ComboFix 10-05-10.05 - Windows XP 11/05/2010 23:05:27.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2046.1286 [GMT 1:00]
Running from: c:\documents and settings\Windows XP\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
AV: Spyware Doctor with AntiVirus *On-access scanning disabled* (Updated) {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\1677677782.dat
c:\windows\system32\STEC3.sys
c:\windows\system32\vb40032.dll
Infected copy of c:\windows\system32\drivers\iaStor.sys was found and disinfected
Restored copy from - Kitty had a snack
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_EVENTSYSTEMRPCLOCATOR
-------\Legacy_STEC3
-------\Legacy_XMLPROVCLR_OPTIMIZATION_V2.0.50727_32
-------\Service_EventSystemRpcLocator
-------\Service_STEC3
-------\Service_xmlprovclr_optimization_v2.0.50727_32
((((((((((((((((((((((((( Files Created from 2010-04-11 to 2010-05-11 )))))))))))))))))))))))))))))))
.
2010-05-11 22:07 . 2010-05-11 22:07 -------- d-----w- c:\windows\LastGood.Tmp
2010-05-11 21:51 . 2010-05-11 21:51 -------- d-----w- c:\documents and settings\Windows XP\Application Data\AVG9
2010-05-10 22:49 . 2010-05-10 22:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-05-10 22:49 . 2010-05-10 22:49 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-05-10 22:46 . 2010-05-10 22:46 -------- d-----w- c:\program files\Trend Micro
2010-05-10 22:28 . 2010-05-10 22:28 -------- d-----w- c:\documents and settings\Windows XP\Application Data\Malwarebytes
2010-05-10 22:28 . 2010-04-29 14:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-05-10 22:28 . 2010-05-10 22:28 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-05-10 22:28 . 2010-04-29 14:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-05-10 22:28 . 2010-05-10 22:28 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-05-10 21:36 . 2010-05-10 21:36 -------- d-----w- C:\$AVG
2010-05-10 20:41 . 2010-05-10 20:41 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2010-05-10 20:41 . 2010-05-10 20:41 242896 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-05-10 20:41 . 2010-05-10 20:41 216200 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-05-10 20:41 . 2010-05-10 20:41 29512 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-05-10 20:40 . 2010-05-11 21:20 -------- d-----w- c:\windows\system32\drivers\Avg
2010-05-10 20:40 . 2010-05-10 21:40 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2010-05-10 20:38 . 2010-05-10 20:38 -------- d-----w- c:\program files\AVG
2010-05-10 20:38 . 2010-05-10 20:38 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2010-05-05 19:07 . 2010-05-05 19:07 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2010-05-05 18:57 . 2010-05-05 18:57 -------- d-----w- c:\documents and settings\Windows XP\Local Settings\Application Data\Threat Expert
2010-05-05 18:47 . 2010-01-22 08:55 767952 ----a-w- c:\windows\BDTSupport.dll
2010-05-05 18:47 . 2010-01-22 08:56 149456 ----a-w- c:\windows\SGDetectionTool.dll
2010-05-05 18:47 . 2010-01-22 08:56 165840 ----a-w- c:\windows\PCTBDRes.dll
2010-05-05 18:47 . 2010-01-22 08:56 1652688 ----a-w- c:\windows\PCTBDCore.dll
2010-05-05 18:47 . 2009-10-28 00:36 1152444 ----a-w- c:\windows\UDB.zip
2010-05-05 18:47 . 2008-11-26 11:08 131 ----a-w- c:\windows\IDB.zip
2010-05-05 18:40 . 2010-02-05 08:17 233136 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2010-05-05 18:40 . 2010-03-29 09:06 218592 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2010-05-05 18:40 . 2009-11-23 12:54 88040 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2010-05-05 18:40 . 2010-04-08 13:29 63360 ----a-w- c:\windows\system32\drivers\pctplsg.sys
2010-05-05 18:40 . 2010-05-07 15:37 -------- d-----w- c:\program files\Spyware Doctor
2010-05-05 18:40 . 2010-05-05 18:47 -------- d-----w- c:\program files\Common Files\PC Tools
2010-05-05 18:40 . 2010-05-05 18:40 -------- d-----w- c:\documents and settings\Windows XP\Application Data\PC Tools
2010-05-05 18:40 . 2010-05-05 18:40 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
2010-05-05 18:40 . 2010-05-11 22:15 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-04-14 17:32 . 2010-04-14 17:32 339968 ----a-w- c:\windows\system32\RapportBuka.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-11 22:18 . 2009-06-27 16:00 -------- d-----w- c:\documents and settings\All Users\Application Data\Kontiki
2010-05-11 22:15 . 2009-01-29 18:25 -------- d-----w- c:\program files\DNA
2010-05-11 22:15 . 2009-01-29 18:25 -------- d-----w- c:\documents and settings\Windows XP\Application Data\DNA
2010-05-11 11:04 . 2009-01-29 18:25 -------- d-----w- c:\documents and settings\Windows XP\Application Data\BitTorrent
2010-05-11 11:03 . 2008-01-17 13:23 -------- d-----w- c:\documents and settings\Windows XP\Application Data\uTorrent
2010-05-10 22:03 . 2005-08-16 19:54 -------- d-----w- c:\program files\DIGStream
2010-05-10 21:36 . 2009-08-19 17:05 -------- d-----w- c:\documents and settings\Windows XP\Application Data\Aleba
2010-05-10 16:51 . 2009-08-23 15:30 -------- d-----w- c:\documents and settings\Windows XP\Application Data\Ciba
2010-05-07 15:20 . 2007-06-26 10:16 -------- d-----w- c:\program files\McAfee
2010-05-06 15:21 . 2009-02-03 14:06 -------- d-----w- c:\documents and settings\LocalService\Application Data\SACore
2010-05-03 16:06 . 2009-11-30 20:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-04-19 09:25 . 2010-05-10 21:40 2117704 ----a-w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar\IEToolbar.dll
2010-03-13 18:07 . 2009-10-03 11:02 256 ----a-w- c:\windows\system32\pool.bin
2010-03-11 12:38 . 2005-08-16 03:18 832512 ----a-w- c:\windows\system32\wininet.dll
2010-03-11 12:38 . 2005-08-16 03:18 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-03-11 12:38 . 2005-08-16 03:18 17408 ----a-w- c:\windows\system32\corpol.dll
2010-03-09 11:09 . 2005-08-16 03:18 430080 ----a-w- c:\windows\system32\vbscript.dll
2010-03-03 17:19 . 2010-03-03 17:19 390528 ----a-w- c:\windows\system32\drivers\RapportBuka.sys
2010-03-03 17:19 . 2010-03-03 17:19 390528 ----a-w- c:\documents and settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportBukaBroom\13897\RapportBuka.sys
2010-03-03 17:19 . 2010-03-03 17:19 249856 ----a-w- c:\documents and settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportBukaBroom\13897\RapportBukaBroom.dll
2010-02-27 16:08 . 2010-02-27 16:08 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\Safari 5.31.21.10\SetupAdmin.exe
2010-02-27 15:51 . 2010-02-27 15:51 72488 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe
2010-02-25 19:40 . 2007-06-26 10:21 86456 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-25 18:13 . 2010-02-25 18:11 256 ----a-w- c:\documents and settings\Windows XP\pool.bin
2010-02-24 12:31 . 2005-08-16 03:18 454016 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-16 17:35 . 2005-08-16 03:18 2143744 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-02-16 16:57 . 2004-08-03 21:59 2021888 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-12 10:03 . 2010-03-17 18:23 293376 ------w- c:\windows\system32\browserchoice.exe
2010-02-12 04:47 . 2005-08-16 03:18 100864 ----a-w- c:\windows\system32\6to4svc.dll
2010-02-11 12:01 . 2005-08-16 03:18 226880 ----a-w- c:\windows\system32\drivers\tcpip6.sys
2007-12-26 11:40 . 2007-12-26 11:40 899414 ----a-w- c:\program files\SetupDVDDecrypter_3.5.4.0.exe
2007-12-25 21:55 . 2007-12-25 21:55 7151072 ----a-w- c:\program files\Ipod converter.exe
2007-12-22 17:06 . 2007-12-22 17:06 1206366 ----a-w- c:\program files\WINRAR.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2010-04-19 09:25 2117704 ----a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-10-07 323392]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-16 68856]
"kdx"="c:\program files\Kontiki\KHost.exe" [2008-10-21 1032640]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 218032]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-06-10 8429568]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
"SigmatelSysTrayApp"="stsystra.exe" [2006-07-24 282624]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2006-07-06 151552]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 94208]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-09-11 218032]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-09-11 86960]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2009-11-15 30192]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-10-29 1218008]
"kdx"="c:\program files\Kontiki\KHost.exe" [2008-10-21 1032640]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-10 417792]
"Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2007-02-21 366400]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-02-15 141608]
"BlackBerryAutoUpdate"="c:\program files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe" [2009-11-19 623960]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-10 15360]
c:\documents and settings\Windows XP\Start Menu\Programs\Startup\
DesktopEarth AutoStart.lnk - c:\documents and settings\Windows XP\Application Data\Microsoft\Installer\{DBA5E973-660D-4CBE-A469-F5C37FBF0CE4}\_C1A9BF9D98647632ED5172.exe [2009-8-11 29926]
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-05-10 20:41 12464 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Shareaza\\Shareaza.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Kontiki\\KService.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [05/05/2010 19:40 218592]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [10/05/2010 21:41 216200]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [10/05/2010 21:41 242896]
R1 RapportBuka;RapportBuka;c:\windows\system32\drivers\RapportBuka.sys [03/03/2010 18:19 390528]
R1 RapportKELL;RapportKELL;c:\program files\Trusteer\Rapport\bin\RapportKELL.sys [15/03/2010 14:47 58984]
R1 RapportPG;RapportPG;c:\program files\Trusteer\Rapport\bin\RapportPG.sys [15/03/2010 14:47 116328]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [10/05/2010 21:39 308064]
R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\Spyware Doctor\BDT\BDTUpdateService.exe [05/05/2010 19:47 112592]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [03/02/2009 15:03 210216]
R2 RapportMgmtService;Rapport Management Service;c:\program files\Trusteer\Rapport\bin\RapportMgmtService.exe [15/03/2010 14:47 779496]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [29/01/2010 13:15 135664]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\AVG\AVG9\Toolbar\ToolbarBroker.exe [10/05/2010 21:40 430152]
S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [26/06/2007 11:18 30192]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [05/05/2010 19:40 366840]
.
Contents of the 'Scheduled Tasks' folder
2010-03-13 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 11:34]
2010-05-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-29 12:15]
2010-05-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-29 12:15]
2007-06-26 c:\windows\Tasks\McDefragTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2007-06-26 11:22]
2007-06-26 c:\windows\Tasks\McQcTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2007-06-26 11:22]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.co.uk/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://uk.search.yahoo.com/search?fr=mcafee&p=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-{4A3869D1-C88B-668A-771D-BA903740048B} - c:\documents and settings\Windows XP\Application Data\Aleba\yrnak.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-05-11 23:17
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(6824)
c:\windows\system32\WININET.dll
c:\program files\McAfee\SiteAdvisor\saHook.dll
c:\program files\Trusteer\Rapport\bin\rooksbas.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\hnetcfg.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\documents and settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S30RP1.EXE
c:\program files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
c:\program files\Kontiki\KService.exe
c:\windows\stsystra.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\program files\DesktopEarth\DesktopEarth.exe
c:\progra~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\progra~1\McAfee\VIRUSS~1\mcshield.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\program files\McAfee\MPF\MPFSrv.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\UAService7.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wscntfy.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\eHome\ehmsas.exe
.
**************************************************************************
.
Completion time: 2010-05-11 23:21:13 - machine was rebooted
ComboFix-quarantined-files.txt 2010-05-11 22:21
Pre-Run: 99,734,421,504 bytes free
Post-Run: 100,104,933,376 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect
- - End Of File - - 7C526D49119AE966B1B268E26B8DA5B1