ComboFix 08-12-13.03 - David 2008-12-13 18:55:55.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.323 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\IE4 Error Log.txt
c:\windows\system32\~.exe
c:\windows\system32\umezimiv.ini
c:\windows\system32\yehifuni.dll
.
((((((((((((((((((((((((( Files Created from 2008-11-14 to 2008-12-14 )))))))))))))))))))))))))))))))
.
2008-12-13 18:41 . 2008-12-13 18:40 410,984 --a------ c:\windows\system32\deploytk.dll
2008-12-13 18:20 . 2008-12-13 18:20
d-------- C:\VundoFix Backups
2008-12-11 17:42 . 2008-12-13 08:02 d-------- c:\documents and settings\David\Application Data\skypePM
2008-12-11 17:42 . 2008-12-11 17:42 56 --ah----- c:\windows\system32\ezsidmv.dat
2008-12-11 17:39 . 2008-12-11 17:39 d-------- c:\documents and settings\David\Application Data\Leadertech
2008-12-11 17:39 . 2008-02-05 21:17 2,570,520 -ra------ c:\windows\system32\drivers\LV302V32.SYS
2008-12-11 17:38 . 2008-02-05 21:21 490,008 -ra------ c:\windows\system32\LVUI2.dll
2008-12-11 17:38 . 2008-02-05 21:21 465,432 -ra------ c:\windows\system32\LVUI2RC.dll
2008-12-11 17:38 . 2008-02-05 21:18 416,280 -ra------ c:\windows\system32\lvcodec2.dll
2008-12-11 17:36 . 2008-02-05 21:20 628,760 -ra------ c:\windows\system32\drivers\lvrs.sys
2008-12-11 17:36 . 2008-02-05 21:18 195,096 -ra------ c:\windows\system32\lvci11701196.dll
2008-12-11 17:36 . 2008-02-05 20:37 66,482 -ra------ c:\windows\system32\lvcoinst.ini
2008-12-11 17:36 . 2008-04-13 14:45 60,032 --a------ c:\windows\system32\drivers\USBAUDIO.sys
2008-12-11 17:36 . 2008-04-13 14:45 60,032 --a------ c:\windows\system32\dllcache\usbaudio.sys
2008-12-11 17:36 . 2008-02-05 21:21 41,752 -ra------ c:\windows\system32\drivers\LVUSBSta.sys
2008-12-11 17:36 . 2008-02-05 20:40 25,056 -ra------ c:\windows\system32\Repository.reg
2008-12-11 17:36 . 2008-02-05 21:17 13,848 -ra------ c:\windows\system32\drivers\lv302af.sys
2008-12-11 17:31 . 2008-12-11 17:31 d-------- c:\program files\Logitech
2008-12-11 17:31 . 2008-12-11 17:39 d-------- c:\program files\Common Files\LogiShrd
2008-12-11 17:31 . 2008-12-11 17:31 d-------- c:\documents and settings\All Users\Application Data\Logitech
2008-12-11 17:31 . 2008-12-11 17:31 d-------- c:\documents and settings\All Users\Application Data\Logishrd
2008-12-11 17:27 . 2008-12-13 18:39 d-------- c:\documents and settings\David\Application Data\Skype
2008-12-11 17:24 . 2008-12-11 17:24 d-------- c:\program files\Skype
2008-12-11 17:24 . 2008-12-11 17:24 d-------- c:\program files\Common Files\Skype
2008-12-11 17:24 . 2008-12-11 17:24 d-------- c:\documents and settings\All Users\Application Data\Skype
2008-12-11 13:14 . 2008-12-11 13:14 d-------- c:\program files\SUPERAntiSpyware
2008-12-11 13:14 . 2008-12-11 13:14 d-------- c:\documents and settings\David\Application Data\SUPERAntiSpyware.com
2008-12-11 13:14 . 2008-12-11 13:14 d-------- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2008-12-10 14:41 . 2008-12-10 14:41 d-------- c:\program files\Trend Micro
2008-12-10 11:24 . 2008-12-10 11:24 d-------- c:\documents and settings\David\Application Data\McAfee
2008-12-03 12:33 . 2008-12-03 12:33 d-------- c:\temp\google
2008-12-03 12:33 . 2008-12-03 12:33 d-------- C:\temp
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-13 23:40 --------- d-----w c:\program files\Java
2008-12-13 23:35 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2008-12-13 21:24 2,243 ----a-w c:\program files\eTikrUpdate.original
2008-12-13 02:35 --------- d-----w c:\documents and settings\All Users\Application Data\Google Updater
2008-12-12 18:13 --------- d-----w c:\program files\Dl_cats
2008-12-11 18:13 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2008-12-10 19:44 --------- d-----w c:\program files\BAE
2008-12-10 16:36 --------- d-----w c:\documents and settings\All Users\Application Data\McAfee
2008-12-09 18:45 --------- d-----w c:\program files\eTikr AddIn
2008-11-13 21:21 --------- d-----w c:\documents and settings\All Users\Application Data\Kodak
2008-11-01 18:11 --------- d-----w c:\documents and settings\All Users\Application Data\MGS
2008-11-01 18:09 --------- d-----w c:\documents and settings\All Users\Application Data\Microgaming
2008-10-26 16:36 --------- d--h--w c:\program files\InstallShield Installation Information
2008-10-26 15:36 --------- d-----w c:\program files\Slots Plus Casino
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-23 01:40 --------- d-----w c:\documents and settings\David\Application Data\VTExtra
2008-10-23 01:36 --------- d-----w c:\documents and settings\David\Application Data\InstallShield
2008-10-19 11:25 --------- d-----w c:\documents and settings\David\Application Data\ID Vault
2008-10-19 11:19 --------- d-----w c:\program files\ID Vault
2008-10-17 12:00 --------- d-----w c:\documents and settings\David\Application Data\Intuit
2008-10-17 11:50 --------- d-----w c:\program files\Common Files\AnswerWorks 4.0
2008-10-17 11:47 --------- d-----w c:\documents and settings\All Users\Application Data\Intuit
2008-10-17 11:45 --------- d-----w c:\program files\TurboTax
2007-12-31 20:14 3,024 ----a-w c:\program files\Setup.log
2007-12-31 20:14 170,207 ----a-w c:\program files\X_eTikrUpdate.exe
2007-12-31 20:14 170,207 ----a-w c:\program files\eTikrUpdate.exe
2006-12-12 08:19 156,672 ----a-w c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
2008-10-13 23:55 228,640 ----a-w c:\program files\mozilla firefox\components\IdVault.XPCOM.dll
2007-07-30 21:47 88 --sh--r c:\windows\system32\82A74C8DE9.sys
2006-08-12 10:45 56 --sh--r c:\windows\system32\E98D4CA782.sys
2007-07-30 21:47 4,184 --sha-w c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Blue]
@="{E300CD91-100F-4E67-9AF3-1384A6124015}"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Partial]
@="{E300CD91-100F-4E67-9AF3-1384A6124015}"
[HKEY_CLASSES_ROOT\CLSID\{E300CD91-100F-4E67-9AF3-1384A6124015}]
2008-06-13 22:19 527296 -ra------ c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Green]
@="{95A27763-F62A-4114-9072-E81D87DE3B68}"
[HKEY_CLASSES_ROOT\CLSID\{95A27763-F62A-4114-9072-E81D87DE3B68}]
2008-06-13 22:19 527296 -ra------ c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Blue]
@="{E300CD91-100F-4E67-9AF3-1384A6124015}"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Partial]
@="{E300CD91-100F-4E67-9AF3-1384A6124015}"
[HKEY_CLASSES_ROOT\CLSID\{E300CD91-100F-4E67-9AF3-1384A6124015}]
2008-06-13 22:19 527296 -ra------ c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Red]
@="{01CCCC8C-1D50-4b13-B96D-4B922DD3128B}"
[HKEY_CLASSES_ROOT\CLSID\{01CCCC8C-1D50-4b13-B96D-4B922DD3128B}]
2008-06-13 22:19 527296 -ra------ c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Yellow]
@="{5E529433-B50E-4bef-A63B-16A6B71B071A}"
[HKEY_CLASSES_ROOT\CLSID\{5E529433-B50E-4bef-A63B-16A6B71B071A}]
2008-06-13 22:19 527296 -ra------ c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-12-04 1809648]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-04-03 68856]
"RegistryMechanic"="c:\program files\Registry Mechanic\RegMech.exe" [2008-07-08 2828184]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2007-11-15 202544]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"Creative Detector"="c:\program files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-02 102400]
"Aim6"="c:\program files\AIM6\aim6.exe" [2006-11-07 50736]
"AdobeUpdater"="c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2008-11-11 2356088]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-11-18 21633320]
"SetDefaultMIDI"="MIDIDef.exe" [2004-12-22 c:\windows\MIDIDEF.EXE]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DLCGCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLCGtime.dll" [2005-09-08 73728]
"VoiceCenter"="c:\program files\Creative\VoiceCenter\AndreaVC.exe" [2005-09-19 1159168]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-10-03 185896]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-13 136600]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-01-10 385024]
"MSKDetectorExe"="c:\program files\McAfee\SpamKiller\MSKDetct.exe" [2005-07-12 1117184]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-01-15 267048]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2006-12-14 241152]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"DMXLauncher"="c:\program files\Sonic\Product\Media Experience\DMXLauncher.exe" [2007-04-02 113400]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2006-09-21 127036]
"ddoctorv2"="c:\program files\Comcast\Desktop Doctor\bin\sprtcmd.exe" [2008-04-24 202560]
"CTSysVol"="c:\program files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe" [2005-09-15 57344]
"Carbonite Backup"="c:\program files\Carbonite\Carbonite Backup\CarboniteUI.exe" [2008-06-13 600000]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-05 344064]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 63712]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2008-02-13 564496]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-02-13 2196240]
"MSConfig"="c:\windows\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2008-04-13 169984]
"SigmatelSysTrayApp"="stsystra.exe" [2005-03-22 c:\windows\stsystra.exe]
"MBMon"="CTMBHA.DLL" [2005-05-19 c:\windows\system32\CTMBHA.DLL]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RealUpgradeHelper"="c:\program files\Common Files\Real\Update_OB\upgrdhlp.exe" [2008-10-03 136768]
c:\documents and settings\David\Start Menu\Programs\Startup\
eTikr - Auto Update.lnk - c:\program files\eTikrUpdate.exe [2007-12-31 170207]
Logitech . Product Registration.lnk - c:\program files\Logitech\QuickCam\eReg.exe [2008-02-13 493832]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-05-27 24576]
ID Vault.lnk - c:\program files\ID Vault\IDVault.exe [2008-10-13 795936]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2008-03-18 972064]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-03 14:56 352256 c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Adobe\\Photoshop Elements 5.0\\AdobePhotoshopElementsMediaServer.exe"=
"c:\\Program Files\\Intuit\\QuickBooks 2007\\QBDBMgrN.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\WINDOWS\\system32\\verclsid.exe"=
"c:\\WINDOWS\\stsystra.exe"=
"c:\\Program Files\\Adobe\\Photoshop Album Starter Edition\\3.2\\Apps\\apdproxy.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 SASDIFSV;SASDIFSV;\??\c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2008-12-04 8944]
R1 SASKUTIL;SASKUTIL;\??\c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2008-12-04 55024]
R2 Viewpoint Manager Service;Viewpoint Manager Service;"c:\program files\Viewpoint\Common\ViewpointService.exe" [2007-03-24 24652]
R3 mtsftkey;mtsftkey;c:\windows\system32\drivers\mtsftkey.sys [2007-11-18 60032]
R3 SASENUM;SASENUM;\??\c:\program files\SUPERAntiSpyware\SASENUM.SYS [2008-12-04 7408]
R3 SMCSTUB;SMCSTUB;c:\windows\system32\drivers\smcstub.sys [2007-11-18 55680]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
\Shell\AutoRun\command - E:\setup.exe
.
Contents of the 'Scheduled Tasks' folder
2008-12-13 c:\windows\Tasks\AdwareAlert Scheduled Scan.job
- c:\program files\AdwareAlert\AdwareAlert.exe []
2008-12-13 c:\windows\Tasks\AdwareAlert Scheduled Scan.job
- c:\program files\AdwareAlert [2008-02-06 00:32]
2008-12-10 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 13:57]
2008-11-15 c:\windows\Tasks\McDefragTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]
2008-12-01 c:\windows\Tasks\McQcTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]
.
- - - - ORPHANS REMOVED - - - -
BHO-{67c163d8-6f80-4fae-885f-bfd72db08783} - c:\windows\system32\yefeluki.dll
WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file)
MSConfigStartUp-CPMeb26379f - c:\windows\system32\novunimu.dll
MSConfigStartUp-dopibidopo - c:\windows\system32\tusubiku.dll
MSConfigStartUp-e8150403 - c:\windows\system32\womimago.dll
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.comcast.net/home.html
mStart Page = hxxp://www.comcast.net/
mWindow Title = Windows Internet Explorer provided by Comcast
FF - ProfilePath - c:\documents and settings\David\Application Data\Mozilla\Firefox\Profiles\ghoptwjn.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.comcast.net/
FF - plugin: c:\program files\Google\Google Updater\2.4.1368.5602\npCIDetect13.dll
FF - plugin: c:\program files\iTunes\Mozilla Plugins\npitunes.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - plugin: c:\program files\Picasa2\npPicasa2.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-13 19:02:35
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCGCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLCGtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(684)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
- - - - - - - > 'explorer.exe'(5608)
c:\windows\TEMP\logishrd\LVPrcInj01.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\program files\Lavasoft\Ad-Aware 2007\aawservice.exe
c:\program files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
c:\progra~1\COMMON~1\AOL\ACS\AOLacsd.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Carbonite\Carbonite Backup\CarboniteService.exe
c:\windows\system32\CTSVCCDA.EXE
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\program files\Common Files\McAfee\MNA\McNASvc.exe
c:\progra~1\COMMON~1\McAfee\McProxy\McProxy.exe
c:\progra~1\McAfee\VIRUSS~1\Mcshield.exe
c:\program files\McAfee\MPF\MpfSrv.exe
c:\progra~1\McAfee.com\Agent\mcagent.exe
c:\windows\ehome\mcrdsvc.exe
c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
c:\windows\system32\dllhost.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\progra~1\McAfee\VIRUSS~1\mcsysmon.exe
c:\windows\system32\rundll32.exe
c:\docume~1\David\LOCALS~1\Temp\clclean.0001
c:\windows\ehome\ehmsas.exe
c:\program files\Google\Google Desktop Search\GoogleDesktopIndex.exe
c:\program files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Common Files\LogiShrd\LQCVFX\COCIManager.exe
c:\program files\X_eTikrUpdate.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
c:\windows\system32\scardsvr.exe
.
**************************************************************************
.
Completion time: 2008-12-13 19:19:13 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-14 00:19:07
Pre-Run: 46,749,126,656 bytes free
Post-Run: 46,766,333,952 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect
304 --- E O F --- 2008-11-14 08:04:33