combo
ComboFix 08-08-30.03 - kkooo 2008-08-29 21:45:07.5 -
FAT32x86
Running from: C:\Documents and Settings\kkooo\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\kkooo\Application Data\macromedia\Flash Player\#SharedObjects\JDU9UDDQ\static.youku.com
C:\Documents and Settings\kkooo\Application Data\macromedia\Flash Player\#SharedObjects\JDU9UDDQ\static.youku.com\v1.0.0318\v\swf\qplayer.swf\qplayer.sol
C:\Documents and Settings\kkooo\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#static.youku.com
C:\Documents and Settings\kkooo\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#static.youku.com\settings.sol
C:\Documents and Settings\kkooo\Cookies\kkooo@aniscartujo[2].txt
C:\Documents and Settings\kkooo\Start Menu\Programs\Startup\Deewoo.lnk
C:\Documents and Settings\kkooo\Start Menu\Programs\Startup\DW_Start.lnk
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\WINDOWS\BM670e68bf.txt
C:\WINDOWS\faceback.exe
C:\WINDOWS\Fonts\Setup.exe
C:\WINDOWS\system32\acxkhylp.exe
C:\WINDOWS\system32\blphcrpdj0er4j.scr
C:\WINDOWS\system32\dwwnw64r.exe
C:\WINDOWS\system32\hbxcra.dll
C:\WINDOWS\system32\liurgvwc.dll
C:\WINDOWS\system32\lphcrpdj0er4j.exe
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mjbnsxkj.exe
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\msnav32.ax
C:\WINDOWS\system32\onkjkpqu.dll
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\phcrpdj0er4j.bmp
C:\WINDOWS\system32\qoMfedCu.dll
C:\WINDOWS\system32\rnypfpxd.dll
C:\WINDOWS\system32\rqRHyxyY.dll
C:\WINDOWS\system32\swmwrt.dll
C:\WINDOWS\system32\tsYaHRqr.ini
C:\WINDOWS\system32\tsYaHRqr.ini2
C:\WINDOWS\system32\uqpkjkno.ini
C:\WINDOWS\system32\winpfz33.sys
C:\WINDOWS\system32\yjrcjmer.dll
C:\WINDOWS\system32\zxdnt3d.cfg
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_CMDSERVICE
-------\Legacy_NETWORK_MONITOR
-------\Legacy_TNIDRIVER
-------\Service_TnIDriver
((((((((((((((((((((((((( Files Created from 2008-07-28 to 2008-08-30 )))))))))))))))))))))))))))))))
.
2008-08-29 09:56 . 2008-08-29 09:56 <DIR> d-------- C:\WINDOWS\system32\unknown
2008-08-29 06:21 . 2008-08-29 06:21 <DIR> d-------- C:\Program Files\Spyware Doctor
2008-08-29 02:05 . 2008-08-29 02:05 <DIR> d--hs---- C:\WINDOWS\U2FudGE
2008-08-29 02:05 . 2008-08-29 02:05 548,928 --a------ C:\WINDOWS\system32\ncntqtdl.exe
2008-08-29 02:05 . 2008-08-29 02:05 153,444 --a------ C:\WINDOWS\system32\g59.exe
2008-08-29 02:04 . 2008-08-29 02:04 <DIR> d-------- C:\WINDOWS\system32\wTR02
2008-08-29 02:04 . 2008-08-29 02:04 <DIR> d-------- C:\WINDOWS\system32\towl
2008-08-29 02:04 . 2008-08-29 02:04 <DIR> d-------- C:\WINDOWS\system32\tec
2008-08-29 02:04 . 2008-08-29 02:04 <DIR> d-------- C:\WINDOWS\system32\dbl
2008-08-29 02:04 . 2008-08-29 02:04 <DIR> d-------- C:\WINDOWS\system32\bdir
2008-08-29 02:04 . 2008-08-29 02:04 <DIR> d-------- C:\Temp\dax41
2008-08-29 02:04 . 2008-08-29 02:04 <DIR> d-------- C:\Temp
2008-08-29 02:01 . 2008-08-29 02:01 <DIR> d--hs---- C:\FOUND.000
2008-08-28 21:49 . 2008-08-28 21:49 <DIR> d-------- C:\Documents and Settings\kkooo\Application Data\LimeWire
2008-08-28 12:47 . 2008-08-28 12:47 <DIR> d-------- C:\Program Files\AIM Search
2008-08-28 12:46 . 2008-08-28 12:46 <DIR> d-------- C:\Program Files\Viewpoint
2008-08-28 05:09 . 2008-08-28 05:09 51,436 --ah----- C:\WINDOWS\system32\mlfcache.dat
2008-08-28 03:32 . 2008-08-28 03:32 <DIR> d-------- C:\Program Files\Safari
2008-08-28 03:23 . 2008-08-28 03:24 <DIR> d-------- C:\Program Files\QuickTime
2008-08-28 03:20 . 2008-08-28 03:20 <DIR> d-------- C:\Program Files\Apple Software Update
2008-08-27 08:26 . 2008-08-28 08:27 758 ---hs---- C:\WINDOWS\system32\wdpdjaaj.ini
2008-08-27 08:26 . 2008-08-27 08:26 0 --a------ C:\WINDOWS\BM670e68bf.xml
2008-08-27 05:58 . 2008-08-27 05:58 <DIR> d-------- C:\Documents and Settings\kkooo\Application Data\imo.im
2008-08-27 05:28 . 2008-08-27 05:28 <DIR> d-------- C:\Documents and Settings\kkooo\DoctorWeb
2008-08-27 00:07 . 2008-08-27 00:07 <DIR> d-------- C:\Documents and Settings\kkooo\Application Data\Thinstall
2008-08-26 12:29 . 2008-08-26 12:29 <DIR> d-------- C:\Program Files\AOL Search
2008-08-26 12:28 . 2008-08-26 12:28 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-08-26 06:35 . 2008-08-26 06:35 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\NCH Software
2008-08-26 01:52 . 2004-05-13 17:32 276,480 --a------ C:\WINDOWS\system32\slbcsp.dll
2008-08-26 01:52 . 2004-05-13 17:27 171,008 --a------ C:\WINDOWS\system32\sccsccp.dll
2008-08-26 01:52 . 2004-05-13 17:27 169,984 --a------ C:\WINDOWS\system32\sccbase.dll
2008-08-26 01:52 . 2004-05-13 17:33 89,600 --a------ C:\WINDOWS\system32\slbiop.dll
2008-08-26 01:52 . 2004-05-13 17:33 14,848 --a------ C:\WINDOWS\system32\slbrccsp.dll
2008-08-25 20:33 . 2008-08-25 20:33 <DIR> d-------- C:\Documents and Settings\kkooo\Application Data\Apple Computer
2008-08-25 20:32 . 2008-08-25 20:32 <DIR> d-------- C:\Documents and Settings\kkooo
2008-08-25 05:26 . 2008-08-25 05:26 <DIR> d-------- C:\Program Files\Bonjour
2008-08-25 05:21 . 2008-08-25 05:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-07-17 17:46 . 2008-08-26 01:15 250 --a------ C:\WINDOWS\gmer.ini
2008-07-15 13:42 . 2007-09-24 23:31 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-07-14 22:38 . 2008-07-14 22:38 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-07-14 22:31 . 2008-07-14 22:31 <DIR> d-------- C:\Program Files\Trend Micro
2008-07-13 21:07 . 2008-07-13 21:07 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-07-13 21:07 . 2008-07-13 21:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-13 17:47 . 2008-07-13 17:47 <DIR> d-------- C:\Program Files\Opera
2008-07-13 17:44 . 2008-07-13 17:44 262,144 --a------ C:\Documents and Settings\KEATON~3
2008-07-13 17:44 . 2008-07-13 17:44 262,144 --a------ C:\Documents and Settings\KEATON~1
2008-07-13 12:34 . 2008-07-13 12:34 262,144 --a------ C:\Documents and Settings\KEF90A~3.KEA
2008-07-13 12:34 . 2008-07-13 12:34 262,144 --a------ C:\Documents and Settings\keaton1
2008-07-13 10:35 . 2008-07-13 10:35 717,296 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2008-07-13 01:52 . 2008-07-13 01:52 <DIR> d-------- C:\Documents and Settings\Default User
2008-07-11 23:31 . 2008-07-11 23:31 262,144 --a------ C:\Documents and Settings\KEF90A~2.KEA
2008-07-11 23:30 . 2008-07-11 23:30 <DIR> d-------- C:\Documents and Settings\Administrator
2008-07-11 18:47 . 2008-07-15 17:30 4,298 ---hs---- C:\WINDOWS\system32\uvphrjcr.ini
2008-07-11 17:39 . 2008-07-11 17:39 262,144 --a------ C:\Documents and Settings\KEF90A~1.KEA
2008-07-11 17:39 . 2008-07-11 17:39 262,144 --a------ C:\Documents and Settings\AD59A3~1
2008-07-11 17:22 . 2008-07-11 17:34 262,144 --a------ C:\Documents and Settings\KEATON~4.KEA
2008-07-11 17:22 . 2008-07-11 17:34 262,144 --a------ C:\Documents and Settings\ADMINI~4
2008-07-11 17:04 . 2008-07-11 17:04 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-07-11 17:04 . 2008-07-11 17:04 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-07-11 17:04 . 2008-07-11 17:04 76,040 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-07-11 17:04 . 2008-07-11 17:04 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-07-11 16:56 . 2008-07-11 17:06 8,192 --a------ C:\Documents and Settings\KEATON~3.KEA
2008-07-11 16:56 . 2008-07-11 17:06 8,192 --a------ C:\Documents and Settings\ADMINI~3
2008-07-11 14:29 . 2008-07-11 14:29 262,144 --a------ C:\Documents and Settings\KEATON~2.KEA
2008-07-11 14:29 . 2008-07-11 14:29 262,144 --a------ C:\Documents and Settings\ADMINI~2
2008-07-11 11:44 . 2008-07-11 12:19 262,144 --a------ C:\Documents and Settings\ADMINI~1
2008-07-11 11:44 . 2008-07-11 17:06 8,192 --a------ C:\Documents and Settings\T_REX
2008-07-11 11:44 . 2008-07-11 17:06 8,192 --a------ C:\Documents and Settings\BLAHBLAH
2008-07-11 11:44 . 2008-07-11 17:06 8,192 --a------ C:\Documents and Settings\blah13
2008-07-11 11:43 . 2008-07-11 12:19 262,144 --a------ C:\Documents and Settings\KEATON~1.KEA
2008-07-11 11:43 . 2008-07-11 17:06 8,192 --a------ C:\Documents and Settings\KEATON20
2008-07-11 11:43 . 2008-07-11 17:06 8,192 --a------ C:\Documents and Settings\keaton
2008-07-11 11:43 . 2008-07-11 17:06 8,192 --a------ C:\Documents and Settings\every1
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-29 18:09 2,036,227 ----a-w C:\Program Files\zia01476
2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 17:41 245,248 ------w C:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 17:41 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-06-20 10:45 360,320 ------w C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 10:44 138,368 ------w C:\WINDOWS\system32\dllcache\afd.sys
2008-06-20 09:52 225,920 ------w C:\WINDOWS\system32\dllcache\tcpip6.sys
2008-06-13 13:10 272,128 ------w C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-06 16:24 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE
2008-06-06 16:24 307,200 ------w C:\WINDOWS\Setup1.exe
2008-05-15 19:58 403,794 ----a-w C:\WINDOWS\469.exe
2008-05-14 05:45 737,280 ----a-w C:\WINDOWS\iun6002.exe
2008-05-08 12:28 202,752 ------w C:\WINDOWS\system32\dllcache\rmcast.sys
2008-05-07 05:18 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2008-05-07 05:18 1,287,680 ------w C:\WINDOWS\system32\dllcache\quartz.dll
2007-04-23 22:21 269,824 ----a-w C:\WINDOWS\inf\WG111v3\Vista64\wg111v3.sys
2007-04-23 22:11 224,896 ----a-w C:\WINDOWS\inf\WG111v3\wg111v3.sys
2006-12-15 19:30 98,304 ----a-w C:\WINDOWS\inf\WG111v3\UScanM.exe
2006-12-15 19:30 66,048 ----a-w C:\WINDOWS\inf\WG111v3\EAPPkt.sys
2006-12-15 19:30 315,392 ----a-w C:\WINDOWS\inf\WG111v3\InstallDriver.exe
2006-12-15 19:30 28,672 ----a-w C:\WINDOWS\inf\WG111v3\SetDrv.exe
2006-12-15 19:30 212,992 ----a-w C:\WINDOWS\inf\WG111v3\CopyWHQLDriver.exe
2006-12-15 19:30 20,480 ----a-w C:\WINDOWS\inf\WG111v3\RTWUPath.exe
2006-12-15 19:30 19,968 ----a-w C:\WINDOWS\inf\WG111v3\RTWREFU.EXE
2005-08-03 00:46 187,904 --sha-r C:\WINDOWS\U2FudGE\asappsrv.dll
2005-08-03 00:58 293,888 --sha-r C:\WINDOWS\U2FudGE\command.exe
2005-07-30 00:24 472 --sha-r C:\WINDOWS\U2FudGE\oZIRx3H.vbs
.
------- Sigcheck -------
2002-12-31 12:00 17408 41fbc74ad30ec94ccb5e381adff97801 C:\WINDOWS\system32\svchost.exe
2002-12-31 12:00 506368 57fe5ee5e09a64592c68aa4b0e006db9 C:\WINDOWS\system32\winlogon.exe
2007-06-12 23:23 1035776 3fbd51a7602a6b620be096b72e7a7a27 C:\WINDOWS\explorer.exe
2007-06-12 23:23 1033216 97bd6515465659ff8f3b7be375b2ea87 C:\WINDOWS\VCP_TEMP\explorer.exe
2007-06-12 23:23 1033216 97bd6515465659ff8f3b7be375b2ea87 C:\WINDOWS\VCP_SAVE\explorer.exe
2007-06-13 00:26 1033216 7712df0cdde3a5ac89843e61cd5b3658 C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
2007-06-12 23:23 1033216 97bd6515465659ff8f3b7be375b2ea87 C:\WINDOWS\SoftwareDistribution\Download\44d74c37f0595a363bcec5e9229d8564\sp2gdr\explorer.exe
2007-06-13 00:26 1033216 7712df0cdde3a5ac89843e61cd5b3658 C:\WINDOWS\SoftwareDistribution\Download\44d74c37f0595a363bcec5e9229d8564\sp2qfe\explorer.exe
2002-12-31 12:00 1032192 a0732187050030ae399b241436565e64 C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
2002-12-31 12:00 110592 207939da390a3cef38fdf89cf5f42277 C:\WINDOWS\system32\services.exe
2002-12-31 12:00 14848 d2d425dcd5a37199666e21b826f52fee C:\WINDOWS\system32\lsass.exe
2005-06-10 16:53 58880 d519475810eb24a5cbb31bcc45e19622 C:\WINDOWS\system32\spoolsv.exe
2005-06-10 17:17 57856 ad3d9d191aea7b5445fe1d82ffbb4788 C:\WINDOWS\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
2002-12-31 13:00 57856 7435b108b935e42ea92ca94f59c8e717 C:\WINDOWS\$NtUninstallKB896423$\spoolsv.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"IPHSend"="C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe" [2006-02-17 08:59 124520]
"AIMWDInstallFilename"="C:\Program Files\AIM\AIMWDInstall.exe" [2004-01-12 09:29 102400]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-05-27 10:50 413696]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableStatusMessages"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.MJPG"= jl_mjpg2.drv
"msacm.fraunhoferacm"= l3codecp.acm
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\Spybot - Search & Destroy\\SDShred.exe"=
"C:\\Program Files\\NETGEAR\\WG111v3\\WG111v3.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\Common Files\\AOL\\1214617059\\ee\\aolsoftware.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"86:TCP"= 86:TCP:BroadCam Web Server
R2 avg8emc;AVG Free8 E-mail Scanner;C:\WINDOWS\system32\DRIVERS\avg8emc.syS []
R2 avg8wd;AVG Free8 WatchDog;C:\WINDOWS\system32\DRIVERS\avg8wd.syS []
R3 ASPI;Advanced SCSI Programming Interface Driver;C:\WINDOWS\System32\DRIVERS\ASPI32.sys [2002-07-17 09:05]
R3 JL2005;JL2005A Toy Camera;C:\WINDOWS\system32\DRIVERS\JL2005.syS []
R3 SCREAMINGBDRIVER;Screaming Bee Audio;C:\WINDOWS\system32\drivers\ScreamingBAudio.sys []
R3 USRTI;U.S. Robotics Faxmodem Driver TI;C:\WINDOWS\system32\DRIVERS\USRTI.SYS [2004-12-24 11:16]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\System32\Drivers\avgldx86.sys [2008-07-11 17:04]
S2 AvgTdiX;AVG Free8 Network Redirector;C:\WINDOWS\System32\Drivers\avgtdix.sys [2008-07-11 17:04]
S2 Viewpoint Manager Service;Viewpoint Manager Service;C:\Program Files\Viewpoint\Common\ViewpointService.exe [2007-01-04 13:38]
S3 ctlsb16;Creative SB16/AWE32/AWE64 Driver (WDM);C:\WINDOWS\system32\drivers\ctlsb16.sys [2004-12-24 11:15]
S3 es1969;ESS 1969 Audio Driver (WDM);C:\WINDOWS\system32\drivers\es1969.sys [2004-12-24 11:15]
S3 FA312;NETGEAR FA330/FA312/FA311 Fast Ethernet Adapter Driver;C:\WINDOWS\system32\DRIVERS\FA312nd5.sys [2004-12-24 11:15]
S3 RTL8187B;NETGEAR WG111v3 54Mbps Wireless USB 2.0 Adapter Vista Driver;C:\WINDOWS\system32\DRIVERS\wg111v3.sys [2007-04-23 14:11]
S3 S3SAVAGE4M;S3SAVAGE4M;C:\WINDOWS\system32\DRIVERS\s3sav4m.sys [2004-12-24 11:16]
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -
URLSearchHooks-HookURL - (no file)
URLSearchHooks-Rank - (no file)
URLSearchHooks-HookURL - (no file)
URLSearchHooks-Rank - (no file)
BHO-{76FE34BE-BD5D-4A35-B131-1F588F2D65FE} - C:\WINDOWS\system32\rqRHaYst.dll
HKLM-Run-643d5b23 - C:\WINDOWS\system32\onkjkpqu.dll
HKLM-Run-lphcrpdj0er4j - C:\WINDOWS\system32\lphcrpdj0er4j.exe
HKLM-Run-{D5-5B-B8-8C-DW} - C:\windows\system32\dwwnw64r.exe
Notify-ddcDvvUL - ddcDvvUL.dll
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\kkooo\Application Data\Mozilla\Firefox\Profiles\gzajy2e7.default\
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npqtplugin8.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll
FF -: plugin - C:\Program Files\Opera\program\plugins\npjava11.dll
FF -: plugin - C:\Program Files\Opera\program\plugins\npjava12.dll
FF -: plugin - C:\Program Files\Opera\program\plugins\npjava13.dll
FF -: plugin - C:\Program Files\Opera\program\plugins\npjava14.dll
FF -: plugin - C:\Program Files\Opera\program\plugins\npjava32.dll
FF -: plugin - C:\Program Files\Opera\program\plugins\npjpi160_03.dll
FF -: plugin - C:\Program Files\Opera\program\plugins\npoji610.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-08-29 21:53:02
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\SYSTEM32\MSDTC.EXE
C:\PROGRAM FILES\BONJOUR\MDNSRESPONDER.EXE
C:\WINDOWS\SYSTEM32\WDFMGR.EXE
C:\WINDOWS\SYSTEM32\MQSVC.EXE
C:\WINDOWS\SYSTEM32\WSCNTFY.EXE
C:\Program Files\NETGEAR\WG111v3\WG111v3.exe
C:\WINDOWS\system32\rundll32.exe
.
**************************************************************************
.
Completion time: 2008-08-29 21:57:32 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-30 05:57:02
Pre-Run: 5,701,074,944 bytes free
Post-Run: 5,743,083,520 bytes free
266 --- E O F --- 2008-06-27 21:26:32