ComboFix was run, but it was difficult to download on infected computer.
Initially, a window opened up with the code displayed.
Eventually, a box popped up and it was successfully saved to the desktop.
Here is the log.
ComboFix 09-10-04.01 - Raymond 10/05/2009 13:51.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.641 [GMT -4:00]
Running from: c:\documents and settings\Raymond\Desktop\Combo-Fix.exe
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\aIx11A.tmp
c:\documents and settings\All Users\Application Data\awekymyry.bin
c:\documents and settings\All Users\Application Data\canycy.bat
c:\documents and settings\All Users\Application Data\dekuha.dll
c:\documents and settings\All Users\Application Data\dijibot.vbs
c:\documents and settings\All Users\Application Data\ehatepu.lib
c:\documents and settings\All Users\Application Data\ekusaleb.scr
c:\documents and settings\All Users\Application Data\elanijudup.reg
c:\documents and settings\All Users\Application Data\igycoh.sys
c:\documents and settings\All Users\Application Data\iqesytakyq.lib
c:\documents and settings\All Users\Application Data\kebexugaq.dl
c:\documents and settings\All Users\Application Data\nydyhaz.com
c:\documents and settings\All Users\Application Data\tohakut.inf
c:\documents and settings\All Users\Application Data\vupofajo.dl
c:\documents and settings\All Users\Application Data\wiwete._sy
c:\documents and settings\All Users\Application Data\ysotujev.dl
c:\documents and settings\All Users\Documents\ekixejy.sys
c:\documents and settings\All Users\Documents\eniwityb.bat
c:\documents and settings\All Users\Documents\erozak.pif
c:\documents and settings\All Users\Documents\iweby.scr
c:\documents and settings\All Users\Documents\notapos.reg
c:\documents and settings\All Users\Documents\ubegedabi.sys
c:\documents and settings\All Users\Documents\unenif.reg
c:\documents and settings\All Users\Documents\ygyzu.inf
c:\documents and settings\Raymond\Application Data\ebej.inf
c:\documents and settings\Raymond\Application Data\ehepun.vbs
c:\documents and settings\Raymond\Application Data\emocyxohu.dll
c:\documents and settings\Raymond\Application Data\exeqoh.com
c:\documents and settings\Raymond\Application Data\fosevaluxy.exe
c:\documents and settings\Raymond\Application Data\lizkavd.exe
c:\documents and settings\Raymond\Application Data\Microsoft\Internet Explorer\Quick Launch\AntivirusPro_2010.lnk
c:\documents and settings\Raymond\Application Data\mocy.vbs
c:\documents and settings\Raymond\Application Data\obop.com
c:\documents and settings\Raymond\Application Data\otyxel.exe
c:\documents and settings\Raymond\Application Data\seres.exe
c:\documents and settings\Raymond\Application Data\svcst.exe
c:\documents and settings\Raymond\Application Data\upebekur.com
c:\documents and settings\Raymond\Application Data\vecufig.com
c:\documents and settings\Raymond\Application Data\yloza.pif
c:\documents and settings\Raymond\Cookies\bahysyq.dll
c:\documents and settings\Raymond\Cookies\ciworyzeb._dl
c:\documents and settings\Raymond\Cookies\cynihijip.db
c:\documents and settings\Raymond\Cookies\geda.bin
c:\documents and settings\Raymond\Cookies\jesa.scr
c:\documents and settings\Raymond\Cookies\mosuxype.reg
c:\documents and settings\Raymond\Cookies\okofiroja.bin
c:\documents and settings\Raymond\Cookies\osyg.lib
c:\documents and settings\Raymond\Cookies\pobiz._dl
c:\documents and settings\Raymond\Cookies\qepysyduw._dl
c:\documents and settings\Raymond\Cookies\ryfite.dat
c:\documents and settings\Raymond\Cookies\vexype.exe
c:\documents and settings\Raymond\Cookies\viduwa.dat
c:\documents and settings\Raymond\Cookies\xubow.inf
c:\documents and settings\Raymond\Cookies\yliqaripot._dl
c:\documents and settings\Raymond\Local Settings\Application Data\amutaduwyx._dl
c:\documents and settings\Raymond\Local Settings\Application Data\hihamo.reg
c:\documents and settings\Raymond\Local Settings\Application Data\jinun.inf
c:\documents and settings\Raymond\Local Settings\Application Data\navur.ban
c:\documents and settings\Raymond\Local Settings\Application Data\rehuqex.dll
c:\documents and settings\Raymond\Local Settings\Application Data\relenoqa._dl
c:\documents and settings\Raymond\Local Settings\Application Data\rifubojo.inf
c:\documents and settings\Raymond\Local Settings\Application Data\ujyvim._dl
c:\documents and settings\Raymond\Local Settings\Application Data\usiz.dll
c:\documents and settings\Raymond\Local Settings\Application Data\ymaq.dll
c:\documents and settings\Raymond\Local Settings\Application Data\zoturubam._dl
c:\documents and settings\Raymond\Local Settings\Temporary Internet Files\cibo.dat
c:\documents and settings\Raymond\Local Settings\Temporary Internet Files\ehekur.ban
c:\documents and settings\Raymond\Local Settings\Temporary Internet Files\emifem.exe
c:\documents and settings\Raymond\Local Settings\Temporary Internet Files\hyfe.dll
c:\documents and settings\Raymond\Local Settings\Temporary Internet Files\icev.pif
c:\documents and settings\Raymond\Local Settings\Temporary Internet Files\ivewacohe.dat
c:\documents and settings\Raymond\Local Settings\Temporary Internet Files\kewo.com
c:\documents and settings\Raymond\Local Settings\Temporary Internet Files\qaryheq.bin
c:\documents and settings\Raymond\Local Settings\Temporary Internet Files\sejad.dll
c:\documents and settings\Raymond\Local Settings\Temporary Internet Files\urofosoti.sys
c:\documents and settings\Raymond\Start Menu\Programs\AntivirusPro_2010
c:\documents and settings\Raymond\Start Menu\Programs\AntivirusPro_2010\AntivirusPro_2010.lnk
c:\documents and settings\Raymond\Start Menu\Programs\AntivirusPro_2010\Uninstall.lnk
c:\program files\AntivirusPro_2010
c:\program files\AntivirusPro_2010\AntivirusPro_2010.exe
c:\program files\Common Files\dipyzuh.scr
c:\program files\Common Files\hamys.reg
c:\program files\Common Files\ibawihadoc._dl
c:\program files\Common Files\kumyces.bin
c:\program files\Common Files\lajora.reg
c:\program files\Common Files\oradyryxi.ban
c:\program files\Common Files\yluquzec.reg
c:\windows\afoj.bin
c:\windows\cidyjocad.dl
c:\windows\edukusen.ban
c:\windows\emygybymyq.vbs
c:\windows\esunewyw.inf
c:\windows\foga.dll
c:\windows\hamiq.inf
c:\windows\ikyzasa.dl
c:\windows\isucimoce.ban
c:\windows\isylebo.inf
c:\windows\kygemadik.reg
c:\windows\mynudiha.sys
c:\windows\nomoq.sys
c:\windows\obituzawy.dl
c:\windows\ocavazydo.vbs
c:\windows\povomar.pif
c:\windows\qaqe.bat
c:\windows\qeromunoci.bat
c:\windows\qujuwopa.reg
c:\windows\rera.bin
c:\windows\system32\_scui.cpl
c:\windows\system32\~.exe
c:\windows\system32\asewohet.sys
c:\windows\system32\awixakoduh.vbs
c:\windows\system32\byxuzekod.reg
c:\windows\system32\drivers\gasfkyebwupqoy.sys
c:\windows\system32\drivers\snetcfg.exe
c:\windows\system32\ewunekexe.bat
c:\windows\system32\gicogyjy.vbs
c:\windows\system32\jofu.sys
c:\windows\system32\lyjyxysofi.exe
c:\windows\system32\osihutig.bin
c:\windows\system32\pabogumo.pif
c:\windows\system32\qabekus.inf
c:\windows\system32\rejobedil._dl
c:\windows\system32\ulacesa.inf
c:\windows\system32\wbem\proquota.exe
c:\windows\system32\yqeb.reg
c:\windows\system32\ysyrobohaj.scr
c:\windows\tipok.dl
c:\windows\unataqu._dl
c:\windows\utolimasu.exe
c:\windows\vizeqodub.dl
c:\windows\xubifobaf._dl
c:\windows\ybewy.dll
c:\windows\yjedywymav.exe
Infected copy of c:\windows\system32\eventlog.dll was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\eventlog.dll
c:\windows\system32\proquota.exe was missing
Restored copy from - c:\windows\ServicePackFiles\i386\proquota.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
((((((((((((((((((((((((( Files Created from 2009-09-05 to 2009-10-05 )))))))))))))))))))))))))))))))
.
2009-10-05 17:55 . 2008-04-14 00:12 50176 ----a-w- c:\windows\system32\proquota.exe
2009-10-05 17:42 . 2009-10-05 17:42 -------- d--h--w- c:\windows\PIF
2009-10-05 13:17 . 2009-10-05 13:17 11942 ----a-w- c:\windows\ylidazuse.dat
2009-10-05 00:13 . 2009-10-05 00:13 -------- d-----w- c:\program files\Temp
2009-10-05 00:12 . 2009-10-05 00:12 -------- d-----w- c:\program files\Ttemp
2009-10-03 19:56 . 2009-10-05 00:11 -------- d-----w- c:\program files\Trend Micro
2009-10-03 19:49 . 2009-10-03 19:49 -------- d-----w- c:\program files\ERUNT
2009-10-01 20:16 . 2009-10-01 20:16 -------- d-----w- c:\documents and settings\All Users\Application Data\TEMP
2009-10-01 18:28 . 2009-10-01 20:33 -------- d-----w- c:\windows\SxsCaPendDel
2009-10-01 18:05 . 2009-10-01 18:05 14893 ----a-w- c:\windows\yhiqyxe.dat
2009-10-01 17:49 . 2009-10-01 17:49 -------- d-----w- c:\documents and settings\All Users\Application Data\SITEguard
2009-10-01 17:48 . 2009-10-01 17:48 -------- d-----w- c:\program files\Common Files\iS3
2009-10-01 17:48 . 2009-10-01 18:27 -------- d-----w- c:\documents and settings\All Users\Application Data\STOPzilla!
2009-10-01 13:11 . 2009-10-01 13:11 10501 ----a-w- c:\windows\urihito.dat
2009-10-01 04:12 . 2009-10-01 04:12 17640 ----a-w- c:\windows\unedoto.com
2009-10-01 04:12 . 2009-10-01 04:12 11951 ----a-w- c:\windows\okokejo.dat
2009-10-01 04:05 . 2009-10-01 04:05 12362 ----a-w- c:\windows\zapi.dat
2009-10-01 03:29 . 2009-10-05 13:16 0 ----a-r- c:\windows\win32k.sys
2009-10-01 03:29 . 2009-10-01 03:29 57856 ----a-w- C:\vklebc.exe
2009-10-01 03:29 . 2009-10-01 03:29 46592 ----a-w- C:\hrngen.exe
2009-10-01 03:29 . 2009-10-01 03:29 52736 ----a-w- C:\afuqr.exe
2009-10-01 03:29 . 2009-10-01 03:29 12288 ----a-w- C:\qtpjjuur.exe
2009-10-01 03:29 . 2009-10-01 03:29 6144 ----a-w- C:\avjelge.exe
2009-10-01 03:28 . 2009-10-01 03:29 79360 ----a-w- C:\aefxixl.exe
2009-10-01 03:28 . 2009-10-01 03:29 17920 ----a-w- C:\qgferewy.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-05 17:43 . 2008-10-24 14:30 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-10-05 17:28 . 2008-10-24 21:45 -------- d-----w- c:\program files\McAfee
2009-10-05 16:04 . 2008-10-25 02:31 -------- d-----w- c:\program files\Mozilla Thunderbird
2009-10-05 13:17 . 2009-10-05 13:17 15281 ----a-w- c:\program files\Common Files\exagim._sy
2009-10-01 20:37 . 2008-10-24 14:30 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-10-01 04:12 . 2009-10-01 04:12 10079 ----a-w- c:\documents and settings\Raymond\Application Data\uwudorexiq.dat
2009-09-29 20:05 . 2009-02-11 13:00 -------- d-----w- c:\documents and settings\Raymond\Application Data\U3
2009-09-28 13:37 . 2008-10-24 21:40 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2009-07-16 16:32 . 2008-10-24 21:45 120136 ----a-w- c:\windows\system32\drivers\Mpfp.sys
2009-07-08 17:44 . 2008-10-24 21:46 40552 ----a-w- c:\windows\system32\drivers\mfesmfk.sys
2009-07-08 17:44 . 2008-10-24 21:46 35272 ----a-w- c:\windows\system32\drivers\mfebopk.sys
2009-07-08 17:44 . 2008-10-24 21:45 79816 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
2009-07-08 17:44 . 2008-10-24 21:45 214024 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2009-07-08 17:43 . 2008-10-24 21:46 34248 ----a-w- c:\windows\system32\drivers\mferkdk.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaunchApp"="Alaunch" [X]
"ntiMUI"="c:\program files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe" [2005-05-12 45056]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-03 32768]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"IMEKRMIG6.1"="c:\windows\ime\imkr6_1\IMEKRMIG.EXE" [2004-08-04 44032]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2006-07-21 98304]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2006-07-21 86016]
"Persistence"="c:\windows\system32\igfxpers.exe" [2006-07-21 81920]
"eRecoveryService"="c:\acer\Empowering Technology\eRecovery\eRAgent.exe" [2006-06-01 413696]
"Acrobat Assistant 7.0"="c:\program files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2008-04-23 483328]
"HPWUTOOLBOX"="c:\program files\HP\HP Officejet Pro K550 Series\Toolbox\HPWUTBX.exe" [2005-07-23 352256]
"zBrowser Launcher"="c:\program files\Logitech\iTouch\iTouch.exe" [2004-03-18 892928]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-10-24 136600]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-07-10 645328]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-26 413696]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2006-05-17 16207872]
"SkyTel"="SkyTel.EXE" - c:\windows\SkyTel.exe [2006-05-16 2879488]
c:\documents and settings\Raymond\Start Menu\Programs\Startup\
DING!.lnk - c:\program files\Southwest Airlines\Ding\Ding.exe [2006-6-22 462848]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
ImageMixer 3 SE Camera Monitor for SD.lnk - c:\program files\PIXELA\ImageMixer 3 SE for SD\CameraMonitor.exe [2008-10-29 253952]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
S2 eLock2BurnerLockDriver;eLock2BurnerLockDriver;\??\c:\windows\system32\eLock2BurnerLockDriver.sys --> c:\windows\system32\eLock2BurnerLockDriver.sys [?]
S2 eLock2FSCTLDriver;eLock2FSCTLDriver;\??\c:\windows\system32\eLock2FSCTLDriver.sys --> c:\windows\system32\eLock2FSCTLDriver.sys [?]
.
Contents of the 'Scheduled Tasks' folder
2009-10-01 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
2009-08-15 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2008-10-24 01:26]
2009-06-01 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2008-10-24 01:26]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.kitco.com/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*
http://www.yahoo.com
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-mserv - c:\documents and settings\Raymond\Application Data\svcst.exe
HKLM-Run-eDataSecurity Loader - c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-10-05 13:59
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(3492)
c:\program files\Logitech\iTouch\iTchHk.dll
c:\program files\Common Files\Logitech\Scrolling\LgMsgHk.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\progra~1\COMMON~1\McAfee\MNA\McNASvc.exe
c:\progra~1\COMMON~1\McAfee\McProxy\McProxy.exe
c:\progra~1\McAfee\VIRUSS~1\Mcshield.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\progra~1\McAfee.com\Agent\mcagent.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-10-05 14:03 - machine was rebooted
ComboFix-quarantined-files.txt 2009-10-05 18:03
Pre-Run: 67,637,608,448 bytes free
Post-Run: 69,542,277,120 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
333 --- E O F --- 2008-10-23 20:20