Ok restored
I had to restore back to 18th- got my data and saved it off pc. Re-did all steps back to this point here are fresh logs.
combofix
ComboFix 09-05-22.05 - Dee 23/05/2009 0:05.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.895.391 [GMT 1:00]
Running from: c:\documents and settings\Dee\Desktop\SYSTEMTOOLS\worknow.com.exe
AV: AVG Anti-Virus *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\install.exe
c:\program files\IEToolbar
c:\program files\IEToolbar\BANS Toolbar\tbhelper.dll
c:\program files\IEToolbar\BANS Toolbar\uninstall.exe
c:\windows\a3kebook.ini
c:\windows\akebook.ini
c:\windows\ANS2000.INI
c:\windows\system32\Ijl11.dll
c:\windows\system32\oledb32.dll
E:\Autorun.inf
E:\Desktop.ini
.
((((((((((((((((((((((((( Files Created from 2009-04-22 to 2009-05-22 )))))))))))))))))))))))))))))))
.
2009-05-22 22:44 . 2009-04-06 14:32 15504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-05-22 22:44 . 2009-04-06 14:32 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-21 14:29 . 2009-05-22 20:48 -------- d-sh--w C:\RECYCLER(2)
2009-05-20 00:00 . 2009-05-20 00:00 -------- d-----w c:\documents and settings\Dee\Application Data\Malwarebytes
2009-05-20 00:00 . 2009-05-22 22:44 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-05-20 00:00 . 2009-05-20 00:00 -------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-05-17 22:54 . 2009-05-17 22:54 -------- d-----w c:\program files\ERUNT
2009-05-16 23:04 . 2009-05-16 23:05 -------- d-----w c:\program files\Defraggler
2009-05-16 19:28 . 2009-05-22 22:57 117760 ----a-w c:\documents and settings\Dee\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-05-16 19:27 . 2009-05-16 19:27 -------- d-----w c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-05-16 19:27 . 2009-05-16 19:27 -------- d-----w c:\program files\SUPERAntiSpyware
2009-05-16 19:27 . 2009-05-16 19:27 -------- d-----w c:\documents and settings\Dee\Application Data\SUPERAntiSpyware.com
2009-05-16 18:46 . 2009-05-16 18:46 -------- d-----w c:\program files\CONEXANT
2009-05-16 16:36 . 2009-05-17 08:02 -------- d-----w c:\program files\Spybot - Search & Destroy
2009-05-16 14:03 . 2009-05-16 14:03 -------- d-----w c:\documents and settings\All Users\Application Data\OnlineArmor
2009-05-16 14:03 . 2009-05-16 14:43 -------- d-----w c:\documents and settings\Dee\Application Data\OnlineArmor
2009-05-16 14:02 . 2009-03-06 23:40 30920 ----a-w c:\windows\system32\drivers\OAmon.sys
2009-05-16 14:02 . 2009-03-06 23:40 28872 ----a-w c:\windows\system32\drivers\OAnet.sys
2009-05-16 14:02 . 2009-03-06 23:40 178376 ----a-w c:\windows\system32\drivers\OADriver.sys
2009-05-16 14:02 . 2009-05-16 14:02 -------- d-----w c:\program files\Tall Emu
2009-05-16 14:02 . 2009-05-16 14:02 -------- d-----w C:\OnlineArmor
2009-05-16 14:01 . 2009-05-16 14:03 -------- d-----w c:\program files\a-squared Free
2009-05-15 17:28 . 2009-05-15 17:39 -------- d-----w c:\program files\ICQ6.5
2009-05-13 22:59 . 2009-05-13 22:59 -------- d-----w c:\program files\GC Keyword Analyzer
2009-05-12 11:42 . 2009-05-12 11:42 -------- d-----w c:\documents and settings\All Users\Application Data\Ultimate Keyword Theme Extractor
2009-05-12 11:42 . 2009-05-12 11:42 -------- d-----w c:\program files\Ultimate Keyword Theme Extractor
2009-05-04 13:00 . 2009-05-07 19:59 -------- d-----w c:\documents and settings\Dee\Application Data\Inspyder InSite
2009-05-02 11:26 . 2009-05-02 11:26 152576 ----a-w c:\documents and settings\Dee\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-04-25 21:53 . 2009-04-25 21:55 -------- d-----w C:\astrosite
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-22 22:54 . 2007-06-12 18:25 -------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-05-22 22:12 . 2007-04-26 06:24 -------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-05-22 22:03 . 2006-05-26 08:55 -------- d-----w c:\program files\Java
2009-05-22 21:00 . 2007-08-25 09:31 -------- d-----w c:\program files\Affiliate Organizer
2009-05-18 22:56 . 2006-10-24 15:45 -------- d-----w c:\program files\Windows Live Toolbar
2009-05-16 23:31 . 2006-09-06 18:11 -------- d-----w c:\documents and settings\Dee\Application Data\OpenOffice.org2
2009-05-16 22:31 . 2008-12-10 12:10 -------- d-----w c:\program files\SENuke
2009-05-16 21:59 . 2007-07-22 14:58 -------- d-----w c:\program files\Content-N-Cash
2009-05-16 19:26 . 2007-02-28 01:55 -------- d-----w c:\program files\Common Files\Wise Installation Wizard
2009-05-16 12:02 . 2007-06-26 09:23 -------- d-----w c:\program files\Internet Download Manager
2009-05-15 17:30 . 2008-06-17 15:12 -------- d-----w c:\program files\ICQ6
2009-05-15 09:16 . 2007-06-26 09:23 -------- d-----w c:\documents and settings\Dee\Application Data\IDM
2009-05-14 12:31 . 2008-06-24 14:53 -------- d-----w c:\program files\Article Submitter Pro
2009-05-13 20:07 . 2007-06-26 09:23 -------- d-----w c:\documents and settings\Dee\Application Data\DMCache
2009-05-12 13:19 . 2007-04-07 09:53 -------- d-----w c:\program files\FlashFXP
2009-05-10 14:37 . 2008-01-19 00:57 -------- d-----w c:\program files\RSS Submit
2009-05-10 12:37 . 2007-11-16 15:30 -------- d-----w c:\program files\WordFlood 2.0
2009-05-10 12:03 . 2009-02-19 13:23 -------- d-----w c:\program files\SocialSpeed
2009-05-10 03:29 . 2008-09-29 15:03 -------- d-----w c:\program files\SliQTools
2009-05-10 02:52 . 2009-01-24 11:31 -------- d-----w c:\program files\Common Files\Adobe AIR
2009-05-07 20:10 . 2007-04-13 08:36 -------- d-----w c:\program files\digiXMAS
2009-04-30 17:12 . 2008-08-03 06:09 11952 ----a-w c:\windows\system32\avgrsstx.dll
2009-04-30 17:12 . 2007-12-08 19:41 27784 ----a-w c:\windows\system32\drivers\avgmfx86.sys
2009-04-30 17:12 . 2008-08-03 06:09 325896 ----a-w c:\windows\system32\drivers\avgldx86.sys
2009-04-30 17:12 . 2008-08-03 06:09 108552 ----a-w c:\windows\system32\drivers\avgtdix.sys
2009-04-25 21:25 . 2008-05-30 17:50 -------- d-----w c:\program files\Matrix
2009-03-09 04:19 . 2008-11-21 22:12 410984 ----a-w c:\windows\system32\deploytk.dll
2009-03-06 14:22 . 2004-08-04 08:00 284160 ----a-w c:\windows\system32\pdh.dll
2009-03-04 13:58 . 2009-03-04 13:58 0 ----a-w c:\documents and settings\Dee\ntuser.tmp
2009-03-03 00:18 . 2004-08-04 08:00 826368 ----a-w c:\windows\system32\wininet.dll
2006-05-24 16:38 . 2008-02-22 01:50 233472 -c--a-w c:\program files\mozilla firefox\plugins\CrazyTalk4Native.dll
2006-05-18 17:00 . 2008-02-22 01:50 204895 -c--a-w c:\program files\mozilla firefox\plugins\ctdomemhelper.dll
2005-09-29 14:41 . 2008-02-22 01:50 77824 -c--a-w c:\program files\mozilla firefox\plugins\ctframeplayerobject.dll
2006-05-18 16:59 . 2008-02-22 01:50 426081 -c--a-w c:\program files\mozilla firefox\plugins\ctplayerobject.dll
2005-02-02 12:19 . 2008-02-22 01:50 458752 -c--a-w c:\program files\mozilla firefox\plugins\imagickrt.dll
2006-04-10 18:35 . 2008-02-22 01:50 139264 -c--a-w c:\program files\mozilla firefox\plugins\rlcontentclass.dll
2005-11-09 11:10 . 2008-02-22 01:50 204800 -c--a-w c:\program files\mozilla firefox\plugins\RLMusicPacker.dll
2005-11-09 11:42 . 2008-02-22 01:50 106496 -c--a-w c:\program files\mozilla firefox\plugins\RLMusicUnpacker.dll
2006-01-04 11:22 . 2008-02-22 01:50 212992 -c--a-w c:\program files\mozilla firefox\plugins\RLVoicePacker.dll
2006-01-04 11:21 . 2008-02-22 01:50 167936 -c--a-w c:\program files\mozilla firefox\plugins\RLVoiceUnpacker.dll
2008-02-22 03:30 . 2008-02-22 03:30 80 -csh--r c:\windows\CT5PRET.BIN
2002-07-31 19:55 . 2008-01-06 14:33 106 -csh--w c:\windows\WSYS049.SYS
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-04-04 62976]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-05-14 1830128]
"RegistryMechanic"="c:\program files\Registry Mechanic\RegMech.exe" [2008-07-08 2828184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2007-05-20 185784]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-04-30 1947928]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\Dee\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-4-12 643133]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMBalloonTip"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 11:05 356352 ----a-w c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OneCard]
2005-07-25 18:41 40960 ----a-w c:\program files\HPQ\IAM\Bin\AsWlnPkg.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-04-30 17:12 11952 ----a-w c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IfxWlxEN]
2006-03-03 15:08 434176 ----a-w c:\windows\system32\IfxWlxEN.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli AsWlnPkg
path=
backup=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mqsvc.exe"=
"c:\\WINDOWS\\SMINST\\Scheduler.exe"=
"c:\\Program Files\\FlashFXP\\FlashFXP.exe"=
"c:\\Documents and Settings\\Dee\\My Documents\\Downloads\\Programs\\utorrent.exe"=
"c:\\Program Files\\Micro Niche Finder\\microniche.exe"=
"c:\\Program Files\\iWatermark\\iWatermark.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [03/08/2008 07:09 325896]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [03/08/2008 07:09 108552]
R1 OADevice;OADriver;c:\windows\system32\drivers\OADriver.sys [16/05/2009 15:02 178376]
R1 OAmon;OAmon;c:\windows\system32\drivers\OAmon.sys [16/05/2009 15:02 30920]
R1 OAnet;OAnet;c:\windows\system32\drivers\OAnet.sys [16/05/2009 15:02 28872]
R1 PersonalSecureDrive;PersonalSecureDrive;c:\windows\system32\drivers\psd.sys [29/11/2005 17:56 36768]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [14/05/2009 14:22 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [14/05/2009 14:22 72944]
R2 ASChannel;Local Communication Channel;c:\windows\System32\svchost.exe -k Cognizance [04/08/2004 09:00 14336]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [15/01/2009 11:06 908568]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [15/01/2009 11:06 298776]
R2 CachemanXPService;CachemanXP;c:\progra~1\CACHEM~1\CachemanXP.exe [06/03/2008 20:58 355840]
R2 OAcat;Online Armor Helper Service;c:\program files\Tall Emu\Online Armor\oacat.exe [16/05/2009 15:02 1402568]
R2 ubsbm;Unibrain 1394 SBM Driver;c:\windows\system32\drivers\UBSBM.sys [27/07/2005 17:25 14080]
R2 ubumapi;Unibrain 1394 FireAPI Driver;c:\windows\system32\drivers\UBUMAPI.sys [27/07/2005 17:25 36352]
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [21/10/2005 12:19 36352]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [14/05/2009 14:22 7408]
R3 ubohci;Unibrain 1394 OHCI Driver;c:\windows\system32\drivers\ubohci.sys [27/07/2005 17:25 77056]
S3 SvcOnlineArmor;Online Armor;c:\program files\Tall Emu\Online Armor\oasrv.exe [16/05/2009 15:02 3321032]
S3 tap0801;Smarthide TAP driver;c:\windows\system32\drivers\tap0801.sys [12/10/2007 14:07 55808]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Cognizance REG_MULTI_SZ ASChannel
.
Contents of the 'Scheduled Tasks' folder
2009-05-22 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]
.
- - - - ORPHANS REMOVED - - - -
ShellExecuteHooks-{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - (no file)
SafeBoot-procexp90.Sys
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.bbc.co.uk/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = hxxp://www.hp.com/
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: Download FLV video content with IDM
IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: Open in new background tab - c:\program files\Windows Live Toolbar\Components\en-gb\msntabres.dll.mui/229?d4a8adb91c0f4702972ae83164765d84
IE: Open in new foreground tab - c:\program files\Windows Live Toolbar\Components\en-gb\msntabres.dll.mui/230?d4a8adb91c0f4702972ae83164765d84
IE: RoboForm Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
Trusted Zone: stumbleupon.com
FF - ProfilePath - c:\documents and settings\Dee\Application Data\Mozilla\Firefox\Profiles\lvnyvz54.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - BoardTracker
FF - prefs.js: browser.startup.homepage - hxxp://www.future-forcast.co.uk
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q=
FF - plugin: c:\program files\Mozilla Firefox\plugins\npRLCT4Player.dll
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-05-23 00:08
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-2194445863-3924508569-3793972843-1005\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_USERS\S-1-5-21-2194445863-3924508569-3793972843-1005\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{F5F7521C-F4FE-3D98-F635-1C792DD7D7FA}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"naknkhmegpegmlkeffimcggaflcf"=hex:6a,61,6f,6e,70,61,6d,66,6a,68,6f,62,6d,6f,
66,65,61,64,6b,67,00,fb
"maenajbcgicijgnljclllanbgl"=hex:6a,61,6f,6e,70,61,6d,66,6a,68,6f,62,6d,6f,66,
65,61,64,6b,67,00,fb
"naolclbiegfcceckhchdnibcbdli"=hex:62,61,69,6e,00,8f
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):ea,a4,47,18,6d,ac,32,29,18,4e,ef,ed,d8,6c,f8,06,53,34,fe,5b,b2,
f7,88,52,3a,0f,de,95,cf,34,4f,2f,c4,cb,5c,a2,23,0c,83,8a,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):b4,80,6a,fe,2c,6a,75,d7,84,8b,54,88,3e,2e,ae,42,77,71,6f,10,98,
38,4a,ca,e6,25,6e,08,ec,b5,7b,f1,df,0a,0e,c7,c0,a7,7f,7f,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{93e6e9bd-f9cf-4ae4-ada7-eea9926b48e5}]
@Denied: (Full) (Everyone)
"Model"=dword:000000cc
"Therad"=dword:0000001d
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{e423eca4-9c18-47a7-b6fb-515e406fd7a1}]
@Denied: (Full) (Everyone)
"Model"=dword:0000010f
"Therad"=dword:00000015
"MData"=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5,9f,6a,96,3e,ab,de,c5,81,26,
38,95,44,85,b1,12,f9,90,dd,23,a1,49,8c,bf,1a,9d,fe,41,71,cb,3f,46,a4,7c,ab,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(864)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\Ati2evxx.dll
c:\program files\HPQ\IAM\Bin\AsWlnPkg.dll
c:\windows\system32\IfxWlxEN.dll
- - - - - - - > 'lsass.exe'(920)
c:\program files\HPQ\IAM\bin\AsWlnPkg.dll
.
Completion time: 2009-05-22 0:10
ComboFix-quarantined-files.txt 2009-05-22 23:09
ComboFix2.txt 2009-05-21 14:14
Pre-Run: 16,136,540,160 bytes free
Post-Run: 16,136,409,088 bytes free
260 --- E O F --- 2009-05-15 07:17