ComboFix 09-07-26.03 - Gobbo 07/27/2009 20:10.1.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.991.685 [GMT 2:00]
Running from: c:\documents and settings\Gobbo\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Gobbo\Desktop\CFScript.txt
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Installer\1a6d96.msi
c:\windows\Installer\1a6d97.msp
c:\windows\Installer\1a6d98.msp
c:\windows\Installer\1a6d99.msp
c:\windows\Installer\1a6d9a.msp
c:\windows\Installer\1a6d9b.msp
c:\windows\Installer\1a6d9c.msp
c:\windows\Installer\1a6d9d.msp
c:\windows\Installer\1a6d9e.msp
c:\windows\Installer\1a6d9f.msp
c:\windows\Installer\c29f9.msp
c:\windows\Installer\c29fa.msp
c:\windows\Installer\c29fb.msp
c:\windows\Installer\c29fc.msp
c:\windows\Installer\c29fd.msp
c:\windows\Installer\c29fe.msp
c:\windows\Installer\c29ff.msp
c:\windows\Installer\c2a00.msp
c:\windows\Installer\c2a01.msp
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NPF
((((((((((((((((((((((((( Files Created from 2009-06-27 to 2009-07-27 )))))))))))))))))))))))))))))))
.
2009-07-26 14:16 . 2009-03-30 08:33 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-07-26 14:16 . 2009-03-24 14:08 55640 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-07-26 14:16 . 2009-02-13 10:29 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2009-07-26 14:16 . 2009-02-13 10:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2009-07-26 14:16 . 2009-07-26 14:16 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2009-07-25 11:36 . 2009-07-25 11:36 -------- d-----w- c:\documents and settings\Gobbo\Local Settings\Application Data\MyDownloader
2009-07-25 00:24 . 2009-07-25 00:46 -------- d-----w- c:\program files\vSoft
2009-07-21 20:55 . 2009-07-21 20:55 -------- d-----w- c:\documents and settings\Gobbo\Application Data\JonDo
2009-07-18 14:43 . 2009-07-18 14:43 -------- d-----w- c:\documents and settings\Gobbo\Local Settings\Application Data\Temp
2009-07-14 16:57 . 2003-04-06 17:05 155648 ----a-w- c:\windows\system32\igfxres.dll
2009-07-13 20:36 . 2003-04-06 17:17 221184 ----a-w- c:\windows\system32\igfxeud.dll
2009-07-13 20:36 . 2003-04-06 17:15 45056 ----a-w- c:\windows\system32\igfxdgps.dll
2009-07-13 20:36 . 2003-04-06 17:15 151552 ----a-w- c:\windows\system32\igfxdiag.exe
2009-07-13 20:36 . 2003-04-06 17:07 118784 ----a-w- c:\windows\system32\igfxhk.dll
2009-07-13 19:25 . 2009-07-13 19:25 -------- d-----w- c:\program files\SystemRequirementsLab
2009-07-13 18:52 . 2009-07-13 18:52 -------- d-----w- c:\documents and settings\Gobbo\Application Data\Mchid
2009-07-13 18:52 . 2009-07-13 18:52 -------- d-----w- c:\documents and settings\Gobbo\Application Data\Livestation
2009-07-13 18:52 . 2009-07-13 19:37 -------- d-----w- c:\documents and settings\Gobbo\Livestation
2009-07-13 18:30 . 2009-07-13 18:30 -------- d-----w- c:\documents and settings\Gobbo\Local Settings\Application Data\ZattooPlayer
2009-07-13 18:30 . 2009-07-13 18:39 -------- d-----w- c:\documents and settings\Gobbo\Local Settings\Application Data\Zattoo
2009-07-10 21:20 . 2009-07-10 21:20 -------- d-----w- c:\program files\FileZilla FTP Client
2009-07-10 14:58 . 2009-07-27 17:57 -------- d-----w- c:\documents and settings\Gobbo\Application Data\vlc
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-27 18:04 . 2008-09-19 14:42 -------- d-----w- c:\documents and settings\Gobbo\Application Data\uTorrent
2009-07-26 16:41 . 2009-03-22 15:42 -------- d-----w- c:\documents and settings\Gobbo\Application Data\FileZilla
2009-07-26 15:49 . 2009-07-26 15:49 -------- d-----w- c:\documents and settings\Gobbo\Application Data\Malwarebytes
2009-07-26 15:49 . 2009-07-26 15:49 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-07-26 15:49 . 2009-07-26 15:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-07-26 14:20 . 2008-11-17 09:29 -------- d-----w- c:\program files\Avira
2009-07-26 05:06 . 2006-11-24 13:04 -------- d-----w- c:\program files\FlashGet
2009-07-26 00:32 . 2006-11-16 23:21 -------- d-----w- c:\documents and settings\Gobbo\Application Data\dvdcss
2009-07-25 12:47 . 2006-10-31 19:01 -------- d-----w- c:\program files\Opera
2009-07-25 00:11 . 2006-11-03 21:32 -------- d-----w- c:\program files\BPFTP Server
2009-07-19 15:47 . 2008-10-09 12:01 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-07-13 11:36 . 2009-07-26 15:49 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-13 11:36 . 2009-07-26 15:49 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-16 14:36 . 2001-08-23 12:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 . 2001-08-23 12:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-03 19:09 . 2001-08-23 12:00 1291264 ----a-w- c:\windows\system32\quartz.dll
2009-05-30 01:54 . 2009-05-30 01:54 -------- d--h--w- c:\documents and settings\All Users\Application Data\{A25FEDC1-F6D7-440C-BCE2-B71F595F6646}
2009-05-24 18:56 . 2009-05-24 18:56 390664 ----a-w- c:\documents and settings\Gobbo\Application Data\Real\RealPlayer\Update\RealPlayer11.exe
2009-05-09 23:40 . 2009-05-09 23:40 103872 ----a-w- c:\windows\system32\drivers\AnyDVD.sys
2009-05-07 15:32 . 2001-08-23 12:00 345600 ----a-w- c:\windows\system32\localspl.dll
2009-04-29 04:46 . 2004-01-08 14:23 666624 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:46 . 2004-08-04 07:56 81920 ------w- c:\windows\system32\ieencode.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2002-12-06 126976]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2002-12-06 569344]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2003-04-06 155648]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2003-04-06 114688]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2006-02-07 118784]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2003-04-06 114688]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2003-03-28 53248]
"Resume copy"="copyfstq.exe" - c:\windows\copyfstq.exe [2006-10-31 73728]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"DisableCurrentUserRunOnce"= 0 (0x0)
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0oodbs
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Privoxy.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Privoxy.lnk
backup=c:\windows\pss\Privoxy.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Gobbo^Start Menu^Programs^Startup^CheckMail.LNK]
backup=c:\windows\pss\CheckMail.LNKStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Gobbo^Start Menu^Programs^Startup^Screen Clipper and Launcher til OneNote 2007.lnk]
path=c:\documents and settings\Gobbo\Start Menu\Programs\Startup\Screen Clipper and Launcher til OneNote 2007.lnk
backup=c:\windows\pss\Screen Clipper and Launcher til OneNote 2007.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ProxyCap
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\BPFTP Server\\G6FTPSrv.exe"=
"c:\\Program Files\\FlashFXP\\FlashFXP.exe"=
"d:\\Games\\Diablo II\\Game_crk.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"c:\\Program Files\\Opera\\Opera.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"d:\\Office 2007\\Office12\\OUTLOOK.EXE"=
"d:\\Office 2007\\Office12\\GROOVE.EXE"=
"d:\\Office 2007\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Messenger\\WLM Lite 8.5.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\VoipBuster.com\\VoipBuster\\VoipBuster.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Teamspeak2_RC2\\server_windows.exe"=
"d:\\Program Files\\WASTE\\WASTE.exe"=
"c:\\Program Files\\Java\\jre1.6.0_02\\bin\\javaw.exe"=
"d:\\Program Files\\ProxyWay\\proxyway.exe"=
R0 cdburner;cdburner;c:\windows\system32\drivers\cdburner.sys [9/17/2008 21:46 15872]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [7/26/2009 16:16 108289]
R2 CLEVOIO;CLEVOIO;c:\windows\system32\drivers\CLEVOIO.sys [8/29/2002 18:30 13104]
S0 Ramdisk;Ramdisk Driver;c:\windows\system32\drivers\RamDsk.sys [9/28/2004 05:00 26240]
S0 tclondrv;tclondrv;c:\windows\system32\DRIVERS\tclondrv.sys --> c:\windows\system32\DRIVERS\tclondrv.sys [?]
S2 AntiVirUpgradeService;Avira Upgrade Service;"c:\docume~1\Gobbo\LOCALS~1\Temp\AVSETUP_4a6c6407\basic\avupgsvc.exe" /TEMPSTART:""c:\docume~1\Gobbo\LOCALS~1\Temp\AVSETUP_4a6c6407\basic\setup.exe" /NOTEMPCLEANUP /CROSSUPGRADE" --> c:\docume~1\Gobbo\LOCALS~1\Temp\AVSETUP_4a6c6407\basic\avupgsvc.exe [?]
S3 MovRVDrv32;MovRVDrv32;c:\windows\system32\drivers\MovRVDrv32.sys [9/17/2008 18:43 3768]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{B2C3BB6B-E005-4246-B8E5-DF0A4D073CDC}]
c:\program files\PixiePack Codec Pack\InstallerHelper.exe
.
Contents of the 'Scheduled Tasks' folder
2008-07-17 c:\windows\Tasks\Shut Down.job
- d:\appz\Shut Down.bat [2008-03-10 22:28]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.google.com/uInternet Settings,ProxyServer = 127.0.0.1:4001
IE: Download All by FlashGet - c:\program files\FlashGet\jc_all.htm
IE: Download using FlashGet - c:\program files\FlashGet\jc_link.htm
IE: E&ksporter til Microsoft Excel - d:\office 2007\Office12\EXCEL.EXE/3000
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
TCP: {0100DF2F-9A8F-41E4-883E-68D2A0D1F70E} = 208.67.222.222,208.67.220.220
DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} -
hxxps://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab.
**************************************************************************
creating catchme.sys error: The process cannot access the file because it is being used by another process.
driver loading error catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-07-27 20:16
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-484763869-842925246-854245398-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{73DDA0CF-B141-5588-4684-2CCC0263C684}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"iacjpkodjiobofhjnh"=hex:6b,61,6c,6f,69,69,6f,64,63,62,68,70,6d,63,61,68,6a,65,
6f,6c,6c,6c,00,00
"haakbheaijmdonln"=hex:6b,61,6c,6f,69,69,6f,64,63,62,68,70,6d,63,61,68,6a,65,
6f,6c,6c,6c,00,00
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG11.00.00.01WORKSTATION"="C38E5D0B7D91C6792BA9D7ECB92FFB9314B4BBBB447517280BE5C80AF04AB00F39AFDC20BBB0602A007063B2AB9B37FB9EF1CCEBC399C71DF4BE2837854CB8F1C23AB7EA0331EDB70D9726BE82B93E65039B408AB335BA5578A447606B8703BEFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC79338EDD5E5BE2F6E667C038D530D6EB3452A2D97226D213B5555C855DE6B661B21835AD6948B5D6E7FEB2ED3B8896773DEBF41D0CAF307EAC69F02C23AA6C0D542CEA329E6B03DEC810FC4B5BC450587D66334FD925B3D9B811B9CB411689EC1FEE92D9F013A538479AE1BA972FEA4ADEF2C8496706EBB5637BCDBB52049C70E6065EB3D8789615E7314C9EEA7BEBE7B833F663D0A2852EF377EAE82F029B5A810C21619385B3FDB35A4A6D9194371CE4B92609F3800E373544EE5378D35E414D8BD61720DB3E50368F0EAF0D1497283F0B5FB9F15A7B957595DD8E10EE208F2807199E42CB5CB981BD6B06234CBBA12B255407B21C24628813E1C49DFD830576F3AB5404E0163DA8495E22DBC236700EF5D59ADF69C20C43D8C3308CDF8BB31FB9F1ABAED2D8B5C58684C9042EFDD050E05AAD661576D401F7F5218B27A0038E3674A7D593F74C74BF9E56AD7BEBD5DF3C7E90F8AA4452A0738AFD8D1A10ADB3BB6161C9C5260256B39438AE4B3FE1AF5380A60EE6926D85C3BABDCAB40942030C0988A6C07EAA8F936EEF1F729BAEB4E543E5603CAC6515D362EB3E23A0A27364605D4611FE6DC8855B155C798448E7254D5CEC4FC24ABA067F2926494F8681ED00B348F408C6AE242B51881C671148BAC9A6F6796803E42DB82B86BCF0F8AC4C25769260DD8571FC5661074B913C563F08F8834813490610D4B8A54946587793B122CCFA2C4EC612F59A812CB4541843F99ADD7E9F2B946C3F2E8FECF357EA4C28C862217F98E5D847626597E6B418C8386693904D090C7108FC125A837C91F4338E84E149308CBCACB0E418240D62477B4D762740996AC2632842F65E23FBFC9F2E267F5E35FA1BAB9673EF4A65882A24509C22FDE6B2F9A84875DED779BCC95DF300F2F89B7646EFB44B131B14225035086291F3CE6B22D58A49602283ECB502C08F67B5A947824442E8AABD46C70C5420E13AEF0320BB872D997C5717A78CC60B92BC16FBB98C9C880E91BCFC9626CDD68197A6895CB883070CEAF1DD0C0F095B0E8400831F918F66405A858DB1571080E3562F3AB605B27E0796D4D8BD7347CECA88BC824BB2544F47C86A1FBDCFAC82F5D604C4C3F81E90359D435AE4612996D4447A119706CBC73055A2B0E333DCD964B085AA9EE6F8CD0752E408ADF6F5F8FB65489BDF167569CD2CC911D1187A95212BF5C16510145AAE3B475C47459BCE54519E610660"
"OODEFRAG10.00.00.01WORKSTATION"="FE4E18F54E46A88209A34465B812640B5B93526BC03B854777B914A1DE79EA702DD63C9585AA5D1BF1410BB94666BC21D3A60BAAFBECCBC3E99B654918D6052E667DB79568A702BFAA9E0BEC081DF0A677CC4D8446DD9AD2279E62482CEFFB29F191BE77948068994F011B1E47FDC274DDDEB0D3AC7DC498DD4D84D796F753743A74CB6F0CCFE4C9A53DD69EACA7F95544C80F26270F22AFE44A8762B5F714144C9D1BE5B580526392BF99F2CA0B6009088B083F8AA70FA4B24A6B88C74ACB825A95AEF65BD48D6B2287885592EF45452EB9FE941634E977E617759B739F8AADBBFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC79338EDD5E5BE2F6E667A6171C11EC38DE3D8EDD5E5BE2F6E667C7322FDAA10A809ED217BEE47854B6409F049F4C8E66D37C0DE10B8EF4786D5C824FA8AE352CE8583F2FDFBD47A43394FDC7FE685AB1CFC66272301B6E7B37173CD63BB33DD581A3133D1DC8720D5E840DE9E873B0506A671D8D01BAED2AC5BFFE4316FD1E0182F58E9D8280A2B3DEBC65C7E5731F3ED5E8C7B3A29C866C77D4EC539B860C28196788F0CE4955C64E11AE8331D308F6B8F202A36E541E3321FC390A622A934AE635E81A75E6D7753BF627013DE11E7CAED47FE7F159EDEF8AFE2D30B4A793EC0140AD411E02D075A78724E82DCFEAD4C68287476F070498EF46234F9024BC95700EE6D3252AB47E0A810AA95935CB89831275D0DB9DC12A01630E3628281952B0473C81194FD14ECBC6D1F4CF0C71285CBF3757E0BEDD206189EF79642101AFB4B7E43FBE47C5244A5C0C3ECE32DF43BC68D2F05C73E07FAA1162EE5DDD24C46151AF428C4B07C658EDD9BFCD6AEF6F038FDCF6DEA529CEE7F61133629305278DA97C8AAD785B7D3CC671F5725BCFC602DD8108AEA6E79818D8BBA476DAFAF10978405502D0DE942FDA1DA21B0F7E66021D8006C5A7A46AB1FBB866CFAE2F46941A86A81E3902DDE040BB4A57F35170BC3A2C97D04237D69AC86EDF587122C762116B4BC87C88AC70AEBF38EB5DF00AE14BECA631704E76B0C9593B2F66261D9E021FC97D4688DA7685AE7652805BDD94063E617D12EB6241308AE8273662F264B36875EAA7F044FBC72257B5775F99EA442E3A7D6A65B9134EA51C466DD0F7C6169F60F5987EC9001A4A71F642236DF0855FE63121E41F5C1E62CAC7FBC060C838B2E4366F46D0F245E79BABC11F90A46D8BE0C7416739CABA8F3099B65464E3CF229D756CB0C0BB3953F41BBDA0BB7A42FB68A8B93F327D630A4C5E5503BE053583EAB42E7787B487F3DD42DF47AC587012FDEBDE123987FA48E2EB75172E8E65807128BC2D14AB65C87AD13509A41A84BE675FE75A01F20C51F8CD963078D382D699350033DCE1"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(2372)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\windows\system32\oodag.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-07-27 20:20 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-27 18:20
Pre-Run: 1,691,803,648 bytes free
Post-Run: 1,658,417,152 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
219 --- E O F --- 2009-07-19 15:48