ComboFix 08-12-13.03 - David 2008-12-13 18:55:55.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.323 [GMT -5:00] Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe * Created a new restore point * Resident AV is active . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\IE4 Error Log.txt c:\windows\system32\~.exe c:\windows\system32\umezimiv.ini c:\windows\system32\yehifuni.dll . ((((((((((((((((((((((((( Files Created from 2008-11-14 to 2008-12-14 ))))))))))))))))))))))))))))))) . 2008-12-13 18:41 . 2008-12-13 18:40 410,984 --a------ c:\windows\system32\deploytk.dll 2008-12-13 18:20 . 2008-12-13 18:20 d-------- C:\VundoFix Backups 2008-12-11 17:42 . 2008-12-13 08:02 d-------- c:\documents and settings\David\Application Data\skypePM 2008-12-11 17:42 . 2008-12-11 17:42 56 --ah----- c:\windows\system32\ezsidmv.dat 2008-12-11 17:39 . 2008-12-11 17:39 d-------- c:\documents and settings\David\Application Data\Leadertech 2008-12-11 17:39 . 2008-02-05 21:17 2,570,520 -ra------ c:\windows\system32\drivers\LV302V32.SYS 2008-12-11 17:38 . 2008-02-05 21:21 490,008 -ra------ c:\windows\system32\LVUI2.dll 2008-12-11 17:38 . 2008-02-05 21:21 465,432 -ra------ c:\windows\system32\LVUI2RC.dll 2008-12-11 17:38 . 2008-02-05 21:18 416,280 -ra------ c:\windows\system32\lvcodec2.dll 2008-12-11 17:36 . 2008-02-05 21:20 628,760 -ra------ c:\windows\system32\drivers\lvrs.sys 2008-12-11 17:36 . 2008-02-05 21:18 195,096 -ra------ c:\windows\system32\lvci11701196.dll 2008-12-11 17:36 . 2008-02-05 20:37 66,482 -ra------ c:\windows\system32\lvcoinst.ini 2008-12-11 17:36 . 2008-04-13 14:45 60,032 --a------ c:\windows\system32\drivers\USBAUDIO.sys 2008-12-11 17:36 . 2008-04-13 14:45 60,032 --a------ c:\windows\system32\dllcache\usbaudio.sys 2008-12-11 17:36 . 2008-02-05 21:21 41,752 -ra------ c:\windows\system32\drivers\LVUSBSta.sys 2008-12-11 17:36 . 2008-02-05 20:40 25,056 -ra------ c:\windows\system32\Repository.reg 2008-12-11 17:36 . 2008-02-05 21:17 13,848 -ra------ c:\windows\system32\drivers\lv302af.sys 2008-12-11 17:31 . 2008-12-11 17:31 d-------- c:\program files\Logitech 2008-12-11 17:31 . 2008-12-11 17:39 d-------- c:\program files\Common Files\LogiShrd 2008-12-11 17:31 . 2008-12-11 17:31 d-------- c:\documents and settings\All Users\Application Data\Logitech 2008-12-11 17:31 . 2008-12-11 17:31 d-------- c:\documents and settings\All Users\Application Data\Logishrd 2008-12-11 17:27 . 2008-12-13 18:39 d-------- c:\documents and settings\David\Application Data\Skype 2008-12-11 17:24 . 2008-12-11 17:24 d-------- c:\program files\Skype 2008-12-11 17:24 . 2008-12-11 17:24 d-------- c:\program files\Common Files\Skype 2008-12-11 17:24 . 2008-12-11 17:24 d-------- c:\documents and settings\All Users\Application Data\Skype 2008-12-11 13:14 . 2008-12-11 13:14 d-------- c:\program files\SUPERAntiSpyware 2008-12-11 13:14 . 2008-12-11 13:14 d-------- c:\documents and settings\David\Application Data\SUPERAntiSpyware.com 2008-12-11 13:14 . 2008-12-11 13:14 d-------- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com 2008-12-10 14:41 . 2008-12-10 14:41 d-------- c:\program files\Trend Micro 2008-12-10 11:24 . 2008-12-10 11:24 d-------- c:\documents and settings\David\Application Data\McAfee 2008-12-03 12:33 . 2008-12-03 12:33 d-------- c:\temp\google 2008-12-03 12:33 . 2008-12-03 12:33 d-------- C:\temp . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-12-13 23:40 --------- d-----w c:\program files\Java 2008-12-13 23:35 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP 2008-12-13 21:24 2,243 ----a-w c:\program files\eTikrUpdate.original 2008-12-13 02:35 --------- d-----w c:\documents and settings\All Users\Application Data\Google Updater 2008-12-12 18:13 --------- d-----w c:\program files\Dl_cats 2008-12-11 18:13 --------- d-----w c:\program files\Common Files\Wise Installation Wizard 2008-12-10 19:44 --------- d-----w c:\program files\BAE 2008-12-10 16:36 --------- d-----w c:\documents and settings\All Users\Application Data\McAfee 2008-12-09 18:45 --------- d-----w c:\program files\eTikr AddIn 2008-11-13 21:21 --------- d-----w c:\documents and settings\All Users\Application Data\Kodak 2008-11-01 18:11 --------- d-----w c:\documents and settings\All Users\Application Data\MGS 2008-11-01 18:09 --------- d-----w c:\documents and settings\All Users\Application Data\Microgaming 2008-10-26 16:36 --------- d--h--w c:\program files\InstallShield Installation Information 2008-10-26 15:36 --------- d-----w c:\program files\Slots Plus Casino 2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys 2008-10-23 01:40 --------- d-----w c:\documents and settings\David\Application Data\VTExtra 2008-10-23 01:36 --------- d-----w c:\documents and settings\David\Application Data\InstallShield 2008-10-19 11:25 --------- d-----w c:\documents and settings\David\Application Data\ID Vault 2008-10-19 11:19 --------- d-----w c:\program files\ID Vault 2008-10-17 12:00 --------- d-----w c:\documents and settings\David\Application Data\Intuit 2008-10-17 11:50 --------- d-----w c:\program files\Common Files\AnswerWorks 4.0 2008-10-17 11:47 --------- d-----w c:\documents and settings\All Users\Application Data\Intuit 2008-10-17 11:45 --------- d-----w c:\program files\TurboTax 2007-12-31 20:14 3,024 ----a-w c:\program files\Setup.log 2007-12-31 20:14 170,207 ----a-w c:\program files\X_eTikrUpdate.exe 2007-12-31 20:14 170,207 ----a-w c:\program files\eTikrUpdate.exe 2006-12-12 08:19 156,672 ----a-w c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll 2008-10-13 23:55 228,640 ----a-w c:\program files\mozilla firefox\components\IdVault.XPCOM.dll 2007-07-30 21:47 88 --sh--r c:\windows\system32\82A74C8DE9.sys 2006-08-12 10:45 56 --sh--r c:\windows\system32\E98D4CA782.sys 2007-07-30 21:47 4,184 --sha-w c:\windows\system32\KGyGaAvL.sys . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Blue] @="{E300CD91-100F-4E67-9AF3-1384A6124015}" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Partial] @="{E300CD91-100F-4E67-9AF3-1384A6124015}" [HKEY_CLASSES_ROOT\CLSID\{E300CD91-100F-4E67-9AF3-1384A6124015}] 2008-06-13 22:19 527296 -ra------ c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Green] @="{95A27763-F62A-4114-9072-E81D87DE3B68}" [HKEY_CLASSES_ROOT\CLSID\{95A27763-F62A-4114-9072-E81D87DE3B68}] 2008-06-13 22:19 527296 -ra------ c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Blue] @="{E300CD91-100F-4E67-9AF3-1384A6124015}" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Partial] @="{E300CD91-100F-4E67-9AF3-1384A6124015}" [HKEY_CLASSES_ROOT\CLSID\{E300CD91-100F-4E67-9AF3-1384A6124015}] 2008-06-13 22:19 527296 -ra------ c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Red] @="{01CCCC8C-1D50-4b13-B96D-4B922DD3128B}" [HKEY_CLASSES_ROOT\CLSID\{01CCCC8C-1D50-4b13-B96D-4B922DD3128B}] 2008-06-13 22:19 527296 -ra------ c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Yellow] @="{5E529433-B50E-4bef-A63B-16A6B71B071A}" [HKEY_CLASSES_ROOT\CLSID\{5E529433-B50E-4bef-A63B-16A6B71B071A}] 2008-06-13 22:19 527296 -ra------ c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360] "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232] "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-12-04 1809648] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-04-03 68856] "RegistryMechanic"="c:\program files\Registry Mechanic\RegMech.exe" [2008-07-08 2828184] "DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2007-11-15 202544] "DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784] "Creative Detector"="c:\program files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-02 102400] "Aim6"="c:\program files\AIM6\aim6.exe" [2006-11-07 50736] "AdobeUpdater"="c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2008-11-11 2356088] "Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-11-18 21633320] "SetDefaultMIDI"="MIDIDef.exe" [2004-12-22 c:\windows\MIDIDEF.EXE] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "DLCGCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLCGtime.dll" [2005-09-08 73728] "VoiceCenter"="c:\program files\Creative\VoiceCenter\AndreaVC.exe" [2005-09-19 1159168] "UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112] "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-10-03 185896] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-13 136600] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-01-10 385024] "MSKDetectorExe"="c:\program files\McAfee\SpamKiller\MSKDetct.exe" [2005-07-12 1117184] "mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-01-15 267048] "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920] "ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856] "Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2006-12-14 241152] "ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584] "dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384] "DMXLauncher"="c:\program files\Sonic\Product\Media Experience\DMXLauncher.exe" [2007-04-02 113400] "DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2006-09-21 127036] "ddoctorv2"="c:\program files\Comcast\Desktop Doctor\bin\sprtcmd.exe" [2008-04-24 202560] "CTSysVol"="c:\program files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe" [2005-09-15 57344] "Carbonite Backup"="c:\program files\Carbonite\Carbonite Backup\CarboniteUI.exe" [2008-06-13 600000] "ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-05 344064] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792] "Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 63712] "LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2008-02-13 564496] "LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-02-13 2196240] "MSConfig"="c:\windows\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2008-04-13 169984] "SigmatelSysTrayApp"="stsystra.exe" [2005-03-22 c:\windows\stsystra.exe] "MBMon"="CTMBHA.DLL" [2005-05-19 c:\windows\system32\CTMBHA.DLL] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "RealUpgradeHelper"="c:\program files\Common Files\Real\Update_OB\upgrdhlp.exe" [2008-10-03 136768] c:\documents and settings\David\Start Menu\Programs\Startup\ eTikr - Auto Update.lnk - c:\program files\eTikrUpdate.exe [2007-12-31 170207] Logitech . Product Registration.lnk - c:\program files\Logitech\QuickCam\eReg.exe [2008-02-13 493832] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-05-27 24576] ID Vault.lnk - c:\program files\ID Vault\IDVault.exe [2008-10-13 795936] Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588] QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2008-03-18 972064] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2008-12-03 14:56 352256 c:\program files\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusDisableNotify"=dword:00000001 "UpdatesDisableNotify"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"= "c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "c:\\Program Files\\America Online 9.0\\waol.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"= "c:\\Program Files\\Adobe\\Photoshop Elements 5.0\\AdobePhotoshopElementsMediaServer.exe"= "c:\\Program Files\\Intuit\\QuickBooks 2007\\QBDBMgrN.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"= "c:\\WINDOWS\\system32\\verclsid.exe"= "c:\\WINDOWS\\stsystra.exe"= "c:\\Program Files\\Adobe\\Photoshop Album Starter Edition\\3.2\\Apps\\apdproxy.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= R1 SASDIFSV;SASDIFSV;\??\c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2008-12-04 8944] R1 SASKUTIL;SASKUTIL;\??\c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2008-12-04 55024] R2 Viewpoint Manager Service;Viewpoint Manager Service;"c:\program files\Viewpoint\Common\ViewpointService.exe" [2007-03-24 24652] R3 mtsftkey;mtsftkey;c:\windows\system32\drivers\mtsftkey.sys [2007-11-18 60032] R3 SASENUM;SASENUM;\??\c:\program files\SUPERAntiSpyware\SASENUM.SYS [2008-12-04 7408] R3 SMCSTUB;SMCSTUB;c:\windows\system32\drivers\smcstub.sys [2007-11-18 55680] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}] \Shell\AutoRun\command - E:\setup.exe . Contents of the 'Scheduled Tasks' folder 2008-12-13 c:\windows\Tasks\AdwareAlert Scheduled Scan.job - c:\program files\AdwareAlert\AdwareAlert.exe [] 2008-12-13 c:\windows\Tasks\AdwareAlert Scheduled Scan.job - c:\program files\AdwareAlert [2008-02-06 00:32] 2008-12-10 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 13:57] 2008-11-15 c:\windows\Tasks\McDefragTask.job - c:\program files\mcafee\mqc\QcConsol.exe [2007-12-04 12:32] 2008-12-01 c:\windows\Tasks\McQcTask.job - c:\program files\mcafee\mqc\QcConsol.exe [2007-12-04 12:32] . - - - - ORPHANS REMOVED - - - - BHO-{67c163d8-6f80-4fae-885f-bfd72db08783} - c:\windows\system32\yefeluki.dll WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file) MSConfigStartUp-CPMeb26379f - c:\windows\system32\novunimu.dll MSConfigStartUp-dopibidopo - c:\windows\system32\tusubiku.dll MSConfigStartUp-e8150403 - c:\windows\system32\womimago.dll . ------- Supplementary Scan ------- . uStart Page = hxxp://www.comcast.net/home.html mStart Page = hxxp://www.comcast.net/ mWindow Title = Windows Internet Explorer provided by Comcast FF - ProfilePath - c:\documents and settings\David\Application Data\Mozilla\Firefox\Profiles\ghoptwjn.default\ FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q= FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://www.comcast.net/ FF - plugin: c:\program files\Google\Google Updater\2.4.1368.5602\npCIDetect13.dll FF - plugin: c:\program files\iTunes\Mozilla Plugins\npitunes.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll FF - plugin: c:\program files\Picasa2\npPicasa2.dll FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-12-13 19:02:35 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... HKLM\Software\Microsoft\Windows\CurrentVersion\Run DLCGCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLCGtime.dll,_RunDLLEntry@16??????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????? scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(684) c:\program files\SUPERAntiSpyware\SASWINLO.dll - - - - - - - > 'explorer.exe'(5608) c:\windows\TEMP\logishrd\LVPrcInj01.dll . ------------------------ Other Running Processes ------------------------ . c:\windows\system32\ati2evxx.exe c:\program files\Lavasoft\Ad-Aware 2007\aawservice.exe c:\program files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe c:\progra~1\COMMON~1\AOL\ACS\AOLacsd.exe c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\program files\Carbonite\Carbonite Backup\CarboniteService.exe c:\windows\system32\CTSVCCDA.EXE c:\windows\ehome\ehrecvr.exe c:\windows\ehome\ehSched.exe c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe c:\program files\Java\jre6\bin\jqs.exe c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe c:\progra~1\McAfee\MSC\mcmscsvc.exe c:\program files\Common Files\McAfee\MNA\McNASvc.exe c:\progra~1\COMMON~1\McAfee\McProxy\McProxy.exe c:\progra~1\McAfee\VIRUSS~1\Mcshield.exe c:\program files\McAfee\MPF\MpfSrv.exe c:\progra~1\McAfee.com\Agent\mcagent.exe c:\windows\ehome\mcrdsvc.exe c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe c:\windows\system32\dllhost.exe c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe c:\progra~1\McAfee\VIRUSS~1\mcsysmon.exe c:\windows\system32\rundll32.exe c:\docume~1\David\LOCALS~1\Temp\clclean.0001 c:\windows\ehome\ehmsas.exe c:\program files\Google\Google Desktop Search\GoogleDesktopIndex.exe c:\program files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe c:\program files\iPod\bin\iPodService.exe c:\program files\Common Files\LogiShrd\LQCVFX\COCIManager.exe c:\program files\X_eTikrUpdate.exe c:\program files\Skype\Plugin Manager\skypePM.exe c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe c:\windows\system32\scardsvr.exe . ************************************************************************** . Completion time: 2008-12-13 19:19:13 - machine was rebooted ComboFix-quarantined-files.txt 2008-12-14 00:19:07 Pre-Run: 46,749,126,656 bytes free Post-Run: 46,766,333,952 bytes free WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect 304 --- E O F --- 2008-11-14 08:04:33