 2013-03-29 17:28 ——– d—–w- c:\program files\Java
2013-03-28 18:03 . 2008-04-13 18:31 36352 —-a-w- c:\windows\system32\drivers\intelppm.sys
2013-03-28 18:03 . 2008-04-13 18:31 36352 —-a-w- c:\windows\system32\dllcache\intelppm.sys
2013-03-27 20:02 . 2013-03-27 20:02 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2013-03-27 20:00 . 2013-03-27 20:00 ——– d—–w- c:\program files\Mozilla Maintenance Service
2013-03-18 16:37 . 2013-03-18 18:09 ——– d—–w- C:\jgh
2013-03-14 14:50 . 2013-03-14 14:50 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\BVRP Software
2013-03-13 20:26 . 2013-03-13 20:26 ——– d-sh–w- c:\documents and settings\Administrator\PrivacIE
2013-03-13 20:12 . 2013-03-13 20:12 ——– d-sh–w- c:\documents and settings\Administrator\IETldCache
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-03-29 17:28 . 2010-09-22 13:36 782240 —-a-w- c:\windows\system32\deployJava1.dll
2013-03-29 17:18 . 2012-06-01 11:51 693976 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2013-03-29 17:18 . 2012-02-13 15:40 73432 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-03-08 08:36 . 2004-08-04 11:00 293376 —-a-w- c:\windows\system32\winsrv.dll
2013-03-07 01:32 . 1980-01-01 06:00 2149888 —-a-w- c:\windows\system32\ntoskrnl.exe
2013-03-07 00:50 . 1980-01-01 06:00 2028544 —-a-w- c:\windows\system32\ntkrnlpa.exe
2013-03-02 02:06 . 2004-08-04 11:00 916480 —-a-w- c:\windows\system32\wininet.dll
2013-03-02 02:06 . 2004-08-04 11:00 43520 ——w- c:\windows\system32\licmgr10.dll
2013-03-02 02:06 . 2004-08-04 11:00 1469440 ——w- c:\windows\system32\inetcpl.cpl
2013-03-02 01:25 . 2004-08-04 11:00 1867264 —-a-w- c:\windows\system32\win32k.sys
2013-03-02 01:08 . 2004-08-04 11:00 385024 ——w- c:\windows\system32\html.iec
2013-02-27 07:56 . 2004-08-04 11:00 2067456 —-a-w- c:\windows\system32\mstscax.dll
2013-02-19 19:15 . 2012-04-10 17:30 60920 —-a-w- c:\windows\system32\drivers\cfwids.sys
2013-02-19 19:12 . 2012-04-10 17:20 172416 —-a-w- c:\windows\system32\mfevtps.exe
2013-02-19 19:11 . 2012-04-10 17:30 91640 —-a-w- c:\windows\system32\drivers\mfetdi2k.sys
2013-02-19 19:11 . 2012-04-10 17:30 10088 —-a-w- c:\windows\system32\drivers\mfeclnk.sys
2013-02-19 19:10 . 2012-04-10 17:30 92632 —-a-w- c:\windows\system32\drivers\mferkdet.sys
2013-02-19 19:09 . 2011-10-15 16:16 565888 —-a-w- c:\windows\system32\drivers\mfehidk.sys
2013-02-19 19:09 . 2012-12-17 15:09 84904 —-a-w- c:\windows\system32\drivers\mfendisk.sys
2013-02-19 19:09 . 2012-04-10 17:30 363080 —-a-w- c:\windows\system32\drivers\mfefirek.sys
2013-02-19 19:08 . 2012-04-10 17:30 65928 —-a-w- c:\windows\system32\drivers\mfebopk.sys
2013-02-19 19:08 . 2012-04-10 17:30 235264 —-a-w- c:\windows\system32\drivers\mfeavfk.sys
2013-02-19 19:07 . 2011-10-15 16:16 133416 —-a-w- c:\windows\system32\drivers\mfeapfk.sys
2013-02-12 00:32 . 2008-09-03 23:47 12928 ——w- c:\windows\system32\drivers\usb8023x.sys
2013-02-12 00:32 . 2004-08-04 11:00 12928 —-a-w- c:\windows\system32\drivers\usb8023.sys
2013-01-26 03:55 . 2004-08-04 11:00 552448 —-a-w- c:\windows\system32\oleaut32.dll
2013-03-07 14:31 . 2013-03-27 20:00 263064 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-04-21 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-08-25 339968]
"IntelMeM"="c:\program files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-04 221184]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-10-12 57344]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2004-01-07 110592]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-08-13 122939]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2005-01-05 98304]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"ControlCenter2.0"="c:\program files\Brother\ControlCenter2\brctrcen.exe" [2007-10-30 77824]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-10-10 185784]
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2007-10-11 29984]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2007-10-11 46368]
"PPort11reminder"="c:\program files\ScanSoft\PaperPort\Ereg\Ereg.exe" [2007-08-31 328992]
"BrMfcWnd"="c:\program files\Brother\Brmfcmon\BrMfcWnd.exe" [2009-02-10 745472]
"ControlCenter3"="c:\program files\Brother\ControlCenter3\brctrcen.exe" [2007-10-30 77824]
"Memeo Instant Backup"="c:\program files\Memeo\AutoBackup\MemeoLauncher2.exe" [2010-12-11 136416]
"Seagate Dashboard"="c:\program files\Seagate\Seagate Dashboard\MemeoLauncher.exe" [2011-11-03 73728]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-01-04 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2013-01-14 1278064]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
.
c:\documents and settings\Amy\Start Menu\Programs\Startup\
TrayDay.lnk - c:\program files\TrayDay\TrayDay.exe [2005-1-28 204800]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Google Calendar Sync.lnk - c:\program files\Google\Google Calendar Sync\GoogleCalendarSync.exe [2011-4-8 542264]
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\3.0.318\SSScheduler.exe [2013-2-5 272248]
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2005-1-20 724992]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToMyPC]
2011-11-13 12:53 15216 —-a-w- c:\program files\Citrix\GoToMyPC\G2WinLogon.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Seagate\\Seagate Dashboard\\HipServAgent\\HipServAgent.exe"=
.
R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\SYSTEM32\DRIVERS\mfetdi2k.sys [4/10/2012 1:30 PM 91640]
R2 LxrSII1d;Secure II Driver;c:\windows\SYSTEM32\DRIVERS\LxrSII1d.sys [5/13/2008 2:31 PM 72672]
R2 McNaiAnn;McAfee VirusScan Announcer;"c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [4/10/2012 1:30 PM 167784]
R2 MemeoBackgroundService;MemeoBackgroundService;c:\program files\Memeo\AutoBackup\MemeoBackgroundService.exe [12/10/2010 9:49 PM 25824]
R2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\Mcafee\SystemCore\mfefire.exe [4/10/2012 1:31 PM 169320]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\SYSTEM32\mfevtps.exe [4/10/2012 1:20 PM 172416]
R2 RapidPortM1;RapidPortM1;c:\windows\SYSTEM32\DRIVERS\CAPM1LP.SYS [2/23/2005 7:04 PM 22912]
R2 SeagateDashboardService;Seagate Dashboard Service;c:\program files\Seagate\Seagate Dashboard\SeagateDashboardService.exe [11/3/2011 2:10 PM 8704]
R3 mfefirek;McAfee Inc. mfefirek;c:\windows\SYSTEM32\DRIVERS\mfefirek.sys [4/10/2012 1:30 PM 363080]
R3 mfendiskmp;mfendiskmp;c:\windows\SYSTEM32\DRIVERS\mfendisk.sys [12/17/2012 11:09 AM 84904]
S3 cfwids;McAfee Inc. cfwids;c:\windows\SYSTEM32\DRIVERS\cfwids.sys [4/10/2012 1:30 PM 60920]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\3.0.318\McCHSvc.exe [2/5/2013 11:48 AM 235216]
S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\SYSTEM32\DRIVERS\mfendisk.sys [12/17/2012 11:09 AM 84904]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\SYSTEM32\DRIVERS\mferkdet.sys [4/10/2012 1:30 PM 92632]
S4 xmasbus;xmasbus;c:\windows\SYSTEM32\DRIVERS\xmasbus.sys [2/4/2005 2:11 PM 140800]
S4 xmasscsi;xmasscsi;c:\windows\SYSTEM32\DRIVERS\xmasscsi.sys [2/4/2005 2:11 PM 5504]
.
— Other Services/Drivers In Memory —
.
*Deregistered* - mfeavfk01
.
Contents of the 'Scheduled Tasks' folder
.
2013-04-10 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-01 17:18]
.
2013-04-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-22 20:34]
.
2005-01-07 c:\windows\Tasks\ISP signup reminder 1.job
- c:\windows\system32\OOBE\OOBEBALN.EXE [2004-08-04 00:12]
.
2013-04-10 c:\windows\Tasks\ReclaimerUpdateFiles_Amy.job
- c:\documents and settings\Amy\Application Data\Real\Update\UpgradeHelper\RealPlayer\10.40\agent\rnupgagent.exe [2013-03-29 17:08]
.
2013-04-10 c:\windows\Tasks\ReclaimerUpdateXML_Amy.job
- c:\documents and settings\Amy\Application Data\Real\Update\UpgradeHelper\RealPlayer\10.40\agent\rnupgagent.exe [2013-03-29 17:08]
.
2013-04-11 c:\windows\Tasks\RNUpgradeHelperLogonPrompt_Amy.job
- c:\documents and settings\Amy\Application Data\Real\Update\UpgradeHelper\RealPlayer\10.40\agent\rnupgagent.exe [2013-03-29 17:08]
.
2013-04-10 c:\windows\Tasks\User_Feed_Synchronization-{9F65D221-A6DA-4935-A0FB-B46D030E6DFB}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 08:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
mStart Page =
uInternet Connection Wizard,ShellNext = hxxp://www.dell4me.com/myway
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
TCP: DhcpNameServer = [removed] [removed]
DPF: {A762E064-A885-40E4-AC10-671BB62DC2B2} - hxxp://www.eomniform.com/OF5/nsplugins/OFMailX.cab
FF - ProfilePath -
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2013-04-11 07:12
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG08.00.00.01WORKSTATION"="4FDA30922D1D3A4A1A518A89786166259F7EDB5C427B6808351193CC975D2AF0366B0F1D0D2
9192344801B1DA40F8878C6AF3B417DB9EAC349444851CFCDD2C520FADA1F447948AE66148D529013
6FAD41FB00C56744F61778843EEBB9CBE595E3A5E2CF484EA8ED9D5A9C1B05ACF5CE1083F2333F7C8
7B3CA5D6961A87C1C5C2B89678E23ABCC46D823758EE164ADC908E54DF9DA09C8B29762B11806445F
7876CB1C5A70DAFB82DBC2FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BE
CC74CFEBC9E127BECC74CFEBC9E127BECC74C8EDD5E5BE2F6E667C038D530D6EB3452A6A0AC4980AC
7933BA7FD869164D679495747435A8FAC96341B3DE98263F27383A1B78105C0A222DC2209BCEE5FCA
1B5F1912D37D708A550DD8E2F2D5E33805417129D6F9D6DDC5C788D9F09E36E97BCC0958BD1B4AAE9
090018327694D560A956A9839D36F5A005FAE07D91E80208B41FBE6C83E01A0F499528FA5547C6822
752F4157BA34C1065B38514688D8A98CAA471C58F33735ED1803CB46EA90DF7BB59A850AF96019EBE
FD89D756A040433356B4207E3738766494751C2AA491235D2D1F4722F285965527A14F63A1BDD524B
1B516982ACA4B4A9B1982B35121BC8384D5A10251AF92F37222965D4783F057A6435970FEF3A24DD1
0ECC7C036DCFAB886F183D7EBB04E79607DA58FBF38B8C19522FD65DE1193F68E275B6390C3DD5573
1F98B7B463104C0F062A9DB57EF066079EDE29EA21BF1044988DC2E76B6878286A8E57CD2B01C8D9F
02EAB857B98A4AF50271D02CEB3E3F93A7A94C89C54991FA9B08E947F18B11FCA5FA18855DE394A6E
CA038D5247EA53D089D34074727FC415B7460EEB3AED2914D7B33531FE1F411C253C95D2D15B86173
FBB61468B2B4AF08EFAF760B67CC0E0BD2789A985713DAAA3130624562EC42464E5E3A2DFE97C0D20
3DCF0609B6E4407AA0A94B71A0AD1E1254B697FCFACC37260E5676F267E9082FAA155F1359BAA7D72
3BE1BE046B64385E2C59C349546FFCC1BC6DD8C3B363F0EAE87ECEA229DDBBDB1705C3753A2891CF9
901CB3D34F000C785006A79721E0CA453295D53E49B25DB5AE530D06ED2E7318E1026A0921BA70918
3AF7EBEEC8D744B67955BD8B47332EF7CFC07B7542C5FDB99A376A27E135E201972943CE1468A41AF
3445DD167EECF13F108E12C75CBF3FC983416A0DD00757D7B792C2CD06969BA050A2D5DA679838860
6CF1EA112F97EF6828231D4D6E2405AA38D61574987589F9DB31CAD4044F6291279DF5DB37AEDAC7F
016B50FFE183BCC89798A994872AA84426D27E457FCE46146DB8B4241C5BFDB44F57029C3BB7D72E6
CA037D5F4EF53D9A6BF6EB4D1B8390AAA7DA54BBAACD2FA54E4B44DF415B0B9888E982573A789C153
A312657FBE8400B0009C5ACF16DAA"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(1076)
c:\program files\Citrix\GoToMyPC\G2WinLogon.dll
.
Completion time: 2013-04-11 07:16:01
ComboFix-quarantined-files.txt 2013-04-11 11:15
ComboFix2.txt 2013-04-05 18:37
ComboFix3.txt 2013-03-29 19:11
ComboFix4.txt 2013-03-28 18:24
ComboFix5.txt 2013-04-11 10:48
.
Pre-Run: 37,115,568,128 bytes free
Post-Run: 37,101,027,328 bytes free
.
- - End Of File - - 354D7813E6BBF0A6422F57642FB8D199