ComboFix 08-04-22.5 - Daddy 2008-04-25 0:48:28.1 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.696 [GMT -4:00]
Running from: C:\Documents and Settings\Daddy\desktop\combofix.exe
Command switches used :: /killall
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\winupdates
C:\Program Files\winupdates\a.zip
C:\Temp\1cb
C:\Temp\abW9
C:\temp\tn3
C:\WINDOWS\cookies.ini
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\bszip.dll
C:\WINDOWS\system32\drivers\usbscann.sys
C:\WINDOWS\system32\mUBbHRqr.ini
C:\WINDOWS\system32\mUBbHRqr.ini2
C:\WINDOWS\system32\qttwyccf.ini
C:\WINDOWS\system32\qttwyccf.ini2
C:\WINDOWS\system32\rMa02yy
C:\WINDOWS\Fonts\'
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_USBSCANN
-------\Service_usbscann
((((((((((((((((((((((((( Files Created from 2008-03-25 to 2008-04-25 )))))))))))))))))))))))))))))))
.
2008-04-22 23:28 . 2008-04-22 23:28 <DIR> d-------- C:\WINDOWS\CAVTemp
2008-04-22 22:52 . 2008-04-22 22:52 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-22 08:03 . 2008-04-22 08:03 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-04-21 22:41 . 2008-04-25 00:56 64,090 --a------ C:\WINDOWS\system32\drivers\kmxcfg.u2k0
2008-04-21 22:41 . 2008-04-25 00:56 64 --a------ C:\WINDOWS\system32\drivers\kmxcfg.u2k7
2008-04-21 22:41 . 2008-04-25 00:56 64 --a------ C:\WINDOWS\system32\drivers\kmxcfg.u2k6
2008-04-21 22:41 . 2008-04-25 00:56 64 --a------ C:\WINDOWS\system32\drivers\kmxcfg.u2k5
2008-04-21 22:41 . 2008-04-25 00:56 64 --a------ C:\WINDOWS\system32\drivers\kmxcfg.u2k4
2008-04-21 22:41 . 2008-04-25 00:56 64 --a------ C:\WINDOWS\system32\drivers\kmxcfg.u2k3
2008-04-21 22:41 . 2008-04-25 00:56 64 --a------ C:\WINDOWS\system32\drivers\kmxcfg.u2k2
2008-04-21 22:41 . 2008-04-25 00:56 64 --a------ C:\WINDOWS\system32\drivers\kmxcfg.u2k1
2008-04-21 19:38 . 2008-04-21 19:38 <DIR> d-------- C:\Program Files\CA
2008-04-21 19:38 . 2008-04-21 19:38 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\CA
2008-04-21 19:38 . 2007-08-20 13:38 879,784 --a------ C:\WINDOWS\system32\drivers\vetefile.sys
2008-04-21 19:38 . 2007-08-20 13:38 108,312 --a------ C:\WINDOWS\system32\drivers\veteboot.sys
2008-04-21 19:38 . 2007-08-20 13:37 99,592 --a------ C:\WINDOWS\system32\isafeif.dll
2008-04-21 19:38 . 2007-08-20 13:26 79,424 --a------ C:\WINDOWS\system32\vetredir.dll
2008-04-21 19:38 . 2007-08-20 13:37 75,016 --a------ C:\WINDOWS\system32\isafprod.dll
2008-04-21 19:38 . 2007-08-20 13:38 32,264 --a------ C:\WINDOWS\system32\drivers\vetmonnt.sys
2008-04-21 19:38 . 2007-08-20 13:38 26,376 --a------ C:\WINDOWS\system32\drivers\vet-filt.sys
2008-04-21 19:38 . 2007-08-20 13:38 21,512 --a------ C:\WINDOWS\system32\drivers\vetfddnt.sys
2008-04-21 19:38 . 2007-08-20 13:38 21,128 --a------ C:\WINDOWS\system32\drivers\vet-rec.sys
2008-04-21 18:16 . 2008-04-21 18:16 230 --a------ C:\WINDOWS\system32\spupdsvc.inf
2008-04-21 11:16 . 2008-04-21 11:16 167,545 --a------ C:\WINDOWS\system32\drivers\core.cache.dsk
2008-04-21 11:02 . 2008-04-21 11:02 <DIR> d-------- C:\Program Files\Picasa2
2008-04-21 08:48 . 2008-04-21 08:48 272,896 --a------ C:\WINDOWS\system32\fccywttq.dll
2008-04-21 08:48 . 2008-04-21 08:48 27,136 --a------ C:\Documents and Settings\Linda\services.exe
2008-04-21 03:39 . 2008-04-21 03:39 <DIR> d-------- C:\Program Files\Common Files\Scanner
2008-04-21 02:27 . 2008-04-21 11:01 1,541,770 ---hs---- C:\WINDOWS\system32\TDQTVYGV.INI
2008-04-21 02:24 . 2008-04-21 02:24 73 --a------ C:\WINDOWS\st_affiliate.ini
2008-04-21 02:19 . 2008-04-22 15:49 109,738 --a------ C:\WINDOWS\BM0e272022.xml
2008-04-21 01:42 . 2008-04-21 01:42 <DIR> d-------- C:\Program Files\Enigma Software Group
2008-04-20 19:10 . 2008-04-20 19:10 297 --a------ C:\102.bat
2008-04-20 18:51 . 2008-04-20 21:48 16 --a------ C:\WINDOWS\system32\coh.cache
2008-04-20 18:25 . 2008-04-20 18:25 63,893 --a------ C:\WINDOWS\system32\{2a85c597-4256-3835-f9b1-a0f0fb38b661}.dll-uninst.exe
2008-04-20 18:24 . 2008-04-20 18:24 400,501 --a------ C:\WINDOWS\system32\g20.exe
2008-04-20 14:16 . 2008-04-20 14:16 <DIR> d-------- C:\Program Files\Safari
2008-04-20 11:36 . 2008-04-20 11:36 147,456 --a------ C:\WINDOWS\system32\vbzip10.dll
2008-04-20 11:35 . 2008-04-20 11:35 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\TEMP
2008-04-20 11:33 . 2008-04-20 11:33 88,961 --a------ C:\WINDOWS\system32\mysidesearch_sidebar_uninstall.exe
2008-04-20 11:33 . 2008-04-20 11:33 862 --a------ C:\WINDOWS\system32\winpfz33.sys
2008-04-20 11:32 . 2008-04-20 11:32 <DIR> d-------- C:\WINDOWS\system32\xcsDd18
2008-04-20 11:32 . 2008-04-20 11:32 <DIR> d-------- C:\WINDOWS\system32\trcTMP
2008-04-20 11:32 . 2008-04-20 11:32 <DIR> d-------- C:\WINDOWS\system32\slNew
2008-04-20 11:32 . 2008-04-20 11:32 <DIR> d-------- C:\WINDOWS\system32\iTmp
2008-04-20 11:32 . 2008-04-20 11:32 <DIR> d-------- C:\temp\berDrv11
2008-04-20 11:32 . 2008-04-20 11:32 298,311 --a------ C:\WINDOWS\system32\gside.exe
2008-04-20 11:32 . 2008-04-20 11:32 200,768 --a------ C:\WINDOWS\system32\qcntrkdn.exe
2008-04-20 11:32 . 2008-04-20 11:32 167,545 --a------ C:\WINDOWS\system32\drivers\core.cache(3).dsk
2008-04-20 11:32 . 2008-04-20 11:32 167,545 --a------ C:\WINDOWS\system32\drivers\core.cache(2).dsk
2008-04-20 11:18 . 2008-04-20 11:18 <DIR> d-------- C:\Program Files\BitDownload
2008-04-20 11:18 . 2008-04-20 11:18 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\INTERNET SPAM SUPPORT AUDIO
2008-04-20 11:05 . 2006-11-13 15:45 1,419,232 --a------ C:\WINDOWS\system32\wdfcoinstaller01005.dll
2008-04-20 11:05 . 2007-04-02 22:13 21,632 --a------ C:\WINDOWS\system32\drivers\motmodem.sys
2008-04-20 10:42 . 2008-04-20 10:42 0 --ah----- C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-04-20 10:42 . 2008-04-20 10:42 0 --ah----- C:\WINDOWS\system32\drivers\Msft_Kernel_motmodem_01005.Wdf
2008-04-20 10:41 . 2008-04-20 10:41 <DIR> d-------- C:\Program Files\Common Files\Motorola Shared
2008-04-09 13:51 . 2008-04-09 13:51 <DIR> d-------- C:\Program Files\iTunes
2008-04-07 12:18 . 2008-04-07 12:18 329,216 --a------ C:\WINDOWS\system32\{2a85c597-4256-3835-f9b1-a0f0fb38b661}.dll
2008-03-31 07:52 . 2008-03-31 07:52 <DIR> d-------- C:\Documents and Settings\Kady\Application Data\WeatherBug
2008-03-28 23:37 . 2008-03-28 23:37 90,112 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx
2008-03-28 23:37 . 2008-03-28 23:37 57,344 --a------ C:\WINDOWS\system32\QuickTime.qts
2008-03-28 15:42 . 2008-03-28 15:42 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2008-03-27 14:34 . 2008-03-27 14:34 <DIR> d-------- C:\Program Files\Common Files\AOL
2008-03-27 14:34 . 2008-03-27 14:34 <DIR> d-------- C:\Program Files\AIM6
2008-03-27 13:08 . 2008-03-27 13:08 <DIR> d-------- C:\Documents and Settings\Daddy\Application Data\Juniper Networks
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-25 02:03 --------- d-----w C:\Documents and Settings\Owner\Application Data\Viewpoint
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-19 09:47 1,845,248 ------w C:\WINDOWS\system32\dllcache\win32k.sys
2008-03-18 22:11 --------- d-----w C:\Documents and Settings\Daddy\Application Data\Viewpoint
2008-03-10 02:59 --------- d-----w C:\Documents and Settings\Kady\Application Data\DivX
2008-03-01 13:06 63,488 ------w C:\WINDOWS\system32\dllcache\icardie.dll
2008-03-01 13:06 6,066,176 ------w C:\WINDOWS\system32\dllcache\ieframe.dll
2008-03-01 13:06 52,224 ------w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-03-01 13:06 459,264 ------w C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-03-01 13:06 383,488 ------w C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-03-01 13:06 267,776 ------w C:\WINDOWS\system32\dllcache\iertutil.dll
2008-02-28 13:18 67,632 ----a-w C:\Documents and Settings\Linda\Application Data\GDIPFONTCACHEV1.DAT
2008-02-22 10:00 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 06:51 282,624 ------w C:\WINDOWS\system32\dllcache\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-20 05:32 45,568 ------w C:\WINDOWS\system32\dllcache\dnsrslvr.dll
2008-02-20 05:32 148,992 ------w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-02-16 22:29 3,059,712 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2008-02-15 09:23 18,432 ----a-w C:\WINDOWS\system32\dllcache\iedw.exe
2008-02-14 21:17 67,632 ----a-w C:\Documents and Settings\Owner\Application Data\GDIPFONTCACHEV1.DAT
2008-02-14 01:51 67,632 ----a-w C:\Documents and Settings\Daddy\Application Data\GDIPFONTCACHEV1.DAT
2008-02-08 10:48 67,632 ----a-w C:\Documents and Settings\Kady\Application Data\GDIPFONTCACHEV1.DAT
2008-02-08 04:50 51,716 ----a-w C:\WINDOWS\system32\pdf995mon.dll
2008-02-08 04:50 249,856 ----a-w C:\WINDOWS\system32\pdfmona.dll
2008-02-04 22:23 693,792 ----a-w C:\WINDOWS\system32\OGACheckControl.DLL
2008-01-29 16:02 107,368 ----a-w C:\WINDOWS\system32\GEARAspi.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9dac258d-6a94-335b-7525-fc3d6f8e086d}]
2008-04-07 12:18 329216 --a------ C:\WINDOWS\system32\{2a85c597-4256-3835-f9b1-a0f0fb38b661}.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-05 23:05 68856]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 12:24 1694208]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 17:43 4670704]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56 15360]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45 313472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-12-17 14:29 180269]
"ymetray"="C:\Program Files\Yahoo!\Yahoo! Music Engine\YahooMusicEngine.exe" [ ]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2007-06-08 09:59 224248]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"cctray"="C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe" [2007-08-16 22:19 177416]
"QOELOADER"="C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe" [2008-04-21 19:38 14088]
"CAVRID"="C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe" [2007-08-20 13:36 230664]
"cafwc"="C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe" [2008-02-05 11:19 1193224]
"capfasem"="C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe" [2008-02-05 11:19 173320]
"capfupgrade"="C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe" [2008-02-05 11:19 259336]
"BM0e272022"="C:\WINDOWS\system32\dfekblrt.dll" [ ]
C:\Documents and Settings\Owner\Start Menu\Programs\Startup\
GameSpot Download Manager.lnk - C:\Program Files\GameSpot\GDM_TrayApp.exe [2007-05-09 12:48:26 237568]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04 83360]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696]
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-07-16 21:51:34 113664]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\efcCsRli]
efcCsRli.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PFW]
UmxWnp.Dll 2007-05-18 13:30 79368 C:\WINDOWS\system32\UmxWNP.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"= ctwdm32.dll
"MSACM.CEGSM"= mobilev.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\CA Personal Firewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\System32\\LEXPPS.EXE"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\Microsoft ActiveSync\\WCESCOMM.EXE"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
R0 KmxStart;KmxStart;C:\WINDOWS\system32\DRIVERS\kmxstart.sys [2007-10-18 10:24]
R1 KmxAgent;KmxAgent;C:\WINDOWS\system32\DRIVERS\kmxagent.sys [2007-05-18 13:30]
R1 KmxFile;KmxFile;C:\WINDOWS\system32\DRIVERS\KmxFile.sys [2007-05-18 13:30]
R1 KmxFw;KmxFw;C:\WINDOWS\system32\DRIVERS\kmxfw.sys [2007-10-18 14:21]
R2 KmxCF;KmxCF;C:\WINDOWS\system32\DRIVERS\KmxCF.sys [2007-10-18 10:24]
R2 KmxSbx;KmxSbx;C:\WINDOWS\system32\DRIVERS\KmxSbx.sys [2007-11-02 12:09]
R2 UmxAgent;HIPS Event Manager;"C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe" [2007-10-18 10:24]
R2 UmxCfg;HIPS Configuration Interpreter;"C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe" [2007-10-18 10:24]
R2 UmxPol;HIPS Policy Manager;"C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe" [2007-05-18 13:30]
R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 16:38]
R3 KmxCfg;KmxCfg;C:\WINDOWS\system32\DRIVERS\kmxcfg.sys [2007-09-13 15:15]
R3 PPCtlPriv;PPCtlPriv;"C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe" [2007-08-16 21:10]
S3 iscFlash;iscFlash;C:\WINDOWS\SYSTEM32\DRIVERS\iscflash.sys []
S3 SupportSoft RemoteAssist;SupportSoft RemoteAssist;C:\Program Files\Common Files\supportsoft\bin\ssrc.exe [2007-12-11 04:39]
*Newly Created Service* - GTNDIS5
.
Contents of the 'Scheduled Tasks' folder
"2008-04-23 15:38:12 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-25 01:23:18
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\SYSTEM32\LEXBCES.EXE
C:\WINDOWS\SYSTEM32\LEXPPS.EXE
C:\PROGRAM FILES\CA\SHAREDCOMPONENTS\HIPSENGINE\UMXFWHLP.EXE
C:\PROGRAM FILES\COMMON FILES\APPLE\MOBILE DEVICE SUPPORT\BIN\APPLEMOBILEDEVICESERVICE.EXE
C:\PROGRAM FILES\BONJOUR\MDNSRESPONDER.EXE
C:\PROGRAM FILES\CA\CA INTERNET SECURITY SUITE\CA ANTI-VIRUS\ISAFE.EXE
C:\PROGRAM FILES\CA\SHAREDCOMPONENTS\PPRT\BIN\ITMRTSVC.EXE
C:\PROGRAM FILES\CA\CA INTERNET SECURITY SUITE\CA ANTI-VIRUS\VETMSG.EXE
C:\PROGRAM FILES\LINKSYS WIRELESS-G PCI WIRELESS NETWORK MONITOR\WLSERVICE.EXE
C:\PROGRAM FILES\LINKSYS WIRELESS-G PCI WIRELESS NETWORK MONITOR\WMP54GV4.EXE
C:\PROGRAM FILES\COMPACT WIRELESS-G USB ADAPTER WIRELESS NETWORK MONITOR\WLSERVICE.EXE
C:\PROGRAM FILES\COMPACT WIRELESS-G USB ADAPTER WIRELESS NETWORK MONITOR\WUSB54GC.EXE
C:\PROGRAM FILES\VIEWPOINT\VIEWPOINT MANAGER\VIEWMGR.EXE
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
.
**************************************************************************
.
Completion time: 2008-04-25 1:28:48 - machine was rebooted [Daddy]
ComboFix-quarantined-files.txt 2008-04-25 05:27:50
Pre-Run: 29,453,910,016 bytes free
Post-Run: 34,805,776,384 bytes free
252 --- E O F --- 2008-04-22 12:09:11