Below is the log from Combofix. As it was running, I noticed it deleted that .sys file we had worked with earlier.
Several of these error boxes popped up during the log reporting: "Generic Host Process for Win32 Services encountered a problem and needed to close." Those seem to pop-up quite often during "idle" time, along with the svchost.exe errors.
Thanks!!!
ComboFix 08-03-09.1 - HP_Administrator 2008-03-09 15:44:01.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.438 [GMT -6:00]
Running from: C:\Documents and Settings\HP_Administrator\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\drivers\Ipw31.sys
C:\WINDOWS\system32\drivers\symavc32.sys
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_IPW31
-------\Ipw31
((((((((((((((((((((((((( Files Created from 2008-02-09 to 2008-03-09 )))))))))))))))))))))))))))))))
.
2008-03-09 15:55 . 2008-03-09 15:55 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-03-09 15:55 . 2008-03-09 15:55 1,409 --a------ C:\WINDOWS\QTFont.for
2008-03-09 15:54 . 2008-03-09 15:54 26,496 --a------ C:\WINDOWS\system32\drivers\Tcj86.sys
2008-03-09 15:54 . 2008-03-09 15:54 11,776 --a------ C:\WINDOWS\system32\WLCtrl32.dl_
2008-03-08 21:17 . 2008-03-08 21:17 <DIR> d-------- C:\Program Files\Yahoo! Companion
2008-03-07 15:23 . 2008-03-07 15:23 <DIR> d-------- C:\Program Files\Sun
2008-03-07 15:23 . 2008-02-22 03:33 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-03-04 08:44 . 2008-03-04 08:44 91,904 --a------ C:\WINDOWS\system32\cliconfgg.1
2008-03-03 15:26 . 2008-03-03 15:26 <DIR> d-------- C:\Program Files\Trend Micro
2008-03-03 15:15 . 2008-03-03 15:15 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-03-03 15:15 . 2008-03-03 15:15 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-03-03 09:41 . 2008-03-03 09:41 51,968 --a------ C:\WINDOWS\system32\drivers\nkv2.sys
2008-03-02 13:59 . 2008-03-02 13:59 <DIR> d-------- C:\SiteAdvisor
2008-03-02 13:59 . 2008-03-02 13:59 <DIR> d-------- C:\McAfee
2008-03-02 11:51 . 2008-03-02 11:51 <DIR> d-------- C:\Program Files\Common Files\Scanner
2008-03-02 11:50 . 2008-03-02 11:57 <DIR> d-------- C:\Program Files\CA Yahoo! Anti-Spy
2008-02-29 11:17 . 2008-02-29 11:17 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\Yahoo!
2008-02-29 11:14 . 2008-03-09 15:53 8,729 --a------ C:\WINDOWS\system32\Config.MPF
2008-02-29 10:35 . 2008-03-03 13:11 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2008-02-29 10:33 . 2007-07-21 10:08 201,288 --a------ C:\WINDOWS\system32\drivers\mfehidk.sys
2008-02-29 10:33 . 2007-07-13 10:20 113,952 --a------ C:\WINDOWS\system32\drivers\Mpfp.sys
2008-02-29 10:33 . 2007-07-24 08:40 79,304 --a------ C:\WINDOWS\system32\drivers\mfeavfk.sys
2008-02-29 10:33 . 2007-07-21 10:08 40,488 --a------ C:\WINDOWS\system32\drivers\mfesmfk.sys
2008-02-29 10:33 . 2007-07-21 10:08 35,240 --a------ C:\WINDOWS\system32\drivers\mfebopk.sys
2008-02-29 10:33 . 2007-07-24 13:02 33,800 --a------ C:\WINDOWS\system32\drivers\mferkdk.sys
2008-02-29 10:32 . 2008-02-29 10:33 <DIR> d-------- C:\Program Files\McAfee.com
2008-02-29 10:32 . 2008-02-29 11:52 <DIR> d-------- C:\Program Files\McAfee
2008-02-29 10:32 . 2008-02-29 10:33 <DIR> d-------- C:\Program Files\Common Files\McAfee
2008-02-29 10:23 . 2008-02-29 11:13 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\McAfee
2008-02-29 10:11 . 2008-02-29 10:11 108 --a------ C:\WINDOWS\system32\ikhcore.cfg
2008-02-28 10:08 . 2008-03-09 08:51 11,776 --a------ C:\WINDOWS\system32\WLCtrl32.dll
2008-02-27 10:47 . 2008-02-27 14:50 <DIR> d-------- C:\Documents and Settings\HP_Administrator\.housecall6.6
2008-02-23 18:08 . 2004-08-04 00:08 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2008-02-23 18:08 . 2004-08-04 00:08 31,616 --a------ C:\WINDOWS\system32\dllcache\usbccgp.sys
2008-02-21 09:07 . 2008-02-21 09:07 <DIR> d-------- C:\Program Files\Enigma Software Group
2008-02-18 14:45 . 2004-08-10 13:00 27,648 --a------ C:\WINDOWS\system32\qprocessu.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-07 21:23 --------- d-----w C:\Program Files\Java
2008-03-07 19:23 --------- d-----w C:\Program Files\QuickTime
2008-03-07 19:23 --------- d-----w C:\Program Files\iTunes
2008-03-06 04:38 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\OpenOffice.org2
2008-03-03 20:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-03-03 20:29 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-03-03 19:13 --------- d--h--r C:\Documents and Settings\HP_Administrator\Application Data\yahoo!
2008-03-03 19:13 --------- d-----w C:\Documents and Settings\All Users\Application Data\yahoo!
2008-03-01 00:39 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-02-29 17:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-02-27 21:45 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-27 10:05 --------- d-----w C:\Program Files\Windows Live
2008-02-23 23:53 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\LimeWire
2008-02-23 23:03 --------- d-----w C:\Program Files\iPod
2008-02-21 15:22 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\AdobeUM
2008-02-20 18:21 --------- d-----w C:\Program Files\Easy Internet signup
2008-02-06 19:05 --------- d-----w C:\Program Files\Common Files\Remote Control USB Driver
2008-02-06 19:05 --------- d-----w C:\Program Files\Common Files\Remote Control Software Shared
2008-02-06 18:44 --------- d-----w C:\Program Files\Logitech
2008-02-04 00:01 --------- d-----w C:\Program Files\Ipswitch
2008-02-04 00:01 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\Ipswitch
2008-02-04 00:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\Ipswitch
2008-02-01 18:11 586,240 ----a-w C:\WINDOWS\WLXPGSS.SCR
2008-01-31 14:41 33,184 ----a-w C:\Documents and Settings\HP_Administrator\Application Data\wklnhst.dat
2008-01-21 16:30 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\Move Networks
2008-01-16 15:58 --------- d-----w C:\Program Files\OpenOffice.org 2.3
2008-01-16 15:57 --------- d-----w C:\Program Files\OpenOffice.org 2.2
2006-01-23 01:54 32 ----a-r C:\Documents and Settings\All Users\hash.dat
2005-05-12 13:36 12,288 ----a-w C:\WINDOWS\Fonts\RandFont.dll
.
((((((((((((((((((((((((((((( snapshot@2008-03-06_11.05.45.88 )))))))))))))))))))))))))))))))))))))))))
.
- 2005-08-05 20:56:34 64,512 ----a-w C:\WINDOWS\ehome\ehtray.exe
+ 2004-08-11 02:04:42 59,392 ----a-w C:\WINDOWS\ehome\ehtray.exe
- 2000-08-31 15:00:00 163,328 ----a-w C:\WINDOWS\erdnt\Hiv-backup\ERDNT.EXE
+ 2000-08-31 14:00:00 163,328 ----a-w C:\WINDOWS\erdnt\Hiv-backup\ERDNT.EXE
- 2000-08-31 15:00:00 163,328 ----a-w C:\WINDOWS\erdnt\subs\ERDNT.EXE
+ 2000-08-31 14:00:00 163,328 ----a-w C:\WINDOWS\erdnt\subs\ERDNT.EXE
- 2000-08-31 15:00:00 28,160 ----a-w C:\WINDOWS\Nircmd.exe
+ 2000-08-31 14:00:00 28,160 ----a-w C:\WINDOWS\Nircmd.exe
- 2008-03-06 18:00:46 49,152 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-03-09 21:56:39 49,152 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-03-06 18:00:46 229,376 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-03-09 21:56:39 360,448 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-03-06 18:01:16 32,768 --sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008030620080307\index.dat
+ 2008-03-07 05:31:20 147,456 --sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008030620080307\index.dat
+ 2008-03-08 01:47:57 114,688 --sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008030720080308\index.dat
+ 2008-03-09 03:04:31 98,304 --sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008030820080309\index.dat
+ 2008-03-09 21:43:26 49,152 --sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008030920080310\index.dat
- 2008-03-06 18:00:46 49,152 --sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-03-09 21:56:39 884,736 --sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2005-08-05 20:56:34 64,512 ----a-w C:\WINDOWS\system32\dllcache\ehtray.exe
+ 2004-08-11 02:04:42 59,392 ----a-w C:\WINDOWS\system32\dllcache\ehtray.exe
- 2007-09-25 05:30:28 135,168 ----a-w C:\WINDOWS\system32\java.exe
+ 2008-02-22 08:23:35 135,168 ----a-w C:\WINDOWS\system32\java.exe
- 2007-09-25 05:30:30 135,168 ----a-w C:\WINDOWS\system32\javaw.exe
+ 2008-02-22 08:23:39 135,168 ----a-w C:\WINDOWS\system32\javaw.exe
- 2007-09-25 06:31:42 139,264 ----a-w C:\WINDOWS\system32\javaws.exe
+ 2008-02-22 09:33:32 139,264 ----a-w C:\WINDOWS\system32\javaws.exe
- 2007-11-12 23:03:14 53,640 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-03-09 21:51:53 53,640 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2007-11-12 23:03:14 382,022 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-03-09 21:51:53 382,022 ----a-w C:\WINDOWS\system32\perfh009.dat
- 2000-08-31 15:00:00 161,792 ----a-w C:\WINDOWS\system32\swreg.exe
+ 2000-08-31 14:00:00 161,792 ----a-w C:\WINDOWS\system32\swreg.exe
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-30 10:51 68856]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [ ]
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 05:40 218032]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 13:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2004-08-10 20:04 59392]
"HPHUPD08"="c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [ ]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPwuSchd2.exe" [ ]
"Zune Launcher"="C:\Program Files\Zune\ZuneLauncher.exe" [2006-12-12 15:45 21464]
"QUICKCARE"="C:\Program Files\Qwest\QuickCare\bin\sprtcmd.exe" [2007-05-09 18:15 198800]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-02-01 00:13 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-19 14:10 267048]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-08-03 23:33 582992]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
C:\Documents and Settings\HP_Administrator\Start Menu\Programs\Startup\
DING!.lnk - C:\Program Files\Southwest Airlines\Ding\Ding.exe [2006-06-22 15:15:48 462848]
Expedia Fare Alert.lnk - C:\Program Files\Expedia\Expedia Fare Alert\ExpediaFareAlert.exe [2007-02-12 10:15:00 696320]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-05-15 02:19:50 217193]
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-10-31 16:32:07 113664]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-12 07:23:26 282624]
NuvaTime(tm).lnk - C:\Program Files\NuvaTime\NuvaTime(tm).exe [2004-05-17 17:34:30 1051655]
Updates from HP.lnk - C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe [2005-10-10 18:15:27 36903]
ymetray.lnk - C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe [2006-10-03 12:04:38 54776]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WLCtrl32]
WLCtrl32.dll 2008-03-09 08:51 11776 C:\WINDOWS\system32\WLCtrl32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"C:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Macromedia\\Dreamweaver MX\\Dreamweaver.exe"=
"C:\\Program Files\\Macromedia\\Flash MX\\Flash.exe"=
"C:\\WINDOWS\\system32\\fxsclnt.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Documents and Settings\\HP_Administrator\\My Documents\\My Music\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader
R0 Tcj86;Tcj86;C:\WINDOWS\system32\Drivers\Tcj86.sys [2008-03-09 15:54]
R2 Belkin 54g Wireless USB Network Adapter Service;Belkin 54g Wireless USB Network Adapter;C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe [2004-03-29 17:08]
S3 bkn50USB;Belkin 54Mbps Wireless USB Network Adapter;C:\WINDOWS\system32\DRIVERS\rt2500usb.sys [2004-07-16 12:14]
S3 Sharump;Sharump;C:\WINDOWS\system32\drivers\dmload.sys [2004-08-10 13:00]
S3 USB2_04;USB2_04 driver;C:\WINDOWS\system32\drivers\nkv2.sys [2008-03-03 09:41]
S3 usbprint;Microsoft USB PRINTER Class;C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-04 00:01]
*Newly Created Service* - TCJ86
.
Contents of the 'Scheduled Tasks' folder
"2008-03-04 05:24:05 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-03-09 21:25:00 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-02-29 16:33:18 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe'
"2008-03-01 08:00:48 C:\WINDOWS\Tasks\McQcTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe
"2008-03-09 07:00:00 C:\WINDOWS\Tasks\Symantec Drmc.job"
- C:\Program Files\Common Files\Symantec Shared\SymDrmc.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-03-09 15:56:26
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\WLCtrl32.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\Program Files\Belkin\Belkin Wireless Network Utility\WLanCfgG.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\Program Files\Zune\ZuneNss.exe
C:\WINDOWS\system32\dllhost.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
.
**************************************************************************
.
Completion time: 2008-03-09 16:04:48 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-09 22:04:43
ComboFix2.txt 2008-03-06 18:09:21
.
2008-02-27 10:06:22 --- E O F ---