here is the log
ComboFix 09-11-22.08 - stewart Macleod 23/11/2009 17:22.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.511.195 [GMT 0:00]
Running from: c:\users\stewart Macleod\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\users\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\users\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\users\stewart Macleod\Application Data\inst.exe
c:\windows\msa.exe
c:\windows\system32\cooper.mine
c:\windows\system32\Data
c:\windows\system32\nvrtm.dll
c:\windows\system32\tdlclk.dll
c:\windows\system32\tdlcmd.dll
c:\windows\system32\tdlwsp.dll
----- BITS: Possible infected sites -----
hxxp://opt3.biz
c:\windows\system32\DRIVERS\viamraid.sys . . . is infected!!
Infected copy of c:\windows\system32\DRIVERS\atapi.sys was found and disinfected
Restored copy from - Kitty ate it
Infected copy of c:\windows\system32\userinit.exe was found and disinfected
Restored copy from - c:\windows\system32\dllcache\userinit.exe
Infected copy of c:\windows\system32\eventlog.dll was found and disinfected
Restored copy from - c:\windows\system32\dllcache\eventlog.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
((((((((((((((((((((((((( Files Created from 2009-10-23 to 2009-11-23 )))))))))))))))))))))))))))))))
.
2009-11-23 17:18 . 2003-11-28 02:42 71040 ----a-w- c:\windows\system32\drivers\viasprid.sys
2009-11-23 17:18 . 2003-11-28 02:42 71040 ----a-r- c:\windows\system32\drivers\viasprid_2.sys
2009-11-19 20:43 . 2009-11-19 20:43 -------- d-----w- c:\program files\Trend Micro
2009-11-19 20:39 . 2009-11-19 20:40 -------- d-----w- c:\program files\ERUNT
2009-11-18 21:25 . 2009-11-18 21:25 -------- d--h--w- c:\windows\system32\GroupPolicy
2009-11-18 21:17 . 2009-11-18 21:17 70144 ----a-w- c:\users\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-18 21:15 . 2009-11-18 21:15 -------- d-sh--w- c:\users\Administrator\IETldCache
2009-11-18 21:15 . 2009-11-18 21:15 -------- d-sh--w- c:\users\\Administrator\IETldCache
2009-11-18 17:45 . 2009-11-18 17:45 114176 ----a-r- c:\windows\system32\mswpfx32.exe
2009-11-16 18:30 . 2007-10-31 00:33 26112 ----a-w- c:\windows\system32\stu2.exe
2009-11-05 23:33 . 2009-11-05 23:33 -------- d-----w- c:\users\stewart Macleod\output
2009-11-05 23:33 . 2009-11-05 23:33 -------- d-----w- c:\users\\stewart Macleod\output
2009-11-05 22:49 . 2009-11-19 20:02 -------- d-----w- c:\program files\BBC Radio Ripper
2009-10-28 18:12 . 2009-10-28 18:12 147456 ----a-w- c:\windows\system32\nmklo.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-23 17:38 . 2007-12-08 16:42 578048 ----a-w- c:\windows\system32\user32.dll
2009-11-23 17:21 . 2008-02-18 19:16 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-11-23 12:50 . 2009-10-19 09:38 0 ----a-r- c:\windows\win32k.sys
2009-11-19 21:53 . 2009-09-22 23:45 10 ----a-w- c:\windows\popcinfo.dat
2009-11-19 20:00 . 2008-02-10 01:40 -------- d-----w- c:\program files\Soulseek
2009-11-19 17:48 . 2008-02-09 15:24 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-11-18 22:09 . 2008-02-09 15:24 -------- d-----w- c:\users\All Users\Application Data\Spybot - Search & Destroy
2009-11-16 23:46 . 2008-02-09 19:19 -------- d-----w- c:\users\stewart Macleod\Application Data\Vso
2009-11-12 00:21 . 2008-02-18 16:29 -------- d-----w- c:\users\All Users\Application Data\Microsoft Help
2009-11-07 18:24 . 2009-07-08 21:14 -------- d-----w- c:\program files\Songbird
2009-11-02 20:42 . 2009-10-10 10:28 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-09-26 23:34 . 2009-09-26 23:34 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
2009-09-26 23:34 . 2009-09-26 23:34 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2009-09-26 23:25 . 2009-09-26 23:25 -------- d-----w- c:\users\All Users\Application Data\Nokia
2009-09-26 23:21 . 2008-02-09 20:02 -------- d-----w- c:\program files\Nokia
2009-09-26 23:17 . 2008-02-09 20:02 -------- d-----w- c:\program files\Common Files\Nokia
2009-09-26 23:16 . 2009-09-26 23:16 -------- d-----w- c:\program files\MSXML 6.0
2009-09-26 23:15 . 2009-09-26 23:15 3351812 ----a-w- c:\users\All Users\Application Data\Installations\{F983B4FE-547B-4C44-BAF7-4F4DBA93D548}\Installer\CommonCustomActions\msxml6Exec.exe
2009-09-26 23:15 . 2009-09-26 23:15 36864 ----a-w- c:\users\All Users\Application Data\Installations\{F983B4FE-547B-4C44-BAF7-4F4DBA93D548}\Installer\CommonCustomActions\Sleep.exe
2009-09-26 23:15 . 2009-09-26 23:15 3181612 ----a-w- c:\users\All Users\Application Data\Installations\{F983B4FE-547B-4C44-BAF7-4F4DBA93D548}\Installer\CommonCustomActions\vcredistExec.exe
2009-09-26 23:14 . 2009-09-26 23:14 -------- d-----w- c:\users\All Users\Application Data\Installations
2009-09-26 23:11 . 2009-09-26 23:16 24501456 ----a-w- c:\users\All Users\Application Data\Installations\{F983B4FE-547B-4C44-BAF7-4F4DBA93D548}\NokiaSoftwareUpdaterSetup_en.exe
2009-09-11 14:18 . 2007-10-31 00:31 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-04 21:03 . 2007-10-31 00:31 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-29 08:08 . 2007-12-05 16:21 916480 ----a-w- c:\windows\system32\wininet.dll
2009-08-28 17:36 . 2009-03-16 18:37 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-08-28 17:36 . 2009-03-16 18:37 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-28 17:36 . 2008-02-09 14:17 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-08-26 08:00 . 2007-10-31 00:32 247326 ----a-w- c:\windows\system32\strmdll.dll
.
Infected c:\windows\system32\user32.dll hex repaired
------- Sigcheck -------
[7] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[7] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\system32\dllcache\tcpip.sys
[-] 2008-04-13 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\59fc8f12b80caa991163249076d0bcca\tcpip.sys
[-] 2007-10-11 . 270684847A8EF5C51FFF58457E4DC8C6 . 361088 . . [5.1.2600.9999] . . c:\windows\system32\drivers\tcpip.sys
[-] 2008-04-14 . BD38D1EBE24A46BD3EDA059560AFBA12 . 1054208 . . [6.0] . . c:\windows\SoftwareDistribution\Download\59fc8f12b80caa991163249076d0bcca\asms\60\msft\windows\common\controls\comctl32.dll
[-] 2008-04-14 . 06F247492BC786CE5C24A23E178C711A . 617472 . . [5.82] . . c:\windows\SoftwareDistribution\Download\59fc8f12b80caa991163249076d0bcca\comctl32.dll
[-] 2007-12-08 . EE3C29F2EBA27F0081855DCE586CE39A . 692736 . . [5.82] . . c:\windows\system32\comctl32.dll
[-] 2009-11-23 . 72266B82D796C816B7F0A44D8B7E3216 . 578048 . . [5.1.2600.3244] . . c:\windows\system32\user32.dll
[-] 2009-11-23 . 72266B82D796C816B7F0A44D8B7E3216 . 578048 . . [5.1.2600.3244] . . c:\windows\system32\dllcache\user32.dll
[-] 2008-04-14 . B26B135FF1B9F60C9388B4A7D16F600B . 578560 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\59fc8f12b80caa991163249076d0bcca\user32.dll
[-] 2008-04-14 . 12896823FB95BFB3DC9B46BCAEDC9923 . 1033728 . . [6.00.2900.5512] . . c:\windows\SoftwareDistribution\Download\59fc8f12b80caa991163249076d0bcca\explorer.exe
[-] 2007-12-08 . 644B75CE88F50D64D609CC6C72EA5CF2 . 1424384 . . [6.00.2900.3244] . . c:\windows\explorer.exe
[-] 2008-04-14 . 9DD07AF82244867CA36681EA2D29CE79 . 1614848 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\59fc8f12b80caa991163249076d0bcca\sfcfiles.dll
[-] 2007-12-05 . 70D88E6BCF06DD1A53DC1E0381C1B320 . 1614336 . . [5.1.2600.3244] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-07-24 08:55 1090816 ----a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VisualTaskTips"="c:\windows\System32\VisualTaskTips\VisualTaskTips.exe" [2007-09-05 36352]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-03 866584]
"ehTray"="c:\windows\ehome\ehtray.exe" [2007-10-31 50176]
"SecurDisc"="c:\program files\Nero\Nero8\InCD\NBHGui.exe" [2007-10-15 2045224]
"InCD"="c:\program files\Nero\Nero8\InCD\InCD.exe" [2007-10-15 1077032]
"PCSuiteTrayApplication"="c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2006-11-08 222208]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-11-02 2028312]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-04-13 185896]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2007-10-31 110592]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2007-10-31 15360]
"MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2007-09-26 1232384]
"VisualTaskTips"="c:\windows\System32\VisualTaskTips\VisualTaskTips.exe" [2007-09-05 36352]
"TopDesk"="c:\windows\System32\TopDesk\topdesk.exe" [2007-11-16 1937920]
"PcSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2006-11-09 1634304]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
"ProfileFolderName"="hc" [X]
"IESetDefaultSearchScope"="hc" [X]
"CheckUpdates"="wuauclt" [X]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsNetHood"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsNetHood"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsNetHood"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\windows\system32\userinit.exe,c:\windows\system32\mswpfx32.exe,"
"UIHost"=hex(2):25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,53,79,73,74,65,6d,33,32,\
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-28 17:36 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, credssp.dll, msnsspc.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\TVUPlayer\\TVUPlayer.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Users\\stewart Macleod\\Application Data\\Macromedia\\Flash Player\\www.macromedia.com\\bin\\octoshape\\octoshape.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\FlashFXP\\FlashFXP.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Songbird\\songbird.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
"c:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
R0 viasprid;viasprid;c:\windows\system32\drivers\viasprid.sys [23/11/2009 17:18 71040]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [16/03/2009 18:37 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [16/03/2009 18:37 108552]
R3 3xHybrid;3xHybrid service;c:\windows\system32\drivers\3xHybrid.sys [09/02/2008 19:26 584960]
S2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [16/03/2009 18:36 297752]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [03/11/2006 18:19 13592]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [26/09/2009 23:21 136704]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [26/09/2009 23:21 8320]
.
Contents of the 'Scheduled Tasks' folder
2009-01-03 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2009-11-23 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]
.
.
------- Supplementary Scan -------
.
uInternet Connection Wizard,ShellNext = hxxp://free.grisoft.com/doc/registration/us/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\stewart Macleod\Application Data\Mozilla\Firefox\Profiles\zdmyav5x.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - prefs.js: keyword.URL - hxxp://uk.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_uk&p=
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\users\All Users\Application Data\id Software\QuakeLive\npquakezero.dll
FF - plugin: c:\users\stewart Macleod\Application Data\Mozilla\Firefox\Profiles\zdmyav5x.default\extensions\firefox@tvunetworks.com\plugins\npTVUAx.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-11-23 17:49
Windows 5.1.2600 Service Pack 3, v.5857 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
c:\windows\system32\mswpfx32.exe 114176 bytes executable
scan completed successfully
hidden files: 1
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(652)
c:\windows\system32\SETUPAPI.dll
c:\windows\system32\wininet.dll
c:\windows\system32\COMRes.dll
- - - - - - - > 'lsass.exe'(708)
c:\windows\system32\SETUPAPI.dll
c:\windows\system32\wininet.dll
- - - - - - - > 'explorer.exe'(2632)
c:\windows\system32\WININET.dll
c:\windows\System32\VisualTaskTips\VttHooks.dll
c:\windows\system32\COMRes.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\SETUPAPI.dll
c:\windows\system32\NETSHELL.dll
c:\windows\system32\credui.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\wpdshserviceobj.dll
c:\program files\Nokia\Nokia PC Suite 6\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 6\PCSCM.dll
c:\program files\PC Connectivity Solution\ConnAPI.DLL
c:\program files\Nokia\Nokia PC Suite 6\Lang\PhoneBrowser_eng.nlr
c:\program files\Nokia\Nokia PC Suite 6\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\AVG\AVG8\avgrsx.exe
c:\windows\system32\rundll32.exe
.
**************************************************************************
.
Completion time: 2009-11-23 17:54 - machine was rebooted
ComboFix-quarantined-files.txt 2009-11-23 17:53
Pre-Run: 4,518,277,120 bytes free
Post-Run: 4,519,358,464 bytes free
- - End Of File - - 13DFCA4C0D99A1B4E035CA5475FE1C73