ComboFix 09-11-25.05 - Owner 11/26/2009 11:50.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.511.243 [GMT -6:00]
Running from: c:\documents and settings\Owner\Desktop\456out.com
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\temp\tn3
c:\temp\vtmp2
c:\temp\vtmp2\ktnv33.log
c:\winnt\a3kebook.ini
c:\winnt\akebook.ini
c:\winnt\ANS2000.INI
c:\winnt\IA
c:\winnt\icroso~1
c:\winnt\mainms.vpi
c:\winnt\megavid.cdt
c:\winnt\muotr.so
c:\winnt\system32\abaKlkkj.ini
c:\winnt\system32\hljwugsf.bin
c:\winnt\system32\MabryObj.dll
c:\winnt\system32\PrBKlnnn.ini
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_CLBDRIVER
-------\Legacy_MSSECURITY1.209.4
-------\Legacy_PLUGPLAYRPC
((((((((((((((((((((((((( Files Created from 2009-10-26 to 2009-11-26 )))))))))))))))))))))))))))))))
.
2009-11-24 20:22 . 2009-11-24 20:22 152576 ----a-w- c:\documents and settings\Owner\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-11-24 20:22 . 2009-11-24 20:22 79488 ----a-w- c:\documents and settings\Owner\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-11-24 17:07 . 2009-11-24 17:07 2967799 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-11-24 17:07 . 2009-11-24 17:07 -------- d-----w- c:\documents and settings\Owner\Application Data\Malwarebytes
2009-11-24 17:07 . 2009-04-06 21:32 15504 ----a-w- c:\winnt\system32\drivers\mbam.sys
2009-11-24 17:07 . 2009-04-06 21:32 38496 ----a-w- c:\winnt\system32\drivers\mbamswissarmy.sys
2009-11-24 17:07 . 2009-11-24 17:08 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-11-24 17:07 . 2009-11-24 17:07 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-11-24 16:33 . 2009-11-24 16:33 -------- d-----w- c:\program files\CCleaner
2009-11-16 15:47 . 2009-11-25 14:57 -------- d-----w- c:\documents and settings\Owner\Tracing
2009-11-16 14:13 . 2009-11-16 14:13 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-11-16 14:11 . 2009-11-16 14:14 -------- d-----w- c:\program files\Windows Live
2009-11-15 03:35 . 2009-11-15 03:36 -------- d-----w- c:\program files\WAV to MP3 Encoder
2009-11-12 04:06 . 2009-11-12 04:06 -------- d-----w- c:\program files\Common Files\Windows Live
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-26 18:08 . 2003-08-06 16:40 288 ----a-w- c:\winnt\system32\DVCStateBkp-{00000003-00000000-00000003-00001102-00000004-10061102}.dat
2009-11-26 18:08 . 2003-08-06 16:40 288 ----a-w- c:\winnt\system32\DVCState-{00000003-00000000-00000003-00001102-00000004-10061102}.dat
2009-11-25 20:46 . 2006-09-19 04:08 -------- d-----w- c:\program files\Lx_cats
2009-11-25 15:41 . 2005-11-26 03:14 -------- d-----w- c:\program files\FrameShots
2009-11-25 15:40 . 2005-07-06 20:11 -------- d-----w- c:\program files\PacificPoker
2009-11-25 15:40 . 2004-03-14 20:01 -------- d-----w- c:\program files\Poker World
2009-11-25 15:06 . 2008-12-10 12:11 -------- d-----w- c:\documents and settings\Owner\Application Data\Stamps.com Internet Postage
2009-11-25 15:03 . 2008-12-10 12:07 36 ---ha-w- c:\winnt\system32\f9t.dat
2009-11-24 20:25 . 2007-11-22 16:10 -------- d-----w- c:\program files\Java
2009-11-24 16:44 . 2008-06-08 00:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-11-16 15:35 . 2003-08-12 19:47 245984 ----a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-13 14:47 . 2004-04-02 21:04 -------- d-----w- c:\documents and settings\Owner\Application Data\AdobeUM
2009-10-31 02:14 . 2003-08-27 20:14 -------- d-----w- c:\program files\PokerStars
2009-10-26 22:02 . 2007-03-17 05:43 -------- d-----w- c:\program files\Full Tilt Poker
2009-10-25 19:46 . 2003-08-06 16:38 -------- d-----w- c:\program files\Microsoft Works
2009-10-25 19:45 . 2003-08-06 16:37 -------- d-----w- c:\program files\Microsoft Picture It! 7
2009-10-25 19:42 . 2006-12-19 16:44 -------- d-----w- c:\program files\Avanquest update
2009-10-22 23:25 . 2003-08-25 17:35 -------- d-----w- c:\program files\WS_FTP
2009-10-16 13:47 . 2008-06-07 23:30 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-10-13 15:18 . 2009-10-13 15:18 -------- d-----w- c:\program files\PayPal
2009-10-13 15:18 . 2003-08-06 16:34 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-10-13 15:14 . 2009-10-13 15:14 -------- d-----w- c:\documents and settings\Owner\Application Data\InstallShield
2009-10-11 10:17 . 2008-12-11 12:58 411368 ----a-w- c:\winnt\system32\deploytk.dll
2009-10-07 15:30 . 2003-08-11 23:13 -------- d-----w- c:\program files\Cleaner 5 EZ
2009-10-07 15:26 . 2003-08-06 16:40 -------- d-----w- c:\program files\pressplay
2009-09-11 14:33 . 1980-01-01 05:00 133632 ----a-w- c:\winnt\system32\msv1_0.dll
2009-09-04 20:45 . 1980-01-01 05:00 58880 ----a-w- c:\winnt\system32\msasn1.dll
2008-04-24 15:09 . 2008-04-24 15:09 19 -c--a-w- c:\program files\Answer.txt
2003-02-20 21:21 . 2008-04-24 15:20 81920 -c--a-w- c:\program files\msado26.tlb
2001-07-13 13:39 . 2008-06-14 03:03 61440 -c--a-w- c:\program files\msado21.tlb
2000-07-26 20:36 . 2008-04-24 15:20 524560 -c--a-w- c:\program files\msado15.dll
2000-07-26 18:31 . 2007-06-27 16:59 61440 -c--a-w- c:\program files\msado20.tlb
1998-05-15 04:00 . 2007-06-27 16:59 73184 -c--a-w- c:\program files\DAO2535.TLB
2005-11-08 01:01 . 2005-11-08 01:01 952 -csha-w- c:\winnt\system32\KGyGaAvL.sys
2008-06-08 06:10 . 2008-06-08 03:24 5683232 -csha-w- c:\winnt\system32\drivers\fidbox.dat
2008-06-08 06:10 . 2008-06-08 03:23 878368 -csha-w- c:\winnt\system32\drivers\fidbox2.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Green]
@="{95A27763-F62A-4114-9072-E81D87DE3B68}"
[HKEY_CLASSES_ROOT\CLSID\{95A27763-F62A-4114-9072-E81D87DE3B68}]
2009-04-29 22:19 583312 ----a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Partial]
@="{E300CD91-100F-4E67-9AF3-1384A6124015}"
[HKEY_CLASSES_ROOT\CLSID\{E300CD91-100F-4E67-9AF3-1384A6124015}]
2009-04-29 22:19 583312 ----a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Yellow]
@="{5E529433-B50E-4bef-A63B-16A6B71B071A}"
[HKEY_CLASSES_ROOT\CLSID\{5E529433-B50E-4bef-A63B-16A6B71B071A}]
2009-04-29 22:19 583312 ----a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Qup"="c:\winnt\?icrosoft\d?dplay.exe" [?]
"cdloader"="c:\documents and settings\Owner\Application Data\mjusbsp\cdloader2.exe MAGICJACK" [X]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"ctfmon.exe"="c:\winnt\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GWMDMpi"="c:\winnt\GWMDMpi.exe" [2002-08-06 53248]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-04-29 323584]
"Gateway Ink Monitor"="c:\program files\Gateway Utilities\GWInkMonitor.exe" [2003-06-25 303180]
"Microsoft Works Update Detection"="c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2002-07-17 28672]
"PSDrvCheck"="c:\program files\pinnacle\edition 5\program\PSDrvCheck.exe" [2003-03-10 393728]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2005-11-18 180269]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-01-25 155648]
"LXCICATS"="c:\winnt\System32\spool\DRIVERS\W32X86\3\LXCItime.dll" [2005-09-08 73728]
"lxcimon.exe"="c:\program files\Lexmark 7300 Series\lxcimon.exe" [2005-09-30 200704]
"EzPrint"="c:\program files\Lexmark 7300 Series\ezprint.exe" [2005-08-01 94208]
"DDCActiveMenu"="c:\program files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe" [2002-06-07 86016]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-06-07 1177368]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2004-06-16 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-06-16 81920]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"Carbonite Backup"="c:\program files\Carbonite\Carbonite Backup\CarboniteUI.exe" [2009-04-29 669840]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-02-03 233304]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"ATIModeChange"="Ati2mdxx.exe" - c:\winnt\system32\Ati2mdxx.exe [2002-08-28 28672]
"CTHelper"="CTHELPER.EXE" - c:\winnt\system32\cthelper.exe [2003-01-21 28672]
"Hot Key Kbd 9910 Daemon"="SK9910DM.EXE" - c:\winnt\system32\SK9910DM.EXE [2001-01-03 66048]
"GWMDMMSG"="GWMDMMSG.exe" - c:\winnt\GWMDMMSG.exe [2002-08-06 90112]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"LabelMaker2.0"="c:\program files\Common Files\MySoftware\regdll.dll" [2006-08-03 94208]
"SetDefaultMidi"="MIDIDEF.EXE" - c:\winnt\mididef.exe [2002-12-03 49152]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - c:\program files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-10-23 217194]
Adobe Gamma Loader.exe.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2004-3-9 110592]
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2004-3-9 110592]
Microsoft Broadband Networking.lnk - c:\winnt\Installer\{8CC15633-2327-43F4-BA85-B83FDB4B59BE}\_18be6784.exe [2004-7-29 25214]
Wireless Network Monitor.lnk - c:\program files\Linksys\WUSB100\WUSB100.exe [2007-10-30 5677056]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\winnt\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\clbdriver.sys]
@=""
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Broadband Networking\\MSBNUtil.exe"=
"c:\\Program Files\\Microsoft Broadband Networking\\MSBNTray.exe"=
"c:\\Program Files\\Microsoft Broadband Networking\\MSBNCfg.exe"=
"c:\\Program Files\\Microsoft Broadband Networking\\MSBNUpdate.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Pinnacle\\Edition 5\\Program\\RM.exe"=
"c:\\Program Files\\WS_FTP\\WS_FTP95.exe"=
"c:\\NetObjects Fusion 7\\Fusion.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\kav\\kis\\setup.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Documents and Settings\\Owner\\Application Data\\mjusbsp\\magicJack.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"2090:TCP"= 2090:TCP:2090
"2091:TCP"= 2091:TCP:2091
"2092:TCP"= 2092:TCP:2092
"2093:TCP"= 2093:TCP:2093
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\winnt\system32\drivers\avgldx86.sys [6/7/2008 5:31 PM 96520]
R1 hlp;FAST HLP Driver;c:\winnt\system32\drivers\Hlp.sys [8/11/2003 4:16 PM 94964]
R1 SSHDRV5A;SSHDRV5A;c:\winnt\system32\drivers\SSHDRV5A.sys [8/11/2003 4:38 PM 35840]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [6/7/2008 5:30 PM 902424]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [6/7/2008 5:30 PM 282904]
R2 AvgTdiX;AVG8 Network Redirector;c:\winnt\system32\drivers\avgtdix.sys [6/7/2008 5:31 PM 75272]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [1/10/2007 9:06 PM 24652]
R3 lxci_device;lxci_device;c:\winnt\system32\lxcicoms.exe -service --> c:\winnt\system32\lxcicoms.exe -service [?]
R3 rt2870;Linksys 802.11n USB Wireless LAN Card Driver;c:\winnt\system32\drivers\rt2870.sys [7/28/2007 1:50 PM 517632]
S1 sysaudioo;sysaudioo;c:\winnt\system32\drivers\sysaudioo.sys --> c:\winnt\system32\drivers\sysaudioo.sys [?]
.
Contents of the 'Scheduled Tasks' folder
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
DPF: DirectAnimation Java Classes - file://c:\winnt\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\winnt\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\mz2dz5o4.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - plugin: c:\documents and settings\Owner\Local Settings\Application Data\Yahoo!\BrowserPlus\2.4.21\Plugins\npybrowserplus_2.4.21.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\winnt\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
- - - - ORPHANS REMOVED - - - -
BHO-{19AA63C3-07B3-4D65-AF0D-2F276DADD457} - (no file)
BHO-{6BE8ABDD-7057-4639-B367-761A40D535EB} - c:\winnt\system32\jkklKaba.dll
BHO-{70206FB3-30B6-4D9C-9F4C-370F491C9C92} - c:\winnt\system32\nnnlKBrP.dll
BHO-{DC41EA1E-21FE-0627-FB3B-7DA2979E4390} - c:\winnt\system32\wqzxaed.dll
WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file)
HKCU-Run-Zinio DLM - c:\program files\Zinio\ZinioDeliveryManager.exe
HKCU-Run-MoneyAgent - c:\program files\Microsoft Money\System\mnyexpr.exe
HKCU-Run-Ltho - c:\docume~1\Owner\APPLIC~1\MCROSO~1\winword.exe
HKCU-Run-YSearchProtection - c:\program files\Yahoo!\Search Protection\SearchProtection.exe
HKLM-Run-Keyboard Preload Check - c:\oemdrvrs\KEYB\Preload.exe
HKLM-Run-mavenapp://www.brightcove.com - c:\program files\Brightcove\maven/bin/%AppExeName%.exe
HKLM-Run-YSearchProtection - c:\program files\Yahoo!\Search Protection\SearchProtection.exe
HKLM-Run-NexusServer - c:\program files\Common Files\Canopus Shared\ProCoder 2\Kernel\PNXSERVR.exe
HKU-Default-Run-ALUAlert - c:\program files\Symantec\LiveUpdate\ALUNotify.exe
AddRemove-Creative Driver - c:\winnt\System32\ctdrvins
AddRemove-GTW V.92 Voicemodem - c:\winnt\GWMDMU.exe verbose
AddRemove-HijackThis - c:\documents and settings\Owner\Local Settings\Temp\HijackThis.exe
AddRemove-RealJukebox 1.0 - c:\program files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
AddRemove-RealPlayer 6.0 - c:\program files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
AddRemove-RNCompiler 6.0 - c:\program files\Adobe\Premiere 6.0\Plug-ins\RNCompiler\rnuninst.exe RealNetworks|RNCompiler|6.0
AddRemove-Stamps.com - c:\documents and settings\All Users\Application Data\{65F127C6-C287-4690-AF77-F9A8729B2EAD}\stamps.exe REMOVE=TRUE MODIFY=FALSE
AddRemove-{98E8A2EF-4EAE-43B8-A172-74842B764777} - c:\program files\InstallShield Installation Information\{98E8A2EF-4EAE-43B8-A172-74842B764777}\setup.exe REMOVEALL
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-11-26 12:11
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXCICATS = rundll32 c:\winnt\System32\spool\DRIVERS\W32X86\3\LXCItime.dll,_RunDLLEntry@16?????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{BEB3C0C7-B648-4257-96D9-B5D024816E27}\Version*Version]
"Version"=hex:97,a4,fd,1a,9d,b1,b7,14,3a,31,82,6e,b1,49,7e,bb,2c,f0,5b,6c,a1,
ed,65,ac,f5,35,0c,33,6b,a5,7b,50,ac,2f,88,ca,09,d2,d7,2e,b3,9c,cf,be,bf,89,\
[HKEY_LOCAL_MACHINE\software\Minnetonka Audio Software\SurCode Dolby Digital Premiere\Version*Version]
"Version"=hex:97,a4,fd,1a,9d,b1,b7,14,3a,31,82,6e,b1,49,7e,bb,2c,f0,5b,6c,a1,
ed,65,ac,f5,35,0c,33,6b,a5,7b,50,ac,2f,88,ca,09,d2,d7,2e,b3,9c,cf,be,bf,89,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(1716)
c:\program files\Gateway Utilities\inkpeek.dll
c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll
c:\winnt\system32\ctagent.dll
c:\winnt\system32\ieframe.dll
c:\winnt\system32\webcheck.dll
c:\winnt\system32\WPDShServiceObj.dll
c:\winnt\system32\PortableDeviceTypes.dll
c:\winnt\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\winnt\System32\Ati2evxx.exe
c:\program files\Carbonite\Carbonite Backup\carboniteservice.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
c:\program files\Microsoft Broadband Networking\MSBNTray.exe
c:\winnt\system32\lxcicoms.exe
c:\program files\Windows Live\Contacts\wlcomm.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\program files\AVG\AVG8\avgrsx.exe
.
**************************************************************************
.
Completion time: 2009-11-26 12:31 - machine was rebooted
ComboFix-quarantined-files.txt 2009-11-26 18:30
Pre-Run: 19,138,662,400 bytes free
Post-Run: 19,841,019,904 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINNT
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINNT="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
- - End Of File - - BC06F615C53416A1DD52F8E08DA74F11
Post Edited (PanicAttack) : 27-11-2009 17:21:48 GMT