ComboFix 09-10-14.04 - Shy 10/14/2009 22:16.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1255.972.1033.18.3070.1620 [GMT -5:00]
Running from: c:\documents and settings\Shy\My Documents\Downloads\ComboFix.exe
Command switches used :: c:\documents and settings\Shy\My Documents\Downloads\WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
FW: CyberArmor Client *enabled* {E503B27E-6391-4e17-B2CA-F910AF011E23}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Downloaded Program Files\popcaploader.dll
c:\windows\Downloaded Program Files\popcaploader.inf
c:\windows\Installer\313e32e.msi
c:\windows\Installer\739e906.msi
c:\windows\Installer\739e907.msp
c:\windows\Installer\739e908.msp
c:\windows\Installer\739e909.msp
c:\windows\Installer\739e90a.msp
c:\windows\Installer\739e90b.msp
c:\windows\Installer\739e90c.msp
c:\windows\Installer\739e90d.msp
c:\windows\Installer\739e90e.msp
c:\windows\Installer\739e90f.msp
c:\windows\Installer\81fb4a9.msp
c:\windows\Installer\d460445.msp
c:\windows\jestertb.dll
.
((((((((((((((((((((((((( Files Created from 2009-09-15 to 2009-10-15 )))))))))))))))))))))))))))))))
.
2009-10-14 04:17 . 2009-10-14 04:17 -------- d-----w- c:\documents and settings\Shy\Application Data\Malwarebytes
2009-10-14 04:17 . 2009-09-10 19:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-14 04:17 . 2009-10-14 04:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-10-14 04:17 . 2009-09-10 19:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-13 16:35 . 2009-10-13 16:35 -------- d-----w- c:\program files\MSN Toolbar
2009-10-13 16:33 . 2009-10-13 16:35 -------- d-----w- c:\program files\MSN Toolbar Installer
2009-10-09 11:41 . 2009-10-09 11:41 -------- d-----w- c:\program files\Microsoft Office Outlook Connector
2009-09-28 21:22 . 2009-09-28 21:22 -------- d-----w- c:\program files\Spikko
2009-09-28 21:22 . 2009-09-28 21:22 -------- d-----w- c:\documents and settings\Shy\Local Settings\Application Data\Spikko
2009-09-28 21:22 . 2009-09-28 21:22 -------- d-----w- c:\documents and settings\All Users\Application Data\Spikko
2009-09-25 14:55 . 2009-09-25 14:55 -------- d-----w- c:\program files\Common Files\xing shared
2009-09-25 14:55 . 2009-09-25 14:55 -------- d-----w- c:\program files\realaudio
2009-09-25 13:26 . 2001-08-17 18:57 16128 -c--a-w- c:\windows\system32\dllcache\modemcsa.sys
2009-09-25 13:26 . 2001-08-17 18:57 16128 ----a-w- c:\windows\system32\drivers\MODEMCSA.sys
2009-09-25 13:25 . 2009-09-25 13:25 -------- d-----w- c:\program files\CONEXANT
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-15 01:52 . 2009-02-21 15:34 -------- d-----w- c:\program files\Symantec AntiVirus
2009-10-14 16:25 . 2008-05-26 14:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2009-10-14 11:19 . 2008-01-07 05:20 -------- d-----w- c:\program files\LogMeIn
2009-10-14 03:30 . 2008-04-14 14:22 -------- d-----w- c:\program files\MultiBank
2009-10-13 21:38 . 2008-03-16 15:00 -------- d-----w- c:\documents and settings\Shy\Application Data\Skype
2009-10-13 16:33 . 2009-05-10 19:08 -------- d-----w- c:\program files\Nick Arcade
2009-10-13 05:08 . 2008-03-16 15:01 -------- d-----w- c:\documents and settings\Shy\Application Data\skypePM
2009-10-12 06:01 . 2007-12-31 19:46 -------- d--h--w- c:\documents and settings\Shy\Application Data\GTek
2009-10-12 06:01 . 2007-12-31 19:45 -------- d-----w- c:\documents and settings\All Users\Application Data\Gtek
2009-10-02 12:00 . 2008-01-07 05:20 83288 ----a-w- c:\windows\system32\LMIRfsClientNP.dll
2009-10-02 12:00 . 2008-01-07 05:20 28984 ----a-w- c:\windows\system32\LMIport.dll
2009-10-02 12:00 . 2008-01-07 05:20 87352 ----a-w- c:\windows\system32\LMIinit.dll
2009-09-28 21:22 . 2009-05-22 11:29 -------- d-----w- c:\program files\SpeedFan
2009-09-26 00:16 . 2009-05-10 19:09 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-09-25 14:57 . 2009-05-15 02:36 -------- d-----w- c:\program files\American Airlines DealFinder
2009-09-25 14:55 . 2009-02-05 16:25 -------- d-----w- c:\program files\Common Files\Real
2009-09-25 13:06 . 2007-12-31 19:52 -------- d-----w- c:\program files\Google
2009-09-22 20:56 . 2008-02-15 05:04 43520 ----a-w- c:\windows\system32\CmdLineExt03.dll
2009-09-11 23:16 . 2007-12-31 19:49 -------- d-----w- c:\program files\Microsoft Silverlight
2009-09-11 14:18 . 2004-08-04 12:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-10 16:21 . 2007-09-12 17:19 8520 ----a-w- c:\windows\system32\ractrlkeyhook.dll
2009-09-08 13:41 . 2007-11-16 02:46 11552 ----a-w- c:\windows\system32\lmimirr2.dll
2009-09-08 13:41 . 2007-11-16 02:46 25248 ----a-w- c:\windows\system32\lmimirr.dll
2009-09-04 21:03 . 2004-08-04 12:00 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-29 17:45 . 2009-08-29 17:45 -------- d-----w- c:\program files\Garmin
2009-08-29 17:45 . 2009-08-29 17:45 -------- d-----w- c:\program files\DIFX
2009-08-29 08:08 . 2004-08-04 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2009-08-26 08:00 . 2004-08-04 12:00 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-16 22:55 . 2009-08-16 18:27 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton
2009-08-16 18:27 . 2007-12-31 18:11 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2009-08-16 18:27 . 2009-08-16 18:27 -------- d-----w- c:\documents and settings\All Users\Application Data\NortonInstaller
2009-08-05 09:01 . 2004-08-04 12:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-05 00:52 . 2009-08-05 00:52 1193832 ----a-w- c:\windows\system32\FM20.DLL
2009-08-04 15:13 . 2004-08-04 12:00 2145280 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-08-04 14:20 . 2004-08-03 22:59 2023936 ----a-w- c:\windows\system32\ntkrnlpa.exe
2009-07-26 21:44 . 2009-07-26 21:44 48448 ----a-w- c:\windows\system32\sirenacm.dll
2009-07-25 10:23 . 2008-11-27 05:18 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-07-17 19:01 . 2004-08-04 12:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-17 16:22 . 2004-08-04 12:00 1435648 ----a-w- c:\windows\system32\query.dll
2009-05-01 21:02 . 2009-05-01 21:02 1044480 -c--a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2007-08-09 21:08 . 2008-01-23 16:49 8784 -c--a-w- c:\program files\mozilla firefox\plugins\ractrlkeyhook.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 -c--a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2007-08-09 21:10 . 2008-01-23 16:49 245408 -c--a-w- c:\program files\mozilla firefox\plugins\unicows.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-18 68856]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-07-26 3883856]
"NVIDIA nTune"="c:\nvidia\nTune\nTuneCmd.exe" [2007-09-05 81920]
"Creative WebCam Tray"="c:\program files\Creative\Shared Files\CamTray.exe" [2005-10-28 299008]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"eFax 4.4"="c:\program files\eFax Messenger 4.4\J2GDllCmd.exe" [2008-10-07 95744]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"Google Update"="c:\documents and settings\Shy\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-05-02 133104]
"SpikkoPhoneApp"="c:\program files\Spikko\SpikkoPhone.exe" [2009-05-19 1699840]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-04-17 142104]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-04-17 162584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-04-17 138008]
"CgaHelper"="c:\progra~1\CYBERG~1\cgahelp.exe" [2005-04-14 90174]
"CgaViewer"="c:\progra~1\CYBERG~1\cgav.exe" [2005-04-14 81976]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2004-02-12 49152]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 241664]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2007-08-03 63048]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-28 13684736]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-08-13 122939]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2004-01-07 110592]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-07-20 52896]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2006-08-03 124656]
"parentalcontrol"="c:\program files\parentalcontrol\parentalcontrol.exe" [2006-08-31 36544]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-03-28 86016]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-09-25 198160]
"MSN Toolbar"="c:\program files\MSN Toolbar\Platform\4.0.0314.0\mswinext.exe" [2009-09-23 240976]
"Malwarebytes Anti-Malware (reboot)"="c:\utils\Anti-Malware\mbam.exe" [2009-09-10 1312080]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2007-04-26 16132608]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2009-03-28 1657376]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\Shy\Start Menu\Programs\Startup\
Change Proxy Settings.lnk - c:\program files\Superior View\Change Proxy Settings\Change Proxy Settings.exe [2004-5-18 114688]
eFax 4.4.lnk - c:\program files\eFax Messenger 4.4\J2GTray.exe [2008-10-7 656896]
MultiBank.lnk - c:\program files\MultiBank\BMidasM.exe [2008-4-14 217653]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Cisco Systems VPN Client.lnk - c:\program files\Cisco Systems\VPN Client\vpngui.exe [2007-12-31 1425424]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-12-31 50688]
HP Digital Imaging Monitor.lnk - c:\program files\Hp\Digital Imaging\bin\hpqtra08.exe [2004-5-29 241664]
HP Image Zone Fast Start.lnk - c:\program files\Hp\Digital Imaging\bin\hpqthb08.exe [2004-5-29 53248]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2009-10-02 12:00 87352 ----a-w- c:\windows\system32\LMIinit.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ \0
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Auth orizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\RealAudio\\realplay.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Documents and Settings\\Shy\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\Shy\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\Spikko\\SpikkoPhone.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R2 CGAgent;CyberGatekeeper Agent;c:\progra~1\CYBERG~1\cgasvc.exe [12/31/2007 1:55 PM 73788]
R2 iPCAgent;iPCAgent;c:\program files\iPass\iPassConnect 3\iPCAgent.exe [12/31/2007 1:56 PM 90112]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [8/3/2007 6:09 PM 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [1/7/2008 12:20 AM 47640]
R2 MDC80211;iPass Protocol (IEEE 802.1x) v2.3.1.9;c:\windows\system32\drivers\mdc80211.sys [12/31/2007 1:56 PM 15793]
R2 ndserv;ndserv;c:\program files\netDeploy\launcher\ndserv.exe [12/31/2007 8:56 PM 859648]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\eengine\EraserUtilRebootDrv.sys [9/3/2009 12:33 AM 102448]
R3 P0630VID;Creative WebCam Live!;c:\windows\system32\drivers\P0630Vid.sys [1/21/2008 1:47 PM 67968]
S2 wlidsvc;Windows Live ID Sign-in Assistant;c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [8/18/2009 11:29 AM 1529728]
S3 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [8/3/2006 10:48 AM 115952]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]
S4 nenum13E;nenum13E; [x]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-10-08 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
2009-10-14 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-12-31 04:22]
2009-10-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1644491937-1482476501-725345543-1003Core.job
- c:\documents and settings\Shy\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-06-05 02:39]
2009-10-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1644491937-1482476501-725345543-1003UA.job
- c:\documents and settings\Shy\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-06-05 02:39]
2009-10-13 c:\windows\Tasks\SmartDefrag.job
- c:\utils\SmartDefrag\IObit SmartDefrag.exe [2009-09-25 14:22]
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultUrl = hxxp://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZJxdm028YYUS&fl=0&ptb=MabqOIBHRTSQCN6uqleZzw&ind=20080309 17&url=http://www.ask.com/web&q={searchTerms}&l=zj&o=sb
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} - hxxps://secure.gopetslive.com/dev/GoPetsWeb.cab
FF - ProfilePath - c:\documents and settings\Shy\Application Data\Mozilla\Firefox\Profiles\05c8zd1g.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://en-US.start2.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-US

fficial
FF - prefs.js: keyword.URL - hxxp://results.mindspark.com/dft_redir.jhtml?id=ZJxdm268TXUS&ptnrS=ZJxdm268TXUS&fl=0&ptb=h5r.1_BMsw5lEby MemvxPA&st=kwd&searchfor=
FF - component: c:\program files\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\components\SEPsearchhelperff. dll
FF - component: c:\program files\realaudio\browserrecord\firefox\ext\components\nprpffbrowserrecordext .dll
FF - plugin: c:\documents and settings\Shy\Application Data\Mozilla\Firefox\Profiles\05c8zd1g.default\extensions\moveplayer@movene tworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp071101000055.dll
FF - plugin: c:\documents and settings\Shy\Application Data\Mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\Shy\Local Settings\Application Data\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPCentraUpdater.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npRACtrl.dll
FF - plugin: c:\program files\MSN Toolbar\Platform\4.0.0314.0\npwinext.dll
FF - plugin: c:\program files\Picasa\npPicasa2.dll
FF - plugin: c:\program files\Picasa\npPicasa3.dll
FF - plugin: c:\program files\realaudio\Netscape6\nppl3260.dll
FF - plugin: c:\program files\realaudio\Netscape6\nprjplug.dll
FF - plugin: c:\program files\realaudio\Netscape6\nprpjplug.dll
FF - plugin: c:\program files\Virtools\3D Life Player\npvirtools.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
pref(dom.disable_open_during_load, false);.
- - - - ORPHANS REMOVED - - - -
AddRemove-?? ?? ??? ??? º??? - ??º???? - c:\cetlb\SOD_C\Uninst\Uncet.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-10-14 22:23
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\nenum13E]
"ImagePath"=""
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\DeterministicNetworks\DNE\Parameters]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00, 79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,79,00,73,00, \
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1024)
c:\windows\system32\LMIinit.dll
c:\windows\system32\LMIRfsClientNP.dll
.
Completion time: 2009-10-15 22:26
ComboFix-quarantined-files.txt 2009-10-15 03:25
Pre-Run: 83,107,065,856 bytes free
Post-Run: 83,611,971,584 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(3)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(3)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptOut
267 --- E O F --- 2009-10-14 11:47