Combofix log
Hi again
ComboFix 09-11-22.08 - Shirley King 23/11/2009 18:43.5.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.605 [GMT 0:00]
Running from: c:\documents and settings\Shirley King\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Shirley King\Desktop\CFScript.txt
AV: PCguard Anti-Virus *On-access scanning disabled* (Updated) {5B5A3BD7-8573-4672-AEA8-C9BB713B6755}
FW: PCguard Firewall *disabled* {80593BF4-D969-4EC5-ADAE-A22F2DFC7A22}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\SHIRLE~1\LOCALS~1\Temp\clclean.0001.dir.0000\~df394b.tmp
c:\documents and settings\Shirley King\Local Settings\temp\clclean.0001.dir.0000\~df394b.tmp
Infected copy of c:\windows\system32\drivers\ntfs.sys was found and disinfected
Restored copy from - c:\windows\erdnt\cache\ntfs.sys
.
((((((((((((((((((((((((( Files Created from 2009-10-23 to 2009-11-23 )))))))))))))))))))))))))))))))
.
2009-11-23 16:13 . 2009-11-23 16:13 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-11-23 16:12 . 2009-11-23 16:12 152576 ----a-w- c:\documents and settings\Nick Parker\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-11-23 15:47 . 2009-11-23 15:47 86016 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2009-11-23 15:47 . 2009-11-23 16:03 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-11-22 22:11 . 2009-11-22 15:34 85504 ----a-w- c:\windows\system32\Inherit.exe
2009-11-22 15:37 . 2009-11-22 15:34 85504 ----a-w- c:\program files\Inherit.exe
2009-11-22 13:05 . 2009-11-22 13:15 -------- d-----w- c:\documents and settings\Shirley King\Application Data\Virgin Broadband
2009-11-21 13:07 . 2009-11-21 13:07 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-11-05 23:15 . 2008-11-26 15:19 53192 ----a-w- c:\windows\system32\drivers\rp_skt32.sys
2009-11-05 23:15 . 2008-08-06 21:20 48384 ----a-w- c:\windows\system32\drivers\rp_pkt32.sys
2009-11-05 23:15 . 2008-08-28 13:16 71184 ----a-w- c:\windows\system32\drivers\DefragFS.sys
2009-11-05 23:15 . 2009-11-05 23:15 -------- d-----w- c:\program files\Raxco
2009-11-05 23:15 . 2009-11-05 23:15 -------- d-----w- c:\documents and settings\All Users\Application Data\Raxco
2009-11-05 23:12 . 2009-11-22 15:38 -------- d-----w- c:\program files\Virgin Broadband
2009-11-05 20:04 . 2009-11-23 19:03 5444128 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-11-05 19:46 . 2009-11-23 19:02 181792 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-11-05 19:14 . 2009-11-05 23:17 -------- d-----w- c:\documents and settings\Nick Parker\Application Data\Virgin Broadband
2009-11-05 19:14 . 2009-11-05 23:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Virgin Broadband
2009-11-03 17:17 . 2009-11-03 17:17 -------- d-----w- c:\documents and settings\All Users\Application Data\SITEguard
2009-11-03 17:16 . 2009-11-03 17:16 -------- d-----w- c:\program files\Common Files\iS3
2009-11-03 17:16 . 2009-11-03 17:42 -------- d-----w- c:\documents and settings\All Users\Application Data\STOPzilla!
2009-11-03 15:31 . 2009-11-03 15:31 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-23 18:59 . 2009-11-05 20:04 74936 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-11-23 18:59 . 2009-11-05 19:46 19064 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-11-23 18:32 . 2006-02-20 23:18 -------- d-----w- c:\program files\Java
2009-11-23 18:26 . 2007-06-30 19:42 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-11-23 18:26 . 2007-06-30 19:42 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-11-23 15:50 . 2006-02-25 15:10 -------- d-----w- c:\program files\Common Files\Adobe
2009-11-22 16:24 . 2008-11-22 22:01 -------- d-----w- c:\program files\World of Warcraft Trial
2009-11-22 16:22 . 2009-09-12 17:23 -------- d-----w- c:\program files\QuickTime
2009-11-22 16:22 . 2006-02-26 18:49 -------- d-----w- c:\program files\Palm
2009-11-22 16:22 . 2006-02-20 23:24 -------- d-----w- c:\program files\Modem Helper
2009-11-22 16:22 . 2006-02-20 23:24 -------- d-----w- c:\program files\Dell
2009-11-22 16:21 . 2006-02-20 23:31 -------- d-----w- c:\program files\Common Files\aolshare
2009-11-22 16:21 . 2006-02-20 23:30 -------- d-----w- c:\program files\Common Files\AOL
2009-11-22 16:21 . 2006-02-20 23:31 -------- d-----w- c:\program files\AOL 9.0
2009-11-05 23:13 . 2006-02-20 23:24 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-11-05 20:11 . 2006-02-20 23:33 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2009-11-05 20:11 . 2006-02-20 23:33 -------- d-----w- c:\program files\McAfee
2009-11-05 20:10 . 2006-02-20 23:32 -------- d-----w- c:\program files\McAfee.com
2009-11-03 17:18 . 2009-11-03 17:18 384 ----a-w- c:\windows\system32\drivers\kgpcpy.cfg
2009-11-03 15:43 . 2008-08-03 09:18 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-22 20:43 . 2008-10-05 13:23 -------- d-----w- c:\documents and settings\LocalService\Application Data\SACore
2009-10-03 16:36 . 2009-10-03 16:34 -------- d-----w- c:\program files\iTunes
2009-10-03 16:34 . 2009-10-03 16:34 -------- d-----w- c:\program files\iPod
2009-10-03 16:34 . 2009-06-20 18:19 -------- d-----w- c:\program files\Common Files\Apple
2009-10-03 16:27 . 2009-10-03 16:27 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.1.8\SetupAdmin.exe
2009-09-11 14:18 . 2005-08-16 04:18 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-10 14:54 . 2008-08-03 09:18 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 14:53 . 2008-08-03 09:18 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-06 16:11 . 2006-02-25 16:32 4184 --sha-w- c:\windows\system32\KGyGaAvL.sys
2009-09-04 21:03 . 2005-08-16 04:18 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-29 07:36 . 2005-08-16 04:18 832512 ------w- c:\windows\system32\wininet.dll
2009-08-29 07:36 . 2005-08-16 04:18 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-08-29 07:36 . 2005-08-16 04:18 17408 ----a-w- c:\windows\system32\corpol.dll
2009-08-28 18:42 . 2009-06-20 18:19 40448 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2009-08-28 18:42 . 2009-06-20 18:19 2065696 ----a-w- c:\windows\system32\usbaaplrc.dll
2009-08-26 08:00 . 2005-08-16 04:19 247326 ----a-w- c:\windows\system32\strmdll.dll
2006-10-10 21:13 . 2006-10-10 21:13 100448 ----a-w- c:\program files\MC
2007-12-22 15:43 . 2006-02-25 16:53 56 --sh--r- c:\windows\system32\8731209D39.sys
.
((((((((((((((((((((((((((((( SnapShot@2009-11-22_13.40.12 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-11-23 19:00 . 2009-11-23 19:00 16384 c:\windows\Temp\Perflib_Perfdata_5a8.dat
+ 2009-11-23 19:00 . 2009-11-23 19:00 16384 c:\windows\Temp\Perflib_Perfdata_338.dat
- 2009-03-04 21:24 . 2009-03-04 21:25 84661 c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
+ 2009-03-04 21:24 . 2009-11-23 16:04 84661 c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
+ 2009-07-18 03:21 . 2009-07-18 03:21 257440 c:\windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
+ 2009-11-23 16:13 . 2009-11-23 16:13 149280 c:\windows\system32\javaws.exe
+ 2009-11-23 16:13 . 2009-11-23 16:13 145184 c:\windows\system32\javaw.exe
+ 2009-11-23 16:13 . 2009-11-23 16:13 145184 c:\windows\system32\java.exe
- 2005-08-16 04:27 . 2009-06-10 15:54 201736 c:\windows\system32\FNTCACHE.DAT
+ 2005-08-16 04:27 . 2009-11-22 17:46 201736 c:\windows\system32\FNTCACHE.DAT
+ 2009-11-23 16:13 . 2009-11-23 16:13 537600 c:\windows\Installer\9c60a.msi
+ 2009-11-23 16:52 . 2009-05-26 11:40 382840 c:\windows\ie7updates\KB976749-IE7\spuninst\updspapi.dll
+ 2009-11-23 16:52 . 2009-05-26 11:40 231288 c:\windows\ie7updates\KB976749-IE7\spuninst\spuninst.exe
+ 2005-08-16 04:18 . 2009-08-14 13:21 1850624 c:\windows\system32\win32k.sys
+ 2005-08-16 04:18 . 2009-10-21 04:08 3598336 c:\windows\system32\mshtml.dll
- 2005-08-16 04:18 . 2009-08-29 07:36 3598336 c:\windows\system32\mshtml.dll
+ 2009-07-18 03:21 . 2009-07-18 03:21 3883424 c:\windows\system32\Macromed\Flash\NPSWF32.dll
+ 2008-10-18 07:42 . 2009-08-14 13:21 1850624 c:\windows\system32\dllcache\win32k.sys
- 2006-05-19 15:06 . 2009-08-29 07:36 3598336 c:\windows\system32\dllcache\mshtml.dll
+ 2006-05-19 15:06 . 2009-10-21 04:08 3598336 c:\windows\system32\dllcache\mshtml.dll
+ 2009-11-23 15:51 . 2009-11-23 15:51 3940352 c:\windows\Installer\13a3108.msi
+ 2009-11-23 16:52 . 2009-08-29 07:36 3598336 c:\windows\ie7updates\KB976749-IE7\mshtml.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Creative Detector"="c:\program files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-02 102400]
"DellSupport"="c:\program files\Dell Support\DSAgnt.exe" [2004-07-19 306688]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-15 68856]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 204288]
"V Stuff Backup"="c:\program files\VirginMedia\V Stuff Backup\v_stuff_backup.exe" [2009-08-14 9102608]
"SetDefaultMIDI"="MIDIDef.exe" - c:\windows\MIDIDEF.EXE [2004-12-22 24576]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-05 344064]
"IntelMeM"="c:\program files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-03 221184]
"CTSysVol"="c:\program files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe" [2005-09-15 57344]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"VoiceCenter"="c:\program files\Creative\VoiceCenter\AndreaVC.exe" [2005-09-19 1159168]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"AOLDialer"="c:\program files\Common Files\AOL\ACS\AOLDial.exe" [2007-01-10 71216]
"AOL Spyware Protection"="c:\progra~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe" [2004-03-19 78960]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"Corel Photo Downloader"="c:\program files\Corel\Corel Photo Album 6\MediaDetect.exe" [2005-11-17 106496]
"EPSON Stylus Photo R220 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIAIE.EXE" [2005-03-09 98304]
"RepliGo Assistant"="c:\program files\Cerience\RepliGo\RepliGoMon.exe" [2005-11-07 172032]
"HostManager"="c:\program files\Common Files\AOL\1183232413\ee\AOLSoftware.exe" [2006-11-17 50736]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-21 305440]
"MSKDetectorExe"="c:\program files\McAfee\SpamKiller\MSKDetct.exe" [2006-11-07 1121280]
"Broadbandadvisor.exe"="c:\program files\Virgin Broadband\advisor\Broadbandadvisor.exe" [2009-05-27 2303216]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-11-23 149280]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2005-03-23 339968]
"MBMon"="CTMBHA.DLL" - c:\windows\system32\CTMBHA.DLL [2005-05-19 1345520]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\Nick Parker\Start Menu\Programs\Startup\
palmOne Registration.lnk - c:\program files\Palm\register.exe [2006-2-26 2367488]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
AOL 9.0 Tray Icon.lnk - c:\program files\AOL 9.0\aoltray.exe [2006-2-20 156784]
Exif Launcher S.lnk - c:\program files\FinePixViewerS\QuickDCF2.exe [2007-10-20 303104]
Extender Resource Monitor.lnk - c:\windows\ehome\RMSysTry.exe [2005-10-20 18432]
HOTSYNCSHORTCUTNAME.lnk - c:\program files\Palm\Hotsync.exe [2004-6-9 471040]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
Picture Package Menu.lnk - c:\program files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe [2006-3-2 151552]
Picture Package VCD Maker.lnk - c:\program files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe [2006-3-2 106496]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ PDBoot.exe\0autocheck autochk *
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Palm\\HOTSYNC.EXE"=
"c:\\Program Files\\Microsoft Games\\Age of Empires II\\EMPIRES2.ICD"=
"c:\\Documents and Settings\\Shirley King\\Application Data\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe"=
"c:\\Program Files\\AOL 9.0\\waol.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Ubisoft\\THE SETTLERS - Rise of an Empire Demo\\base\\bin\\Settlers6Demo.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3776:UDP"= 3776:UDP:Media Center Extender Service
"3390:TCP"= 3390:TCP:Remote Media Center Experience
"3389:TCP"= 3389:TCP:*

isabled

xpsp2res.dll,-22009
R2 PD91Agent;PD91Agent;c:\program files\Raxco\PerfectDisk2008\PD91Agent.exe [22/09/2008 16:58 693512]
R2 RadialpointSafeConnectAgent;Virgin Broadband PCguard SafeConnectAgent;c:\program files\Virgin Broadband\PCguard\SafeConnect\bin\SanaAgent.exe [14/11/2008 18:28 4937752]
R3 RadialpointSafeConnectDriver;RadialpointSafeConnectDriver;c:\program files\Virgin Broadband\PCguard\SafeConnect\Driver\platform_XP\SafeConnectDriver.sys [14/11/2008 18:28 161304]
R3 RadialpointSafeConnectFilter;RadialpointSafeConnectFilter;c:\program files\Virgin Broadband\PCguard\SafeConnect\Driver\platform_XP\SafeConnectFilter.sys [14/11/2008 18:28 29720]
R3 RadialpointSafeConnectShim;RadialpointSafeConnectShim;c:\program files\Virgin Broadband\PCguard\SafeConnect\Driver\platform_XP\SafeConnectShim.sys [14/11/2008 18:28 27376]
S3 PD91Engine;PD91Engine;c:\program files\Raxco\PerfectDisk2008\PD91Engine.exe [22/09/2008 16:58 910600]
S3 Radialpoint Security Services;Virgin Broadband PCguard;c:\program files\Virgin Broadband\PCguard\RpsSecurityAwareR.exe [27/05/2009 13:10 170736]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
QWAVE REG_MULTI_SZ QWAVE
.
Contents of the 'Scheduled Tasks' folder
2009-11-03 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
.
------- Supplementary Scan -------
.
uStart Page =
www.ntlworld.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Google Search
IE: &Translate English Word
IE: Backward Links
IE: Cached Snapshot of Page
IE: Similar Pages
IE: Translate Page into English
FF - ProfilePath - c:\documents and settings\Shirley King\Application Data\Mozilla\Firefox\Profiles\8rr57ers.default\
FF - prefs.js: keyword.URL - hxxp://www.ask.com/web?&o=13048&l=dis&q=
FF - plugin: c:\program files\Microsoft Silverlight\npctrl.1.0.20926.0.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - plugin: c:\program files\Virgin Broadband\advisor\nprpspa.dll
---- FIREFOX POLICIES ----
FF - user.js: dom.disable_open_during_load - false // Popupblocker control handled by McAfee Privacy Service
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-11-23 19:02
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(3220)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\program files\Creative\Creative Zen Micro\Zen Micro Media Explorer\CTJBNS2.dll
c:\program files\Creative\Creative Zen Micro\Zen Micro Media Explorer\CTIntrfc.dll
c:\program files\Creative\Creative Zen Micro\Zen Micro Media Explorer\CTConfig.DLL
c:\program files\Creative\Creative Zen Micro\Zen Micro Media Explorer\JBNSRES.DLL
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\program files\Virgin Broadband\PCguard\Fws.exe
c:\program files\Common Files\AOL\ACS\AOLAcsd.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\CTsvcCDA.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\ehome\RMSvc.exe
c:\windows\ehome\McrdSvc.exe
c:\program files\Windows Media Player\WMPNetwk.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\Rundll32.exe
c:\windows\eHome\ehmsas.exe
c:\docume~1\SHIRLE~1\LOCALS~1\Temp\clclean.0001
c:\program files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-11-23 19:11 - machine was rebooted
ComboFix-quarantined-files.txt 2009-11-23 19:11
ComboFix2.txt 2009-11-22 23:35
ComboFix3.txt 2009-11-22 13:49
ComboFix4.txt 2008-08-03 12:37
Pre-Run: 99,488,022,528 bytes free
Post-Run: 99,440,410,624 bytes free
- - End Of File - - 57BE2A39313B053B51C85B79C7DBA5D1